# Quickstart

{% embed url="<https://youtu.be/ZJVNKJXFE7g>" %}

###

### AWS

{% content-ref url="/pages/-M2pjoZu9gWzNjnlk1IH" %}
[Getting Started with AWS](/importing/aws/getting-started-with-aws)
{% endcontent-ref %}

* [Cross Account Role](/importing/aws/getting-started-with-aws/cross-account-role)
* [Read Only IAM User](/importing/aws/getting-started-with-aws/read-only-iam-user)
* [Minimum Access IAM User](/importing/aws/getting-started-with-aws/minimum-access-iam-user)

### Azure

{% content-ref url="/pages/-M2pjoZn3rk4EADkA8qq" %}
[Getting Started with Azure](/importing/azure/getting-started-with-azure)
{% endcontent-ref %}

### Google Cloud

{% content-ref url="/pages/-M2pjoZqG\_j8VLGRohDG" %}
[Getting Started with GCP](/importing/google-cloud/getting-started-google-cloud-platform)
{% endcontent-ref %}

### Kubernetes

{% content-ref url="/pages/1H5rpnlqfmxwvSRjLK7y" %}
[Getting Started with Kubernetes](/importing/kubernetes/getting-started-with-kubernetes)
{% endcontent-ref %}


# Create New Account

Welcome to Hava.

Hava produces accurate & logically laid out interactive diagrams when connected to your AWS, Azure or GCP cloud accounts.

This help documentation should help you through the initial set up and operation of the software.

Should you need further help, a one-on-one demo or to discuss our enterprise self hosted solutions, please contact our team on <sales@hava.io> or via the chat widget on [hava.io](https://www.hava.io)

## Getting Started with Hava

Welcome to Hava, you are a few simple steps away from producing accurate cloud infrastructure diagrams in seconds and documenting an audit trail of environment changes as they happen.

<figure><img src="https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Loco-kTiJ7Tu_lfPZqb%2Fuploads%2FYUVzNYN97c78owYMFiHZ%2FTry%20Hava.jpg?alt=media&#x26;token=a0503175-70e6-4592-8390-0843e1500306" alt=""><figcaption><p>Try Hava</p></figcaption></figure>

## Login

Once you have completed the sign up process and have your username and password, log in to the Hava app using the "LOGIN" link in the top right corner of the hava.io website, or directly via the following URL <https://app.hava.io/login>

![Hava Login](/files/dJTE6EdwFr3NAWz4YOwg)

*If at any point you forget your password, click on the "Forgot your Password" at the bottom of the login dialogue box and a reset request will be emailed to the email address associated with your account.*

Once logged in, you will be prompted to "Add Environments" - this process varies depending on the type of cloud infrastructure you are using.

Select from the options below for a detailed walk through of each of the platforms that are supported by Hava.


# Import Demo Data

Getting started with Hava automated interactive cloud network topology diagrams.

## Importing Demo Environments

When you first log in to Hava, you will have the option to import a demo account.

There are currently 3 to choose from.

![Select Demo Data to Import or Import your own](/files/pSYyfVAQDl2E2LSZeixU)

Selecting either AWS, Azure or Google Cloud will import a demo environment for you to explore and get familiar with.

Please choose the cloud platform you are working with the most, as once you select a demo environment import, the demo import option will be removed.

Once you are ready to connect your own cloud account to Hava, select 'add environments'.

Detailed instructions for each platform can be found below this help document:

{% content-ref url="/pages/-M2pjoZu9gWzNjnlk1IH" %}
[Getting Started with AWS](/importing/aws/getting-started-with-aws)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZn3rk4EADkA8qq" %}
[Getting Started with Azure](/importing/azure/getting-started-with-azure)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZqG\_j8VLGRohDG" %}
[Getting Started with GCP](/importing/google-cloud/getting-started-google-cloud-platform)
{% endcontent-ref %}


# Creating Environments

By default, Hava will build at a VPC level. We understand that is not ideal for all use cases, this is why we have built-in search capabilities, meaning you can create custom environment diagrams.

You can use the search to build custom environments based on a wide range of search queries and boolean operators.

To learn how simple it is to start creating and editing your automated diagrams follow the links below.<br>

{% content-ref url="/pages/8zWeYSiZjbLTCaozTVPW" %}
[Search Overview](/discover/searching/overview)
{% endcontent-ref %}

{% content-ref url="/pages/pDBeJa4GuWVPjbF2LqBw" %}
[Search Syntax](/discover/searching/search-syntax)
{% endcontent-ref %}

{% content-ref url="/pages/qLKXn5obN82Ng0wOyyJm" %}
[Search Examples](/discover/searching/examples)
{% endcontent-ref %}


# Exporting Diagrams

How to export auto generated network topology diagrams.

One of the major benefits of utilising Hava is the ability to export diagrams to meet any number of requirements including:

* Internal Documentation
* On-boarding new staff
* Audit & Compliance requirements
* Presentations to management or internal stakeholders
* Use case demonstrations in Managed Services or Devops sales presentations

Because your diagrams are continuously refreshed, exporting up to date diagrams of your environments takes a matter of seconds. If any changes have been made that you want to demonstrate on the diagram, you can manually sync Hava with your cloud provider prior to exporting the diagram.

Hava will export your cloud environment diagrams in several major formats including :

* PDF
* PNG
* Visio (VSDX)
* CSV
* JSON.

Open the diagram you wish to export & select the 'Export" button to open the export dialogue :

![Hava Diagram Export Options](/files/RnyIAIbbeVY5k2tS6mSS)

‌

Select the required output format : Hava will prepare the download - once the "Export Complete" notification is visible, you can download the exported file.

![](/files/N4BHE8bCxsDYfVdY2wMy)

Hava will export exactly what you are looking at in the rendered visualisation.

If you wish to show connections and/or display full resource names on the exported diagram, then make sure you toggle the display of these on prior to exporting the diagram.

![Change Options like names and connecions prior to exporting](/files/FLy1f3BWGSDnew8Awo0j)


# AWS Marketplace

Getting started with Hava using the AWS Marketplace

### HOW TO SUBSCRIBE TO HAVA VIA AWS MARKETPLACE

Navigate to the AWS Marketplace console.

![AWS Marketplace Console](https://www.hava.io/hs-fs/hubfs/AWS_Marketplace_Console.jpg?width=3016\&height=1364\&name=AWS_Marketplace_Console.jpg)

Search for Hava:

![Hava on the AWS Marketplace](https://www.hava.io/hs-fs/hubfs/aws_marketplace_2_hava.jpg?width=2612\&height=1002\&name=aws_marketplace_2_hava.jpg)

Select "Hava Monthly Subscription"

When using the AWS marketplace, Hava is purchased on a month by month subscription basis with no lock in contracts. You can cancel at any time.

![Hava Monthly Subscription](https://www.hava.io/hs-fs/hubfs/aws_marketplace_3_View_Hava_Purchase_Options.jpg?width=2612\&height=636\&name=aws_marketplace_3_View_Hava_Purchase_Options.jpg)

Select purchase options.

The first decision is whether to auto renew at the end of the first month. Set this to yes to avoid your account being disabled after 30 days and your diagram version history being removed,

<img src="https://www.hava.io/hs-fs/hubfs/aws_marketplace_4_renewal.jpg?width=500&#x26;height=273&#x26;name=aws_marketplace_4_renewal.jpg" alt="Set to Renew" height="273" width="500">

Next select the plan that best suits your needs from Professional or Team.

Professional includes 5 sources. Sources are cloud accounts, so you could connect this AWS account plus four more, or mix and match with Microsoft Azure or Google Cloud Platform accounts. Full details of what is included in the two plans can be found on the [Hava Pricing Page](https://www.hava.io/pricing).

![Hava Contract Options (Plans)](https://www.hava.io/hs-fs/hubfs/aws_marketplace_5_hava_contract_options.jpg?width=1734\&height=862\&name=aws_marketplace_5_hava_contract_options.jpg)

In this example, we will proceed with a Professional plan by clicking on the "Create Contract" button.

![Create Contract](https://www.hava.io/hs-fs/hubfs/aws_marketplace_6_create_contract.jpg?width=2608\&height=968\&name=aws_marketplace_6_create_contract.jpg)

AWS will prompt you to confirm the contract. Billing will be immediate and set up via the payment method you use for your AWS account.

<img src="https://www.hava.io/hs-fs/hubfs/aws_marketplace_7_confirm_contract.jpg?width=600&#x26;height=349&#x26;name=aws_marketplace_7_confirm_contract.jpg" alt="Confirm Contract" height="349" width="600">

You will then be prompted to create your Hava account.

![Set Up Your Hava Account](https://www.hava.io/hs-fs/hubfs/aws_marketplace_8_setup_hava_account.jpg?width=1084\&height=722\&name=aws_marketplace_8_setup_hava_account.jpg)

*\*note the $0 due today shown on this screen is a glitch in the AWS marketplace flow which doesn't affect your subscription and has been reported. You will be charged the amount shown in the previous confirm contract screen.*

Click on set up your account.

<img src="https://www.hava.io/hs-fs/hubfs/aws_marketplace_9_hava_login.jpg?width=500&#x26;height=598&#x26;name=aws_marketplace_9_hava_login.jpg" alt="aws_marketplace_9_hava_login" height="598" width="500">

Enter your name, a name for the account (can be anything) and log in details being an email address and password.

Make sure you use your best email as you will need to confirm it as part of the sign up process.

You will then get a message saying the marketplace integration is being set up and to not close or reload the page while this is processing.

You will then be logged into your Hava console and can add you first data source.

### CONNECTING AWS TO HAVA

Adding an AWS data source.

![Add your AWS Data Source (AWS Account)](/files/pSYyfVAQDl2E2LSZeixU)

Take the first option : Import your own environments.

![Connect a Cross Account Role Wizard (Auto)](/files/B2slRiwtWm54ME8L45vW)

Next we need to set up a read-only IAM cross account role. To do this, make sure you are logged into the AWS account you wish to connect then click the auto button.

