AWS
Connect AWS with a one-click CloudFormation stack that creates a read-only role and a CUR 2.0 export.
OpsLyft connects to AWS with a cross-account, read-only IAM role and a CUR 2.0 billing export. A CloudFormation stack creates both for you in about three minutes.
Before you begin
- Sign in to your AWS Organizations management (payer) account. Connecting the management account brings in cost for every member account.
- You need permission to create CloudFormation stacks and IAM roles in that account.
- If you don't have access, copy the join link from the connect screen and send it to your AWS owner. See Don't have access?
What the stack creates
| Resource | Purpose |
|---|---|
IAM role OpsLyftReadOnly | A read-only role OpsLyft assumes to read billing, resource metadata, and metrics |
| CUR 2.0 export | The billing data export OpsLyft reads cost from |
Read-only
OpsLyft can see billing and usage data. It can't change, stop, or delete anything in your account.
Connect AWS
Choose AWS
In onboarding, or from Settings → Integrations, choose AWS.
Launch the stack
Select Launch stack in AWS. The CloudFormation console opens with every parameter pre-filled.
Create the stack
Acknowledge that the stack creates IAM resources and select Create stack. Wait for it to reach CREATE_COMPLETE.
Return to OpsLyft
Come back to OpsLyft. It detects the role automatically and starts reading your billing data.
What OpsLyft reads
| Data | From | Used by |
|---|---|---|
| Cost and usage line items | CUR 2.0 | Every module |
| Resource metadata | Service describe APIs, such as describe-instances | Live inventory, Change history |
| Utilisation metrics | Amazon CloudWatch, 90-day lookback | Optimisation evidence |
| Savings Plans and Reserved Instances | CUR 2.0 and commitment APIs | Coverage, amortization, commitment opportunities |
| Bedrock model usage | CUR 2.0 usage types | Amazon Bedrock cost by model and token type |
Data freshness
AWS updates CUR several times a day, but costs for a given day can keep changing for up to 48 hours, and month-end credits, refunds, and invoice adjustments can land days later. Recent days in OpsLyft are marked as incomplete. See Data freshness.
Reporting dimensions
In addition to the common dimensions, AWS adds dimensions such as region, availability zone, usage type, operation, instance type, purchase option, resource ID, and every activated cost allocation tag.
Activate your cost allocation tags
AWS only includes a tag in CUR after it's activated in Billing → Cost allocation tags, and only from that point forward. Activate your owner tag and other required tags early.
Troubleshooting
Check that you're signed in to the management account and that you have permission to create IAM roles. Delete the failed stack and launch it again from OpsLyft.
Wait a minute and refresh. If it still isn't detected, check that the stack finished with CREATE_COMPLETE and that the role OpsLyftReadOnly exists.
You connected a member account instead of the management account. Connect the management account to see every linked account.
That's the billing delay. AWS finalises daily costs over about 48 hours.