Connecting your AWS account is quick and should take about 10 minutes if you have the required permissions. While we strive to keep our documentation current, AWS may occasionally update their process or UI. If you notice any discrepancies, please contact us at support[at]hava.io.
Prefer a video walkthrough? You can watch it here.
How to create a Cross Account Role
From the Hava Environments screen - select "Add Environments" :
Create you IAM policy
Log in to your AWS Console
In a separate browser tab - log in to your AWS Console.
Navigate to IAM > Policies to create a new policy that your Hava Cross-Account role can use
Note : The resources Hava requests access to allow for the most detailed diagrams of your AWS environment. You can remove any permissions you’re not comfortable with, but this may reduce the accuracy of the analysis, both now and as new features and resources are released.
Then click "Review Policy" & "Name" the new policy.
Click "Create Policy" and the new policy will be created.
Setup cross account role
After setting up your IAM user in AWS, the next step is to configure your cross-account role.
Return to Hava and select the Amazon Data Source.
Ensure the "Cross Account Role" tab is selected.
Click the "Auto Config" button. This will open the Create Role dialog in your AWS Console with the fields pre-filled.
It’s important to verify the following:
Ensure the "Account ID" and "External ID" match the dialogue window in Hava.
Ensure "Require MFA" remains unchecked
Click on Select trusted entity >AWS account
3rd party to perform actions in this account.
Confirm the "Account ID" from Hava
Check "Require external ID"
Confirm the "External ID" from Hava
Uncheck "Require MFA"
Attach permissions policies
"Filter policies" In the search box enter in the name you gave the new Hava policy, you may need to click the "Refresh" button, once found click on the select checkbox.
Select "Next:Tags" - (you can skip this)
Select "Next: Review"
Copy the "Role ARN"
Return to the Hava tab in your browser.
Paste the Role ARN into the Hava dialogue box
(Optional) Add a friendly name for your source; if left blank, Hava will use your AWS account name.
Click "Import"
Video walkthrough
For further assistance, watch the video below on setting up and connecting your AWS account using a cross-account role.
Troubleshooting
Request limit exceeded for (resource)
You can increase these limits in the AWS console, or restrict access to this service in your policy if it's not required.