![Connect Trusted Entity](https://www.hava.io/hs-fs/hubfs/aws_marketplace_12_role_1.jpg?width=1426\&height=762\&name=aws_marketplace_12_role_1.jpg)

Select AWS account (this will be pre-selected). "Another AWS Account" will also be pre selected along with the Hava account ID.

Ensure you leave the "Require MFA" unchecked.

![Connect with another AWS Account](https://www.hava.io/hs-fs/hubfs/aws_marketplace_12_role_2.jpg?width=1860\&height=1032\&name=aws_marketplace_12_role_2.jpg)

Next name and create the new role.

<img src="https://www.hava.io/hs-fs/hubfs/aws_marketplace_13_role_create.jpg?width=600&#x26;height=411&#x26;name=aws_marketplace_13_role_create.jpg" alt="Name The New Role" height="411" width="600">

Create the role. Then from the roles dashboard, open the new role (in this example Hava\_AWS) and copy the role ARN

![Obtain the New Cross Account Role ARN](https://www.hava.io/hs-fs/hubfs/aws_marketplace_14_get_arn.jpg?width=2550\&height=922\&name=aws_marketplace_14_get_arn.jpg)

Return to Hava and paste in the ARN

![Paste the ARN into Hava](/files/XK30rU8yA9sghog45egi)

The click import and Hava will scan the connected AWS account and create interactive diagram sets for every VPC discovered in the account.

Depending on the size and number of environments in your AWS account this will take from a few seconds to a few minutes.

![Hava Discovering VPCs in an AWS Account](/files/gkcKKxEFxtpte31ogzou)

Tiles will appear on your Hava dashboard depicting the discovered VPCs or container workloads in the connected account.

Selecting a VPC will open the architecture diagram.

![Hava Auto Generated Cloud Architecture Diagram](/files/FRjw0CJD2NlzlPotF0bU)

From there you can navigate around the diagram, select resources to view the related attributes, connected resources etc. You can also open the security view to see the security groups, ports, protocols and how traffic moves in and out of the VPC

![Hava Security Diagram](/files/DrgpMhiaRUmGe1D68a1c)

At this point Hava is now monitoring the configuration of all the VPCs running in your AWS account.

Any changes are detected and new diagrams are generated with the superseded diagrams being placed in version history.

You can set architectural monitoring alerts that will send you an email with a diff diagram every time a diagram is updated. You can also manually generate a diff diagram by comparing any two diagram revisions in the versions menu.

To subscribe to Hava via AWS marketplace follow the instructions above.

{% embed url="<https://youtu.be/Hj6lQBEaHlc>" %}


# Providers & Sources

Hava automatically generates network topology diagrams for the following cloud infrastructure vendors.

The shift from static infrastructure to dynamic cloud environments presented us with a whole new problem with creating up-to-date diagrams and knowing "What's Running and Where."

The one thing Hava is NOT is a drag and drop tool. We believe the manual creation of post diagrams in a dynamic environment is near on pointless and can become outdated within days, hours and even minutes.

Hava goal is to eliminate human effort and error by creating automated and interactive diagrams, reports and documentation of your existing cloud infrastructure from the source of truth across many different cloud providers.

To date, we currently support importing from AWS, Azure, and Google Cloud with other providers on their way soon.

{% content-ref url="/pages/-M2pjoZsfss1FbXWL5XA" %}
[AWS Supported Resources](/importing/aws/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZoJfhHsIRN73CC" %}
[Azure Supported Resources](/importing/azure/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZpyuH9bgh1I7wO" %}
[GCP Supported Resources](/importing/google-cloud/supported-resources)
{% endcontent-ref %}

Get in touch with us if you'd like to know where support for your provider currently sits on the roadmap.


# Environments

How to navigate the functions found in the Hava Environments Dashboard.

When you log into the Hava App, you will arrive at the Environments dashboard

![](/files/gkcKKxEFxtpte31ogzou)

The dashboard shows all of your imported cloud environments, the sources for the imported data, a range of view options, filters, account billing and personal settings.

There is also a tool to build custom environments by selecting a range of data like region, vpc, ip, subnet and so on, to build a custom view of resources across multiple source accounts or platforms. When you build a custom environment, this is automatically synced and changes tracked with version control just like an automatically imported environment.

{% embed url="<https://youtu.be/epYoB9Y0SZY>" %}

### **Data Source List**

The list of data sources used to create environment diagrams is displayed on the dashboard when selected from the data sources on the top of the dashboard.

![](/files/7l3UdSVHcgyYcKip3gV3)

Adjacent to each data source is a button that will allow you to :

* Initiate a manual Sync - this option is only visible when no auto sync in queued or in progress
* Change Name
* Edit Credentials
* Delete

On the top of the environments dashboard you can toggle the visibility of sources on or off and also you can use the provider filter to show or hide environments from specific providers like AWS

![Filter visible environments](/files/2FQX3iGD3civETbgSt8F)

### **Account Settings**

Account Settings can be accessed via the 'Settings' menu item cog icon at the bottom left of the screen :

From this menu item you can:

* Change your account name
* Cancel your account
* View billing and payment history
* Create and manage teams

![Your Account Settings are access via the bottom left cog icon](/files/fiRIKdn7OUMCnYD4EmC6)

#### **User "Personal" Settings**

The user settings can be accessed via the top right of your Hava dashboard, or via the account settings menu.

In Personal Settings there are options to :

* Update personal settings
* Change Password
* Add or update email addresses
* Obtain API keys

![](/files/xwpdmf3gTbZFuJxp80V7)

Under "Profile" you can update your personal details and change your account password.

**Update Account Email Addresses**

The "Emails" option in Personal Settings will allow you to enter additional email addresses to your account and nominate which is one is primary.

### **API Tokens**

API Tokens are also located in Personal Settings.

Click on the 'Display Token" button to reveal your unique API token :

![API Tokens - Account Settings](/files/t5Ebc3TsFLmQOw7JXZzb)


# Creating Environments

Hava gives you the ability to create custom environments beyond the standard default import.

This enables you to visualise resources across accounts, data sources or even cloud platforms on a single diagram.

![](/files/AZNtwrHGuqZRlH8dgjfo)

## More Documents & Guides

To learn more about our search syntax and examples please use the below links.

{% content-ref url="/pages/8zWeYSiZjbLTCaozTVPW" %}
[Search Overview](/discover/searching/overview)
{% endcontent-ref %}

{% content-ref url="/pages/pDBeJa4GuWVPjbF2LqBw" %}
[Search Syntax](/discover/searching/search-syntax)
{% endcontent-ref %}

{% content-ref url="/pages/qLKXn5obN82Ng0wOyyJm" %}
[Search Examples](/discover/searching/examples)
{% endcontent-ref %}

### Quick Video Overview

{% embed url="<https://youtu.be/mE1S0EhFBME>" %}


# Filtering Environments

## **Filter Environments**

The Filter Environments field allows you to filter the displayed environment tiles based on partial diagram name and/or availability zone. The filter matching is not case sensitive.

![](https://www.hava.io/hubfs/assets/2020UI/Filter_Hava_Cloud_Diagrams.png)

For instance, you could filter your displayed tiles to only show environments hosted in any us-east availability zone by entering "us-east" into the box

![Use the filter box to display specific regions or diagram names](https://www.hava.io/hubfs/assets/2020UI/Hava_Filter_Cloud_Diagrams_by_Region.png)

## Show / Hide Empty Environments

This button toggles whether empty environment tiles are visible or not :

![Show or Hide Empty Cloud Infrastructure Diagrams](https://www.hava.io/hubfs/assets/2020UI/Hava_Show_Empty_Cloud_Environments.png)

## **Diagram View Filter**

There are several diagram views, like Infrastructure, Container, Security & List. The filter shortcut menu allows you to filter the diagram tiles to show only the environment diagrams that contain data in that view.

This can be utilised by teams only interested in a specific aspect of your environments, for example the security team can select the security views and jump straight into the security diagram for the selected environment.

![Select the type of diagrams to display on your diagram dashboard](https://www.hava.io/hubfs/assets/2020UI/Filter_Cloud_Diagrams_by_Type.png)

###


# AWS

{% content-ref url="/pages/-M2pjoZu9gWzNjnlk1IH" %}
[Getting Started with AWS](/importing/aws/getting-started-with-aws)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZsfss1FbXWL5XA" %}
[AWS Supported Resources](/importing/aws/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/Dj7vKVu0vEgqgTzdQl6Q" %}
[AWS Views](/importing/aws/views)
{% endcontent-ref %}


# Getting Started with AWS

Connecting your AWS accounts to hava.

When you log into Hava for the first time, you will be presented with the opportunity to import some demo environments and also jump right into connecting to your own AWS accounts.

![Getting Started with AWS](/files/pSYyfVAQDl2E2LSZeixU)

The first step in creating accurate AWS infrastructure diagrams with Hava is to connect Hava to your AWS account.

We **strongly advise** creating a **Cross Account Role** to allow access to your AWS environment. Hava is built on AWS and this method is considered AWS best practice.

You may also create a new IAM user with **Read Only Permissions**. Either way, there can be no doubt from an infrastructure integrity and security perspective that Hava cannot change or update anything in your environment and is limited to reading the data it needs to visualise your AWS environment.

{% embed url="<https://youtu.be/mbXJyKpC9jU>" %}

You may also create a Minimum Access Read Only IAM User with customisable permissions if you wish to exclude access to any components of your AWS environment.


# Cross Account Role

### Setting up and Connecting Your AWS Account

Connecting your AWS account is quick and should take about 10 minutes if you have the required permissions. While we strive to keep our documentation current, AWS may occasionally update their process or UI. If you notice any discrepancies, please contact us at support\[at]hava.io.

Prefer a video walkthrough? You can watch it [here](#video-walkthrough).

***

### How to create a Cross Account Role

From the Hava Environments screen - select "**Add Environments**" :

![](/files/4vcXdF7MWLDkNd0TzXEj)

***

### Create you IAM policy

#### Log in to your AWS Console

In a separate browser tab - log in to your AWS Console.

1. Navigate to **IAM > Policies** to create a new policy that your Hava Cross-Account role can use
2. Click **"Create Policy"**
3. Select the **JSON** tab

<div align="left"><img src="https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_CAR_Create_4.jpg" alt="" width="563"></div>

<details>

<summary>Paste the following JSON code (click > to expand)</summary>

{% code fullWidth="true" %}

```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Action": [
        "acm:DescribeCertificate",
        "acm:GetCertificate",
        "acm:ListCertificates",
        "apigateway:GET",
        "appsync:GetApiCache",
        "appsync:ListApiKeys",
        "appsync:ListDataSources",
        "appsync:ListDomainNames",
        "appsync:ListFunctions",
        "appsync:ListGraphqlApis",
        "appsync:ListResolvers",
        "appsync:ListSourceApiAssociations",
        "appsync:ListTagsForResource",
        "appsync:ListTypes",
        "appstream:Get*",
        "autoscaling:Describe*",
        "cloudformation:List*",
        "cloudfront:Get*",
        "cloudfront:List*",
        "cloudhsm:DescribeBackups",
        "cloudhsm:DescribeClusters",
        "cloudhsm:GetResourcePolicy",
        "cloudhsm:ListTags",
        "cloudsearch:Describe*",
        "cloudsearch:List*",
        "cloudtrail:DescribeTrails",
        "cloudtrail:GetTrailStatus",
        "cloudwatch:Describe*",
        "cloudwatch:Get*",
        "cloudwatch:List*",
        "codecommit:BatchGetRepositories",
        "codecommit:Get*",
        "codecommit:GitPull",
        "codecommit:List*",
        "codedeploy:Batch*",
        "codedeploy:Get*",
        "codedeploy:List*",
        "config:Deliver*",
        "config:Describe*",
        "config:Get*",
        "datapipeline:DescribeObjects",
        "datapipeline:DescribePipelines",
        "datapipeline:EvaluateExpression",
        "datapipeline:GetPipelineDefinition",
        "datapipeline:ListPipelines",
        "datapipeline:QueryObjects",
        "datapipeline:ValidatePipelineDefinition",
        "directconnect:Describe*",
        "ds:Check*",
        "ds:Describe*",
        "ds:Get*",
        "ds:List*",
        "ds:Verify*",
        "dynamodb:DescribeGlobalTable",
        "dynamodb:DescribeTable",
        "dynamodb:ListGlobalTables",
        "dynamodb:ListTables",
        "dynamodb:ListTagsOfResource",
        "ec2:Describe*",
        "ec2:GetConsoleOutput",
        "ecr:BatchCheckLayerAvailability",
        "ecr:BatchGetImage",
        "ecr:DescribeRepositories",
        "ecr:GetDownloadUrlForLayer",
        "ecr:ListImages",
        "ecs:Describe*",
        "ecs:List*",
        "eks:Describe*",
        "eks:List*",
        "elasticache:Describe*",
        "elasticache:List*",
        "elasticbeanstalk:Check*",
        "elasticbeanstalk:Describe*",
        "elasticbeanstalk:List*",
        "elasticbeanstalk:RequestEnvironmentInfo",
        "elasticbeanstalk:RetrieveEnvironmentInfo",
        "elasticfilesystem:DescribeFileSystems",
        "elasticfilesystem:DescribeMountTargetSecurityGroups",
        "elasticfilesystem:DescribeMountTargets",
        "elasticfilesystem:DescribeTags",
        "elasticloadbalancing:Describe*",
        "elasticmapreduce:Describe*",
        "elasticmapreduce:List*",
        "elastictranscoder:List*",
        "elastictranscoder:Read*",
        "es:DescribeDomain",
        "es:DescribeDomainNodes",
        "es:DescribeDomains",
        "es:DescribeElasticsearchDomain",
        "es:DescribeElasticsearchDomainConfig",
        "es:DescribeElasticsearchDomains",
        "es:DescribeReservedElasticsearchInstances",
        "es:DescribeVpcEndpoints",
        "es:ESHttpGet",
        "es:ESHttpHead",
        "es:ListDomainNames",
        "es:ListTags",
        "es:ListVpcEndpointAccess",
        "es:ListVpcEndpoints",
        "es:ListVpcEndpointsForDomain",
        "events:DescribeApiDestination",
        "events:DescribeArchive",
        "events:DescribeConnection",
        "events:DescribeEndpoint",
        "events:DescribeEventBus",
        "events:DescribeEventSource",
        "events:DescribePartnerEventSource",
        "events:DescribeReplay",
        "events:DescribeRule",
        "events:ListApiDestinations",
        "events:ListArchives",
        "events:ListConnections",
        "events:ListEndpoints",
        "events:ListEventBuses",
        "events:ListEventSources",
        "events:ListPartnerEventSourceAccounts",
        "events:ListPartnerEventSources",
        "events:ListReplays",
        "events:ListRuleNamesByTarget",
        "events:ListRules",
        "events:ListTagsForResource",
        "events:ListTargetsByRule",
        "events:TestEventPattern",
        "firehose:DescribeDeliveryStream",
        "firehose:ListDeliveryStreams",
        "firehose:ListTagsForDeliveryStream",
        "glacier:DescribeJob",
        "glacier:DescribeVault",
        "glacier:GetDataRetrievalPolicy",
        "glacier:GetJobOutput",
        "glacier:GetVaultAccessPolicy",
        "glacier:GetVaultLock",
        "glacier:GetVaultNotifications",
        "glacier:ListJobs",
        "glacier:ListMultipartUploads",
        "glacier:ListParts",
        "glacier:ListTagsForVault",
        "glacier:ListVaults",
        "iam:GenerateCredentialReport",
        "iam:Get*",
        "iam:List*",
        "inspector:Describe*",
        "inspector:Get*",
        "inspector:List*",
        "iot:Describe*",
        "iot:Get*",
        "iot:List*",
        "kafka:DescribeCluster",
        "kafka:DescribeClusterV2",
        "kafka:DescribeVpcConnection",
        "kafka:ListClientVpcConnections",
        "kafka:ListClusters",
        "kafka:ListClustersV2",
        "kafka:ListNodes",
        "kafka:ListTagsForResource",
        "kafka:ListVpcConnections",
        "kinesis:Describe*",
        "kinesis:DescribeStream",
        "kinesis:DescribeStreamConsumer",
        "kinesis:DescribeStreamSummary",
        "kinesis:ListShards",
        "kinesis:ListStreamConsumers",
        "kinesis:ListStreams",
        "kinesis:ListTagsForStream",
        "kms:Describe*",
        "kms:Get*",
        "kms:List*",
        "lambda:Get*",
        "lambda:List*",
        "logs:Describe*",
        "logs:Get*",
        "logs:TestMetricFilter",
        "machinelearning:Describe*",
        "machinelearning:Get*",
        "opsworks:Describe*",
        "opsworks:Get*",
        "organizations:ListAccounts",
        "rds:Describe*",
        "rds:ListTagsForResource",
        "redshift:Describe*",
        "redshift:ViewQueriesInConsole",
        "route53:Get*",
        "route53:List*",
        "route53domains:CheckDomainAvailability",
        "route53domains:GetDomainDetail",
        "route53domains:GetOperationDetail",
        "route53domains:ListDomains",
        "route53domains:ListOperations",
        "route53domains:ListTagsForDomain",
        "s3:GetAccelerateConfiguration",
        "s3:GetAnalyticsConfiguration",
        "s3:GetBucket*",
        "s3:GetInventoryConfiguration",
        "s3:GetLifecycleConfiguration",
        "s3:GetMetricsConfiguration",
        "s3:GetReplicationConfiguration",
        "s3:List*",
        "sdb:GetAttributes",
        "sdb:List*",
        "sdb:Select*",
        "ses:Get*",
        "ses:List*",
        "sns:Get*",
        "sns:List*",
        "sqs:GetQueueAttributes",
        "sqs:ListQueues",
        "sqs:ReceiveMessage",
        "storagegateway:Describe*",
        "storagegateway:List*",
        "swf:Count*",
        "swf:Describe*",
        "swf:Get*",
        "swf:List*",
        "tag:Get*",
        "trustedadvisor:Describe*",
        "waf-regional:Get*",
        "waf-regional:List*",
        "waf:Get*",
        "waf:List*",
        "wafv2:GetWebACL",
        "wafv2:ListResourcesForWebACL",
        "wafv2:ListTagsForResource",
        "wafv2:ListWebACLs",
        "workspaces:Describe*"
      ],
      "Effect": "Allow",
      "Resource": "*"
    }
  ]
}
```

{% endcode %}

</details>

{% hint style="info" %}
***Note :*** The resources Hava requests access to allow for the most detailed diagrams of your AWS environment. You can remove any permissions you’re not comfortable with, but this may reduce the accuracy of the analysis, both now and as new features and resources are released.
{% endhint %}

4. Then click **"Review Policy"** & **"Name"** the new policy.

<div align="left"><img src="https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_CAR_Create_5.jpg" alt="" width="563"></div>

5. Click **"Create Policy"** and the new policy will be created.

***

### Setup cross account role

After setting up your IAM user in AWS, the next step is to configure your cross-account role.

1. Return to Hava and select the Amazon Data Source.<br>
2. Ensure the **"Cross Account Role"** tab is selected.<br>
3. Click the **"Auto Config"** button. This will open the Create Role dialog in your AWS Console with the fields pre-filled.

<div align="left" data-full-width="false"><img src="/files/LGT3J7uZnseiyGzVTeXE" alt="" width="563"></div>

{% hint style="danger" %}
**It’s important to verify the following:**<br>

* Ensure the **"Account ID"** and **"External ID"** match the dialogue window in Hava.
* Ensure **"Require MFA"** remains **unchecked**
  {% endhint %}

4. Click on **Select trusted entity >** **AWS account**

<div align="left"><img src="/files/gYNgD1x7oF6FyWj3kBEa" alt="" width="563"></div>

5. 3rd party to perform actions in this account.<br>
   1. Confirm the **"Account ID"** from Hava<br>
   2. Check **"Require external ID"**<br>
   3. Confirm the **"External ID"** from Hava<br>
   4. Uncheck **"Require MFA"**

<div align="left"><img src="/files/jXjAGHCfXtZxJnAGqdZt" alt="" width="563"></div>

6. Attach permissions policies<br>

   <div align="left"><img src="https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_CAR_Create_6.jpg" alt="" width="563"></div>

   1. **"Filter policies"** In the search box enter in the name you gave the new Hava policy, you may need to click the **"Refresh"** button, once found click on the select checkbox.<br>
   2. Select **"Next:Tags"** - (you can skip this)<br>
   3. Select **"Next: Review"**

   <div align="left"><img src="https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_CAR_Create_7.jpg" alt="" width="563"></div>
7. **Copy** the **"Role ARN"**

<div align="left"><img src="https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_CAR_Create_8.jpg" alt="" width="563"></div>

8. Return to the Hava tab in your browser.
   1. Paste the **Role ARN** into the Hava dialogue box
   2. (Optional) Add a friendly name for your source; if left blank, Hava will use your AWS account name.
   3. Click **"Import"**

<div align="left"><img src="/files/XK30rU8yA9sghog45egi" alt="" width="563"></div>

### Video walkthrough

For further assistance, watch the video below on setting up and connecting your AWS account using a cross-account role.

{% embed url="<https://youtu.be/mbXJyKpC9jU>" %}

### Troubleshooting

<details>

<summary>Request limit exceeded for (resource)</summary>

You can increase these limits in the AWS console, or restrict access to this service in your policy if it's not required.

**You can learn more here at AWS:**

* Elastic beanstalk: [AWS Elastic Beanstalk endpoints and quotas](https://docs.aws.amazon.com/general/latest/gr/elasticbeanstalk.html)
* Step Function: [AWS Step Functions endpoints and quotas](https://docs.aws.amazon.com/general/latest/gr/step-functions.html)

</details>

<details>

<summary>Failed to authenticate</summary>

Please verify that you’ve entered the correct ARN and placed it in the correct input field as outlined in steps 7 and 8.

</details>

<details>

<summary>Failed to create EKS source</summary>

This error typically indicates a private cluster. Currently, we only support public clusters.

We’re working on supporting private clusters and hope to offer this feature soon.

</details>


# Read Only IAM User

### How to create a Read Only IAM User

Using a cross account role is AWS best practice and the preferred method to enable Hava to build your environment diagrams and log changes. If you prefer to set up access via a key pair, then follow these instructions.

Log in to your AWS console & open the Services menu.

Select IAM from the Security, Identity & Compliance options :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_AWS_Management_Console.jpg)

Select Users :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_IAM_Management_Console.jpg)

Click "Add User" :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_IAM_Add_User.jpg)

Enter a memorable User Name and set the access type to "Programmatic Access"

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_IAM_Add_User_2.jpg)

Click "Next Permissions" to move to the set permissions dialogue.

Select "Attach existing policies directly"

Scroll through the policies : locate and select "ReadOnlyAccess" :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_IAM_Add_User_Permissions.jpg)

Click Next to advance to the "Add tags" dialogue. **Skip this step**.

Click "Next : Review" to advance to the review screen :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_IAM_Add_User_Review.jpg)

Click "Create User" :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_IAM_Add_User_Step_5v2.jpg)

You will get a screen confirming the successful creation of the new user and an Access Key ID and Secret Access Key credentials. You can write these down, however, to ensure accuracy we advise downloading the credentials.csv file and cutting & pasting the user credentials from there.

You now have the necessary user and credentials to connect Hava to your AWS environment.

Open the Hava Environments workspace and select Add Environments :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Add_Environment.jpg)

Enter the Access Key and Secret Key from the previous step and click "Import" :

![](/files/CmoFPwfkJvefWVVjnJgE)

Hava will now import your environment components, construct the diagrams and start logging changes as they happen.


# Minimum Access IAM User

### How to Create a Minimum Access IAM User

Creating the Hava Read-Only IAM user, that uses the standard AWS ReadOnlyAccess Policy will ensure that your user doesn't have enough privileges to change anything in your environment.

If you feel that the default policy from AWS allows too much access you can create a custom policy to limit it to just what we need.

While we recommend the default Read-Only policy to account for future updates to our supported services you can follow these steps to create a minimum access read-only user that Hava can use to visualize your AWS infrastructure.

Before you start make sure you are logged in to the [AWS console](https://console.aws.amazon.com/console/home).

1. From the main console screen click on **Identity & Access Management**.![iam-step1.png](https://www.hava.io/hs-fs/hubfs/iam-help/iam-step1.png?width=256\&name=iam-step1.png)
2. From the IAM dashboard select the **Users** section and then click the **Create New Users** button.![iam-step2.png](https://www.hava.io/hs-fs/hubfs/iam-help/iam-step2.png?width=378\&name=iam-step2.png)
3. Enter a unique username for your new user, make sure **Generate an access key** is checked, and then click the **Create** button.\
   ![iam-step3.png](https://www.hava.io/hs-fs/hubfs/iam-help/iam-step3.png?width=583\&name=iam-step3.png)
4. You should be notified that your user has been created. You can copy the details from this screen or just click **Download** to save them.\
   ![iam-step4.png](https://www.hava.io/hs-fs/hubfs/iam-help/iam-step4.png?width=575\&name=iam-step4.png)
5. Now that you've created your user, you will need to create the customer policy that grants Hava the security it requires at a minimum.From the IAM dashboard select the **Policy** section and then click the **Create New Policy** button.\
   ![IAM-policy-selected.png](https://www.hava.io/hs-fs/hubfs/IAM-policy-selected.png?width=148\&name=IAM-policy-selected.png)\
   ![Screen\_Shot\_2016-04-08\_at\_3.23.48\_PM.png](https://www.hava.io/hs-fs/hubfs/Screen_Shot_2016-04-08_at_3.23.48_PM.png?width=293\&name=Screen_Shot_2016-04-08_at_3.23.48_PM.png)
6. You will then need to select the **Create Your Own Policy** option.\
   ![Screen\_Shot\_2016-04-08\_at\_3.26.09\_PM.png](https://www.hava.io/hs-fs/hubfs/Screen_Shot_2016-04-08_at_3.26.09_PM.png?width=1024\&name=Screen_Shot_2016-04-08_at_3.26.09_PM.png)
7. You will need to provide the name of your policy such as "**HAVA-RO-POLICY",** a description of the policy such as **"Just enough access to ensure Hava can work it's magic"** and then enter in the custom policy seen here:\
   \
   ![Screen\_Shot\_2016-04-08\_at\_3.30.20\_PM.png](https://www.hava.io/hs-fs/hubfs/Screen_Shot_2016-04-08_at_3.30.20_PM.png?width=1024\&name=Screen_Shot_2016-04-08_at_3.30.20_PM.png)\
   \
   You can copy and paste the policy from here:<br>

   ```
   {
     "Version": "2012-10-17",
     "Statement": [
       {
         "Action": [
           "acm:DescribeCertificate",
           "acm:GetCertificate",
           "acm:ListCertificates",
           "apigateway:GET",
           "appsync:GetApiCache",
           "appsync:ListApiKeys",
           "appsync:ListDataSources",
           "appsync:ListDomainNames",
           "appsync:ListFunctions",
           "appsync:ListGraphqlApis",
           "appsync:ListResolvers",
           "appsync:ListSourceApiAssociations",
           "appsync:ListTagsForResource",
           "appsync:ListTypes",
           "appstream:Get*",
           "autoscaling:Describe*",
           "cloudformation:List*",
           "cloudfront:Get*",
           "cloudfront:List*",
           "cloudhsm:DescribeBackups",
           "cloudhsm:DescribeClusters",
           "cloudhsm:GetResourcePolicy",
           "cloudhsm:ListTags",
           "cloudsearch:Describe*",
           "cloudsearch:List*",
           "cloudtrail:DescribeTrails",
           "cloudtrail:GetTrailStatus",
           "cloudwatch:Describe*",
           "cloudwatch:Get*",
           "cloudwatch:List*",
           "config:Describe*",
           "config:Get*",
           "datapipeline:DescribeObjects",
           "datapipeline:DescribePipelines",
           "datapipeline:GetPipelineDefinition",
           "datapipeline:ListPipelines",
           "datapipeline:QueryObjects",
           "directconnect:Describe*",
           "ds:Check*",
           "ds:Describe*",
           "ds:Get*",
           "ds:List*",
           "ds:Verify*",
           "dynamodb:DescribeGlobalTable",
           "dynamodb:DescribeTable",
           "dynamodb:ListGlobalTables",
           "dynamodb:ListTables",
           "dynamodb:ListTagsOfResource",
           "ec2:Describe*",
           "ecr:BatchCheckLayerAvailability",
           "ecr:BatchGetImage",
           "ecr:DescribeRepositories",
           "ecr:GetDownloadUrlForLayer",
           "ecr:ListImages",
           "ecs:Describe*",
           "ecs:List*",
           "eks:Describe*",
           "eks:List*",
           "elasticache:Describe*",
           "elasticache:List*",
           "elasticbeanstalk:Check*",
           "elasticbeanstalk:Describe*",
           "elasticbeanstalk:List*",
           "elasticfilesystem:DescribeFileSystems",
           "elasticfilesystem:DescribeMountTargetSecurityGroups",
           "elasticfilesystem:DescribeMountTargets",
           "elasticfilesystem:DescribeTags",
           "elasticloadbalancing:Describe*",
           "elasticmapreduce:Describe*",
           "elasticmapreduce:List*",
           "elastictranscoder:List*",
           "elastictranscoder:Read*",
           "es:DescribeDomain",
           "es:DescribeDomainNodes",
           "es:DescribeDomains",
           "es:DescribeElasticsearchDomain",
           "es:DescribeElasticsearchDomainConfig",
           "es:DescribeElasticsearchDomains",
           "es:DescribeReservedElasticsearchInstances",
           "es:DescribeVpcEndpoints",
           "es:ListDomainNames",
           "es:ListTags",
           "es:ListVpcEndpointAccess",
           "es:ListVpcEndpoints",
           "es:ListVpcEndpointsForDomain",
           "events:DescribeApiDestination",
           "events:DescribeArchive",
           "events:DescribeConnection",
           "events:DescribeEndpoint",
           "events:DescribeEventBus",
           "events:DescribeEventSource",
           "events:DescribePartnerEventSource",
           "events:DescribeReplay",
           "events:DescribeRule",
           "events:ListApiDestinations",
           "events:ListArchives",
           "events:ListConnections",
           "events:ListEndpoints",
           "events:ListEventBuses",
           "events:ListEventSources",
           "events:ListPartnerEventSourceAccounts",
           "events:ListPartnerEventSources",
           "events:ListReplays",
           "events:ListRuleNamesByTarget",
           "events:ListRules",
           "events:ListTagsForResource",
           "events:ListTargetsByRule",
           "events:TestEventPattern",
           "firehose:DescribeDeliveryStream",
           "firehose:ListDeliveryStreams",
           "firehose:ListTagsForDeliveryStream",
           "glacier:DescribeJob",
           "glacier:DescribeVault",
           "glacier:GetDataRetrievalPolicy",
           "glacier:GetVaultAccessPolicy",
           "glacier:GetVaultLock",
           "glacier:GetVaultNotifications",
           "glacier:ListJobs",
           "glacier:ListMultipartUploads",
           "glacier:ListParts",
           "glacier:ListTagsForVault",
           "glacier:ListVaults",
           "iam:Get*",
           "iam:List*",
           "inspector:Describe*",
           "inspector:Get*",
           "inspector:List*",
           "iot:Describe*",
           "iot:Get*",
           "iot:List*",
           "kafka:DescribeCluster",
           "kafka:DescribeClusterV2",
           "kafka:DescribeVpcConnection",
           "kafka:ListClientVpcConnections",
           "kafka:ListClusters",
           "kafka:ListClustersV2",
           "kafka:ListNodes",
           "kafka:ListTagsForResource",
           "kafka:ListVpcConnections",
           "kinesis:Describe*",
           "kinesis:DescribeStream",
           "kinesis:DescribeStreamConsumer",
           "kinesis:DescribeStreamSummary",
           "kinesis:ListShards",
           "kinesis:ListStreamConsumers",
           "kinesis:ListStreams",
           "kinesis:ListTagsForStream",
           "kms:Describe*",
           "kms:Get*",
           "kms:List*",
           "lambda:Get*",
           "lambda:List*",
           "logs:Describe*",
           "logs:Get*",
           "logs:TestMetricFilter",
           "machinelearning:Describe*",
           "machinelearning:Get*",
           "opsworks:Describe*",
           "opsworks:Get*",
           "organizations:ListAccounts",
           "rds:Describe*",
           "rds:ListTagsForResource",
           "redshift:Describe*",
           "redshift:ViewQueriesInConsole",
           "route53:Get*",
           "route53:List*",
           "route53domains:CheckDomainAvailability",
           "route53domains:GetDomainDetail",
           "route53domains:GetOperationDetail",
           "route53domains:ListDomains",
           "route53domains:ListOperations",
           "route53domains:ListTagsForDomain",
           "s3:GetAccelerateConfiguration",
           "s3:GetAnalyticsConfiguration",
           "s3:GetBucket*",
           "s3:GetInventoryConfiguration",
           "s3:GetLifecycleConfiguration",
           "s3:GetMetricsConfiguration",
           "s3:GetReplicationConfiguration",
           "s3:List*",
           "sdb:GetAttributes",
           "sdb:List*",
           "sdb:Select*",
           "ses:Get*",
           "ses:List*",
           "sns:Get*",
           "sns:List*",
           "sqs:GetQueueAttributes",
           "sqs:ListQueues",
           "storagegateway:Describe*",
           "storagegateway:List*",
           "swf:Count*",
           "swf:Describe*",
           "swf:Get*",
           "swf:List*",
           "tag:Get*",
           "trustedadvisor:Describe*",
           "waf-regional:Get*",
           "waf-regional:List*",
           "waf:Get*",
           "waf:List*",
           "wafv2:GetWebACL",
           "wafv2:ListResourcesForWebACL",
           "wafv2:ListTagsForResource",
           "wafv2:ListWebACLs",
           "workspaces:Describe*"
         ],
         "Effect": "Allow",
         "Resource": "*"
       }
     ]
   }
   ```
8. Once you have entered in all of the details and copy and pasted the policy contents into the **Policy Document** section, you can click **Create Policy** to complete the policy creation process.
9. Click your new user in the list and go to the **Managed Policies** header under **Permissions**. Click **Attach Policy**.\
   ![iam-step5.png](https://www.hava.io/hs-fs/hubfs/iam-help/iam-step5.png?width=401\&name=iam-step5.png)
10. Scroll through the policy list until you find custom policy **HAVA-RO-POLICY**. Click the checkbox and then click **Attach Policy**.\
    ![Screen\_Shot\_2016-04-08\_at\_3.35.27\_PM.png](https://www.hava.io/hs-fs/hubfs/Screen_Shot_2016-04-08_at_3.35.27_PM.png?width=1024\&name=Screen_Shot_2016-04-08_at_3.35.27_PM.png)
11. This policy will allow you to import everything needed to create diagrams and basic reports. If you would like the full data available in your reports you can also add these policies to your user:\
    \
    \&#xNAN;*arn:aws:iam::aws:policy/SecurityAudit*

    *arn:aws:iam::aws:policy/job-function/ViewOnlyAccess*<br>
12. Now head back to the Hava homepage and enter the credentials you downloaded earlier to get started!


# AWS Supported Resources

What AWS resources are visualized on Hava interactive cloud diagrams and which ones are not.

Hava imports and visualises the key resources in your AWS Cloud architecture.

Below is a list of the resources visualised. The Resources that do not make up your automated interactive diagrams are listed in the contextual attributes tab, and also visible when viewing the **Hava List View**

### **Visualised Resources**

<table><thead><tr><th width="408">Visualised on Infrastructure View Diagrams</th><th></th></tr></thead><tbody><tr><td>AppSync GraphQL</td><td><img src="/files/3DqXuju7kfnUzBbRu9Dy" alt="" data-size="line"></td></tr><tr><td>Autoscaling Group</td><td><img src="/files/CZrfA59DZ6356cSZLFYl" alt="" data-size="line"></td></tr><tr><td>API Gateway</td><td><img src="/files/mORg1aZPPxEcKuRX2W1i" alt="" data-size="line"></td></tr><tr><td>API Gateway Rest API</td><td><img src="/files/mORg1aZPPxEcKuRX2W1i" alt="" data-size="line"></td></tr><tr><td>Cloudfront Distribution</td><td><img src="/files/miqzlHRB9PkWfe5CKALo" alt="" data-size="line"></td></tr><tr><td>Cloudfront Streaming</td><td><img src="/files/2ZxQTJKskqxDabOe4tEm" alt="" data-size="line"></td></tr><tr><td>Direct Connect Connection</td><td><img src="/files/skkIqvksBUmFIRP1GLak" alt="" data-size="line"></td></tr><tr><td>Directory Service Directory</td><td><img src="/files/b65wous4LH3Zl0UYsxnP" alt="" data-size="line"></td></tr><tr><td>DynamoDB</td><td><img src="/files/Wfr2a1NZsuytK9jw3Db0" alt="" data-size="line"></td></tr><tr><td>EC2 Customer Gateway</td><td><img src="/files/e3EqVF4TCa3jCbZ1QIHK" alt="" data-size="line"></td></tr><tr><td>EC2 Egress Only Internet Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Egress_Only_Internet_Gateway.png" alt="" data-size="line"></td></tr><tr><td>EC2 Instance</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Instance.png" alt="" data-size="line"></td></tr><tr><td>EC2 Internet Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Internet_Gateway.png" alt="" data-size="line"></td></tr><tr><td>EC2 NAT Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Nat_Gateway.png" alt="" data-size="line"></td></tr><tr><td>EC2 Network ACL</td><td><img src="/files/CYc4OPCdvRyLzz7X9opw" alt="" data-size="line"></td></tr><tr><td>EC2 Network Interface</td><td><img src="/files/3orU7dOV4wS8mQKYI3gh" alt="" data-size="line"></td></tr><tr><td>EC2 Route Table</td><td><img src="/files/cHNzhO8wW5W8XQeWe7Ym" alt="" data-size="line"></td></tr><tr><td>EC2 Security Group</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Security_Group.png" alt="" data-size="line"></td></tr><tr><td>EC2 Subnet</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Subnet.png" alt="" data-size="line"></td></tr><tr><td>EC2 Transit Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_Transit_Gateway.png" alt="" data-size="line"></td></tr><tr><td>EC2 VPC</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_VPC.png" alt="" data-size="line"></td></tr><tr><td>EC2 VPC Endpoint</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_VPC_Endpoint.png" alt="" data-size="line"></td></tr><tr><td>EC2 VPC Peering Connection</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_VPC_Peering_Connection.png" alt="" data-size="line"></td></tr><tr><td>EC2 VPN Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EC2_VPN_Gateway.png" alt="" data-size="line"></td></tr><tr><td>ECS Cluster</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_ECS_Cluster.png" alt="" data-size="line"></td></tr><tr><td>ECS Service</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_ECS_Service.png" alt="" data-size="line"></td></tr><tr><td>ECS Task</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_ECS_Task.png" alt="" data-size="line"></td></tr><tr><td>EFS File System</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_EFS_File_System.png" alt="" data-size="line"></td></tr><tr><td>ElastiCache Cache Node</td><td><img src="/files/K0pZY08ZtogTdCBebYt5" alt="" data-size="line"></td></tr><tr><td>ElastiCache Cache Subnet Group</td><td><img src="/files/GtBGba7O01DcjJZ1vdZd" alt="" data-size="line"></td></tr><tr><td>Elastic Beanstalk</td><td><img src="/files/-M7ur5JEuZqaToKsU4Fq" alt="" data-size="line"></td></tr><tr><td>ELB Application Load Balancer</td><td><img src="/files/XO0Qr3lwjdhWBE0QT4ew" alt="" data-size="line"></td></tr><tr><td>ELB Classic Load Balancer</td><td><img src="/files/qt5C9SaXEdCts1s3slqV" alt="" data-size="line"></td></tr><tr><td>ELB Gateway Load Balancer</td><td><img src="/files/k5IgO40WS6n4i3Y13EI2" alt="" data-size="line"></td></tr><tr><td>ELB Network Load Balancer</td><td><img src="/files/mSFpRJiBhNrDK2ucPmT1" alt="" data-size="line"></td></tr><tr><td>EventBridge Bus</td><td><img src="/files/sI7gQCmZ5JNIFieZZDJ1" alt="" data-size="line"></td></tr><tr><td>Firehose DeliveryStream</td><td><img src="/files/FllVtdVZU4aNSh5635Wv" alt="" data-size="line"></td></tr><tr><td>Glacier Vault</td><td><img src="/files/iaGze06sTXEdgBzh37Ur" alt="" data-size="line"></td></tr><tr><td>MSK Cluster</td><td><img src="/files/H9Oz1EY3vSr25AaC6Nf6" alt="" data-size="line"></td></tr><tr><td>Kinesis DataStream</td><td><img src="/files/pUe4baOo3xSYGmMTEswJ" alt="" data-size="line"></td></tr><tr><td>Lambda Function</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_Lambda_Function.png" alt="" data-size="line"></td></tr><tr><td>OpenSearch Domain</td><td><img src="/files/Z7nSlvcDSgyJsuwOcuvc" alt="" data-size="line"></td></tr><tr><td>OpenSearch VPC Endpoint</td><td><img src="/files/iizZlsNCTm7g2fOo8eNU" alt="" data-size="line"></td></tr><tr><td>RDS DB Instance</td><td><img src="/files/U8UQTRIQTOZWBJWXGzT2" alt="" data-size="line"></td></tr><tr><td>RDS DB Cluster</td><td><img src="/files/JqSkmQh5KgouqD3OOCbK" alt="" data-size="line"></td></tr><tr><td>RDS DB Proxy</td><td><img src="/files/hJF6MfwYF0aq2YtI2dz0" alt="" data-size="line"></td></tr><tr><td>RDS DB Subnet Group</td><td><img src="/files/JqSkmQh5KgouqD3OOCbK" alt="" data-size="line"></td></tr><tr><td>Redshift Cluster Node</td><td><img src="/files/ACPnfZklZstwnTfFQaOj" alt="" data-size="line"></td></tr><tr><td>Redshift Cluster Subnet Group</td><td><img src="/files/ACPnfZklZstwnTfFQaOj" alt="" data-size="line"></td></tr><tr><td>Route 53 Hosted Zone</td><td><img src="/files/GksqRRHFl1LyT17JRlaS" alt="" data-size="line"></td></tr><tr><td>S3 Bucket</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AWS_S3_Bucket.png" alt="" data-size="line"></td></tr><tr><td>SNS Subscription</td><td><img src="/files/9OCfAda6XLZu1UmWWclS" alt="" data-size="line"></td></tr><tr><td>SNS Topic</td><td><img src="/files/OcLK52aazYUJiTEcsDgO" alt="" data-size="line"></td></tr><tr><td>SQS Queue</td><td><img src="/files/DIf7la3XGtZlcLSPeXe8" alt="" data-size="line"></td></tr><tr><td>WAF Web ACL</td><td><img src="/files/wjDdBBc3cJHKeHLGLQc1" alt="" data-size="line"></td></tr><tr><td>Workspaces Workspace</td><td><img src="/files/Nak4syPDLliUuBgwpnnp" alt="" data-size="line"></td></tr></tbody></table>

Imported Resources not visualised on your Automated Cloud Infrastructure Diagram will appear within the Attributes tab and on the **Hava List View**

### **Non Visualised Resources**

| Non Visualised Resources            |
| ----------------------------------- |
| API Gateway Authorizer              |
| Api Gateway Deployment              |
| API Gateway Domain                  |
| API Key                             |
| API Gateway Method                  |
| API Gateway Model                   |
| API Gateway Resource                |
| API Gateway Stage                   |
| API Gateway Usage Plan              |
| API Gateway VPC Link                |
| Autoscaling Launch Configuration    |
| Direct Connect Gateway              |
| Direct Connect LAG                  |
| Direct Connect Virtual Interface    |
| Directory Service Domain Controller |
| Directory Service Trust             |
| EC2 Container Instance              |
| EC2 DHCP Options                    |
| EC2 Elastic IP                      |
| EC2 Route Table                     |
| EC2 Volume                          |
| EC2 VPN Connection                  |
| ECS Container                       |
| EFS Mount Target                    |
| ElastiCache Cache Cluster           |
| Lambda Layer                        |
| OpenSearch Domain Node              |
| Redshift Cluster                    |
| Route 53 Record Set                 |
| WAF Rules                           |
| Workspaces Directory                |

When Hava creates your diagram it can also display network connections based on the meta data returned with the resource. So long as one resource has an explicit link to another resource, Hava will display a connection when a resource is selected, or using the Connections toggle in the view options.

### Supported Connections

| Supported Connections                         |
| --------------------------------------------- |
| API Gateway to Kinesis Stream                 |
| API Gateway to Lambda function                |
| API Gateway to SQS                            |
| API Gateway REST API to Lambda function       |
| API Gateway REST API to load balancers        |
| AppSync to DynamoDB                           |
| AppSync to Lambda Function                    |
| AppSync to OpenSearch                         |
| AppSync to RDS DBCluster                      |
| AppSync to WAF                                |
| Autoscaling groups to load balancers          |
| CloudFront to Lambda Functions                |
| CloudFront to Load Balancers                  |
| CloudFront to Route53                         |
| CloudFront to S3 Buckets                      |
| CloudFront to WAF                             |
| DirectConnect to Transit Gateway              |
| DirectConnect to VPN Gateway                  |
| EC2 Instance to load balancers                |
| EventBridge to API Gateway REST API           |
| EventBridge to EventBus                       |
| EventBridge to Lambda function                |
| EventBridge to Redshift Cluster               |
| EventBridge to SNS                            |
| EventBridge to SQS                            |
| Firehose DeliveryStream to MSK Cluster        |
| Firehose DeliveryStream to Kinesis DataStream |
| Firehose DeliveryStream to Lambda             |
| Firehose DeliveryStream to OpenSearch         |
| Firehose DeliveryStream to Redshift           |
| Firehose DeliveryStream to S3                 |
| Glacier Vault to SNS Topic                    |
| Lambda function to DynamoDB                   |
| Lambda function to SQS                        |
| Load balancers to WAF                         |
| RDS DB Proxy to RDS Instances                 |
| Route53 to Load Balancers                     |
| S3 to Lambda function                         |
| S3 to SNS                                     |
| S3 to SQS                                     |
| SNS Topic to Lambda function                  |
| SNS Topic to SNS dead letter queues           |
| SNS Topic to SNS subscription                 |
| SNS Topic to SQS queue                        |
| Transit Gateway to Customer Gateway           |
| WAF to API Gateway                            |
| WAF to CloudFront                             |

To view a comprehensive list of the visualised and non visualised resources imported from your cloud infrastructure, use the "List View" function while viewing your interactive diagram :

![Selecting Hava List View](/files/rTOKl1BdoZtYCZ2YF9Xz)

This will detail all of the resources Hava has imported.

![Hava AWS List View Sorted by Price](/files/n4qhP09uMAexa3rolK4Q)


# AWS Views

There are five distinct ways to view your cloud architecture built into Hava.

{% content-ref url="/pages/RIh01UmwWlUUVKVfh7hn" %}
[Infrastructure](/importing/aws/views/infrastructure)
{% endcontent-ref %}

{% content-ref url="/pages/N0XWSe5artg7mpeJKKe6" %}
[Security](/importing/aws/views/security)
{% endcontent-ref %}

{% content-ref url="/pages/uBoT0yVAVCO2ABbI83rB" %}
[List](/importing/aws/views/list)
{% endcontent-ref %}

{% content-ref url="/pages/p2Scs24kZWDzZKsmV42q" %}
[Container - ECS](/importing/aws/views/container-ecs)
{% endcontent-ref %}

They are selectable from the "Select your view" collapsible options box in the bottom right of your diagram view screen.

![Select a View](/files/MqOtTvm7QbKGdFaRyHti)


# Infrastructure

### Infrastructure View

![Hava AWS Architecture View](/files/FRjw0CJD2NlzlPotF0bU)

By default when you open your Cloud Architecture Diagram the "Infrastructure" View will be displayed.

By default, the infrastructure view has no labels or connections displayed. All the example screenshots above are taken from the Infrastructure View.

{% embed url="<https://youtu.be/E0q6AtUo2Fw>" %}

### Extended Infrastructure View

The extended Infrastructure view displays key information relating to the visualised resource.

For instance a Nat Gateway visualised on an **Extended Infrastructure View Diagram** will display the Nat Gateway name and both the public and private IP addresses. A visualised RDS Database will display the Database Identifier, Engine type and allocated storage capacity.

The extended information is contextual to the type of resource being visualised and is typically the most useful parameters a security or solutions architect would need to know.

![Hava AWS Externded Infrastructure View](/files/ovNZCeMbkWZTlrnbVjei)

###


# Security

### Security View

Built with your cloud security engineers in mind, the Security Group View is a visualisation of all the security groups set up within your cloud architecture. It details the ports configured for use and resulting traffic flow.

![AWS Security Group Diagram - Auto Generated](/files/DrgpMhiaRUmGe1D68a1c)

Selecting a security group in the visualisation will populate the connected resources for that group in the Attributes Tab to the right.

The attribute data also details the ingress and egress IP addresses, ports in use and port types.

{% embed url="<https://youtu.be/E0q6AtUo2Fw>" %}


# Container - ECS

### Container View

When you have ECS containers configured within your cloud infrastructure and Hava detects them, a "Container View" option will appear in the header toolbar and in the "view selection" dropdown menu.

<figure><img src="/files/iaLDVIARvd6wXMDgpuYn" alt="Picture of Hava automating the visualizing of AWS Security Groups"><figcaption></figcaption></figure>

The Hava container view gives you an overall diagram of your entire ECS cluster. You can see every service and task currently running, any load balancing available to your containers, as well as unused or pending capacity.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_DIag_034.png)

### Service and Capacity Information

The Container View will generally show one main cluster container around one or more service containers, showing the individual services that make up the cluster as well as the tasks running inside.

At the top of the container you can see information about the state of the container as well as it's location, while at the bottom you can see the name and the ID of the service. Clicking anywhere in the service will display all the services attributes in the right hand attributes panel.

Towards the top of the service you will see load balancing information if there are any load balancers connected to your containers. This will show the port and the container the load balancer is connected to for each task. Click the load balancer box to see more information about the target group or class load balancer that is attached.

Each of the tasks running within the service are shown as a hexagonal icon that can be clicked to see the information for the specific task. Tasks are displayed in different styles depending on their current state:

**Green** tasks are running successfully.

**Yellow** tasks are in a pending state, usually starting up or shutting down. You can click the task for more details.

**Dashed** tasks are spare capacity in the service, where the desired count is less than the running count.

### Detailed Resource Information

Clicking on any resource on the diagram will display detailed information about that resources in the attributes bar on the right hand side. This can be used to get more detail on what the diagram is displayed.

From the main cluster you can see what services and tasks are running, as well as the container instances the cluster is spread across. If you are running in an EC2 cluster you will also be able to see the underlying EC2 instances.

From the service you are able to see the task definition it's using as well as deployment and placement information. You can also see a list view of all the tasks running within the services currently, and any load balancing available to those tasks.

In the task attributes you can see the containers running within the task, the container instance it's deployed onto, and the current status of the task.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_DIag_035.png)

{% embed url="<https://youtu.be/E0q6AtUo2Fw>" %}

##

###


# List

List view is an alphabetic list of detected resources Hava has detected in your cloud architecture.

This includes all the resources that are not visualised on the two infrastructure views.

The list view toolbar has the option to sort by Name, Price and Type

![](/files/n4qhP09uMAexa3rolK4Q)

You can select resources in the list and the detailed attributes are displayed in the Attributes Tab.

At a glance, you can also see a cost estimate for the resource.

Some of the unvisualised resources you will find in the **List View** include :

* Elasicache Cluster Nodes
* Network ACLs
* Directory Services
* Workspaces and Workspace Directories
* Storage Volumes
* Elasticache Subnet Groups
* DHCP Options
* Network Interfaces
* WAF Rules

There is a Filter option in the "List View Toolbar" to filter on the type of resource you wish to view.

Place a checkmark next to the resources you wish to view. You can select multiple types.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_030.jpg)

##


# Azure

{% content-ref url="/pages/-M2pjoZn3rk4EADkA8qq" %}
[Getting Started with Azure](/importing/azure/getting-started-with-azure)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZoJfhHsIRN73CC" %}
[Azure Supported Resources](/importing/azure/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/8iddQ8v7bncvhJwDnHI5" %}
[Azure Views](/importing/azure/views)
{% endcontent-ref %}


# Getting Started with Azure

Getting started with Hava interactive network diagrams and Microsoft Azure.

Two methods are available when connecting and importing diagram data from Azure into Hava. Both ways produce the exact information required using Powershell or the Azure Portal.

The first time importing into Hava, you will be presented with a welcome screen with a container displaying "Import your own environments".

![Getting Started with Azure](/files/pSYyfVAQDl2E2LSZeixU)

If you've imported before, there will be a different container, same as the right image below.

![Add Environment](https://codahosted.io/docs/cYayXS-HlE/blobs/bl-qFkqQQ2yp1/876f968c83f712f76bb64a5ee6a5668fb7406795c4ab8bac33ac9dd45a82c1dfc1829d4dd1370e2d6059aa4fdd666a5b85d4a953d7c2d17300c6bed493e5f031f8638733a8dffc730160504abcf1f77230202254264c5ee2d5cfce1cb1ef1bd8a56afc8e)

<figure><img src="/files/4vcXdF7MWLDkNd0TzXEj" alt=""><figcaption><p>Add new environment</p></figcaption></figure>

### 1. Add Environment

Simply click on the button.

### 2. Select Azure

From the left hand menu select Azure.

![](https://codahosted.io/docs/cYayXS-HlE/blobs/bl-f_McExlY1D/f0dae9b9664ed15e7f22c3afac54be6e2988aaab3b119e0dec8d5371207f28dca8dd10757d10ba228475992cef3a22a721109ef38f056f2f0d24f8c93bddd662817236add5d85baa35ac9eca132cbe48a38702401538332b10d30881b59220bdab818323)

<figure><img src="/files/POVyyMULn27Oup28uKH3" alt=""><figcaption></figcaption></figure>

### 3. Create a new Service Principal

Here you will need to create a new Service Principal and retrieve a set of ids and secret keys using Powershell or the Azure Portal at <https://portal.azure.com>.<br>

{% hint style="info" %}
The recommended method to create your credentials is using Powershell. It can be run locally or directly from the Azure Portal, and offers a much simpler approach.
{% endhint %}

* Guide to using Powershell

{% content-ref url="/pages/MsazqyemXpuEpjy8P00p" %}
[Powershell](/importing/azure/getting-started-with-azure/powershell)
{% endcontent-ref %}

* Guide to using the Azure Portal

{% content-ref url="/pages/Ixd2KI6uaes6wxA5ZG43" %}
[Azure Portal](/importing/azure/getting-started-with-azure/azure-portal)
{% endcontent-ref %}

### 4. Import

Once this is complete and the Subscription ID, Tenant ID, Client ID and Secret Key have been populated into Hava simply hit the IMPORT button.<br>

![](https://codahosted.io/docs/cYayXS-HlE/blobs/bl-xbL5l1bsIK/c7f84d39a59e78306e35387d488683c11c4772af9ee52009bddd96b7fc47c1428e64819f2a8298197ded691e7a6cf7e1c53c427a44bf2b3a3fd91d4cd6101ef8d65ef7829a8d46a1ed8e7c1154a01015b92600ff682aef40488d4e3bea2acb29ebb07831)


# Powershell

Creating the required IDs and Keys to import into Hava should only take a couple of minutes. If you run into any trouble, feel free to reach out to us.

{% embed url="<https://www.hava.io/hubfs/hava-azure-import-powershell.mp4?t=1639645096024>" %}
Azure Powershell Video Walkthrough
{% endembed %}

### 1. Launch Powershell

Open the Azure Portal and launch PowerShell from the top menu bar

<figure><img src="/files/OZG9j5AeDUVjB8wBnYqb" alt=""><figcaption></figcaption></figure>

### 2. Create Service Principal

You will need to create a new Service Principal from the command line and a display name. In the below code example, we’ve used HavaServicePrincipal you can edit and choose a name that suits you.

```powershell
$sp = New-AzADServicePrincipal -DisplayName HavaServicePrincipal
```

<figure><img src="/files/s9qqBpo4hhNTMn45PYjR" alt=""><figcaption><p>Create a new Service Principal in Azure</p></figcaption></figure>

### 3. Assign Reader Role

Hava only requires read-only access for most functionality. You can assign the read-only permissions to the Service Principal account using the below command.

If you would also like to automatically detect and import your public kubernetes clusters you can also add the Azure Kubernetes Service Cluster User Rol&#x65;**.**

```powershell
New-AzRoleAssignment -ObjectId $sp.Id -RoleDefinitionName Reader
# This role is optional, but recommened for displaying AKS container views
New-AzRoleAssignment -ObjectId $sp.Id -RoleDefinitionName "Azure Kubernetes Service Cluster User Role"
```

<figure><img src="/files/VK6HC0eU5OPT1f2V0gzY" alt=""><figcaption></figcaption></figure>

### **4. Create the Password**

Once you’ve created the Service Principal and assigned it with a Reader Role, you need to create password credentials to attach to the Service Principal.

{% hint style="warning" %}
The following example `$endDate` is set to expire in 2024. You can set the value to suit and update at a later date if required.
{% endhint %}

```powershell
$startDate = Get-Date
$endDate = Get-Date -Year 2024
$creds = New-AzADSpCredential -StartDate $startDate -EndDate $endDate -ObjectId $sp.Id
```

<figure><img src="/files/GOeqvNW2XO5t8Kp44D36" alt=""><figcaption></figcaption></figure>

### **5. Obtaining the Credentials**

The final step required is to retrieve the necessary credentials to input into Hava.

**Subscription ID**:

```powershell
(Get-AzContext).Subscription.Id
```

**Tenant ID**:

```powershell
(Get-AzContext).Tenant.Id
```

**Client ID**:

```powershell
$sp.AppId
```

**Secret Key**:

```powershell
$creds.SecretText
```

<figure><img src="/files/QB2NTsYFsVB3hTg9Kqp0" alt=""><figcaption></figcaption></figure>

One of the most common reasons we see an import fail due to an authentication error is pasting the credentials in the wrong input field or copied and pasting a trailing (space) when entering the IDs and Secret key. One we are guilty of too :)

### 6. Import in Hava

Once you've populated the input fields with the correct IDs, you can give the Source a familiar name. By default, Hava will use the Subscription ID, which you can update later under the source tab section.

Now hit the IMPORT button and you should start to see Hava importing and generating your automated Azure diagrams.

<figure><img src="/files/GJahQ4yb9VLNohuyRIEq" alt=""><figcaption></figcaption></figure>


# Azure Portal

{% hint style="info" %}
The recommended method to create your credentials is using [Powershell](/importing/azure/getting-started-with-azure/powershell). It can be run locally or directly from the Azure Portal, and offers a much simpler approach.
{% endhint %}

### Using the Azure Portal

There are quite a few steps required to allow Hava to access your Azure resources using the Azure Portal.

To allow Hava to import your Azure account you will need to provide access by creating an Active Directory (Microsoft Entra ID) application and assigning read-only permissions to it. To create Entra ID applications you will need admin access to the Azure account.

### Creating a Microsoft Entra ID (Active Directory) Application

1. Using the search bar in the Azure Portal interface, search for `Entra ID`
2. Click and open Microsoft Entra ID from the search results

<figure><img src="/files/mEaS8LPtNjxJibadRlI7" alt=""><figcaption></figcaption></figure>

1. Select `App Registration` from the left side menu within Azure Active Directory

<figure><img src="/files/VLBFjd9Hfdu49nrzCPsP" alt=""><figcaption></figcaption></figure>

1. Click `+ New registration`

<figure><img src="/files/pTn0drEcPE4xVK4IubkA" alt=""><figcaption></figcaption></figure>

### Register an application

Enter the following details to register the application.

1. Name: `Hava`
2. Application Type: `Web`
3. Redirect URI: `https://app.hava.io/login`
4. Click `Register`

<figure><img src="/files/aSDXtzW3aiuLFWUu415f" alt=""><figcaption></figcaption></figure>

### Assign Roles to the Application

This will step you through adding a role for the application at the subscription level; this will grant Hava access to read everything in your account but not make any changes. You can also apply the access to a specific resource group or groups, or even individual resources - Hava will only draw the resources you give it access to.

1. Using the top search bar, Search for `Subscriptions`
2. Click and open Subscriptions from the search results

<figure><img src="/files/yRQgdHcQmDLKUk3oXCeV" alt=""><figcaption></figcaption></figure>

Select the subscription you would like to assign access to by clicking it.

<figure><img src="/files/QPriab6WUvGhQwGEp0c3" alt=""><figcaption></figcaption></figure>

#### **Add a role assignment**

1\. On the left menu click `Access control (IAM)`

<figure><img src="/files/PhxR1Me5Pk6JDaqgrogF" alt=""><figcaption></figcaption></figure>

\
2\. Click `+ Add`\
3\. Then `Add role assignment`

<figure><img src="/files/aHkpbTIqDt4kHdOpQ9K5" alt=""><figcaption></figcaption></figure>

\
4\. Set role to `Reader`

<figure><img src="/files/ucRIDq2Sb7lbqGGn0CX8" alt=""><figcaption></figcaption></figure>

\
5\. Select - Type in `Hava` now select Hava from the search results, and this should now be added to `Selected members:`<br>

<figure><img src="/files/ldYaPX34DVzhdrBJyx7u" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/hpPFrXEgep3GAqyEaTtT" alt=""><figcaption></figcaption></figure>

6\. Click `Review + Assign`

### Get your parameters to give access to Hava

You will need four separate parameters to give Hava access to your account, first off is the subscription ID.

#### **Subscription ID**

While still in the `Subscriptions` section.

1\. Navigate to `Overview`\
2\. Copy the `Subscription ID` and paste into Hava.

<figure><img src="/files/bhZICU7H4H2BIl4ogiTb" alt=""><figcaption></figcaption></figure>

#### **Application ID and Tenant ID**

1. Search for `Entra ID`
2. Open Microsoft Entra ID
3. Click `App Registrations` from the side menu
4. Click and open `Hava` from the app registration list.

<figure><img src="/files/Hku1ZGhO7T53hddgpkFd" alt=""><figcaption></figcaption></figure>

Here you will find the `Application ID` and `Tenant ID` to copy and paste into Hava.

1\. Application ID\
2\. Directory Tenant ID

<figure><img src="/files/tZap3o6ldwR0W2yOlPYX" alt=""><figcaption></figcaption></figure>

### Create a Secret Key

1. Click on Certificates & secrets

<figure><img src="/files/LXA6IKz58Uf8T6lKiu1k" alt=""><figcaption></figcaption></figure>

1. Add `+ New client secret`

<figure><img src="/files/rAYIpGO4AGjTZs0aHtwF" alt=""><figcaption></figcaption></figure>

1. Description `HavaAccessKey` or any other description you like.
2. Set Expires to `24 Months`
3. Click `Add`

<figure><img src="/files/u5xJowRwviPTLAPISh5c" alt=""><figcaption></figcaption></figure>

6\. Copy and paste the `Secret Key Value` into Hava

<figure><img src="/files/Uj5OwBRYBA9KvVP5ttX7" alt=""><figcaption></figcaption></figure>

In Hava add source, select the Azure tab

<figure><img src="/files/wIpksRqQ6WtXgIhAlTBX" alt=""><figcaption></figcaption></figure>

Field 1 (Subscription ID) - Enter the Azure Subscription ID

Field 2 (Tenant ID) - Enter the Azure Hava App Directory Tenant ID

Field 3 (Client ID) - Enter the Azure Hava Application (Client) ID

Field 4 (Secret Key) - Enter the Azure Hava App Secrets access key **Value**

Choose a project (or set to Default)

Enter a name for the new source

Click Import and the environment import will start.


# Azure Supported Resources

What Azure environment resources are visualized on Hava interactive diagrams and which ones are not.

Hava imports and visualises the key resources in your Azure Cloud architecture.

Below is a list of the resources visualised on your Infrastructure View diagrams. The Resources that do not make up your automated interactive diagrams are listed in the contextual attributes tab, and also visible when viewing the **Hava List View**

<table data-header-hidden><thead><tr><th width="541.6306540288157">Azure Resources Visualised on Hava Infrastructure View Diagrams</th><th></th></tr></thead><tbody><tr><td><strong>Azure Resources Visualised on Hava Infrastructure View Diagrams</strong></td><td></td></tr><tr><td>Application Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Application_Gateway.png" alt="" data-size="line"></td></tr><tr><td>Batch</td><td><img src="/files/vW1txrRFXPbeTUawIHwf" alt="" data-size="line"></td></tr><tr><td>Cognitive Services</td><td><img src="/files/kMH49AmfB44HnwZcgrGZ" alt="" data-size="line"></td></tr><tr><td>Container App</td><td><img src="/files/BPpcyguM9GxjAFfFhpsO" alt="" data-size="line"></td></tr><tr><td>Cosmos DB</td><td><img src="/files/K6PIdkVL3MqR7IPszSAn" alt="" data-size="line"></td></tr><tr><td>Databricks</td><td><img src="/files/je2QbwNELH7xIlt0FJIm" alt="" data-size="line"></td></tr><tr><td>DNS</td><td><img src="/files/jhmWql7q6v5OgNWrBTyO" alt="" data-size="line"></td></tr><tr><td>Event Hub</td><td><img src="/files/UoESHjct8yBNX75077Gd" alt="" data-size="line"></td></tr><tr><td>Express Route</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Express_Route_Circuit.png" alt="" data-size="line"></td></tr><tr><td>Express Route Gateway</td><td><img src="/files/sWcAezIyLvyOujf3Dnfx" alt="" data-size="line"></td></tr><tr><td>Firewall</td><td><img src="/files/-MdR_-AcFCGn6E7GCJAb" alt="" data-size="line"></td></tr><tr><td>KeyVault</td><td><img src="/files/0bDUZbl0oyrILa1XZMSI" alt="" data-size="line"></td></tr><tr><td>Load Balancer</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Load_Balancer.png" alt="" data-size="line"></td></tr><tr><td>Local Network Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Local_Network_Gateway.png" alt="" data-size="line"></td></tr><tr><td>MariaDB</td><td><img src="/files/t7SUErj8stIBeXY02iup" alt="" data-size="line"></td></tr><tr><td>MySQL</td><td><img src="/files/V2uEmZwmR2ZPmMTFiass" alt="" data-size="line"></td></tr><tr><td>NAT Gateway</td><td><img src="/files/VXVMRLAanUVt1NJlEqtc" alt="" data-size="line"></td></tr><tr><td>Network Route</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Route.png" alt="" data-size="line"></td></tr><tr><td>Network Route Table</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Routetable.png" alt="" data-size="line"></td></tr><tr><td>P2S VPN Gateway</td><td><img src="/files/llYccmDtzw9xIheNjiS8" alt="" data-size="line"></td></tr><tr><td>PostgreSQL</td><td><img src="/files/677gBIZ6RJseWbEFYbjS" alt="" data-size="line"></td></tr><tr><td>Private Endpoint</td><td><img src="/files/s145rtfNaU1WHK3GPbsv" alt="" data-size="line"></td></tr><tr><td>Redis Cache</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Redis_Cache.png" alt="" data-size="line"></td></tr><tr><td>Resource Group</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Resource_Group.png" alt="" data-size="line"></td></tr><tr><td>Service Bus</td><td><img src="/files/b5fGIBbC4fYsuSALYUg4" alt="" data-size="line"></td></tr><tr><td>SQL Server</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_SQL_Server.png" alt="" data-size="line"></td></tr><tr><td>Storage Account</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Storage_Account.png" alt="" data-size="line"></td></tr><tr><td>Subnet</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Network_Subnet.png" alt="" data-size="line"></td></tr><tr><td>Virtual Hub</td><td><img src="/files/l0JFi32TDCNIIRYQhYYC" alt="" data-size="line"></td></tr><tr><td>Virtual Machine</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Virtual_Machine.png" alt="" data-size="line"></td></tr><tr><td>Virtual Network</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Virtual_Network.png" alt="" data-size="line"></td></tr><tr><td>Virtual Network Gateway</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Virtual_Network_Gateway.png" alt="" data-size="line"></td></tr><tr><td>Virtual Network Peering</td><td><img src="https://www.hava.io/hubfs/documentation/Icons/AZ_Virtual_Network_Peering.png" alt="" data-size="line"></td></tr><tr><td>Virtual WAN</td><td><img src="/files/Vx4RbvcdI0p8JYkx8u3L" alt="" data-size="line"></td></tr><tr><td>VPN Gateway</td><td><img src="/files/Ahb6xcX8volJNl9aw6uS" alt="" data-size="line"></td></tr><tr><td>VPN Site</td><td><img src="/files/bBFp3gKCHunG8hhp7hui" alt="" data-size="line"></td></tr></tbody></table>

Imported Azure Resources not visualised on your automated cloud infrastructure diagram will appear within the Attributes tab and on the **Hava List View**

| **Non Visualised Resources** |
| ---------------------------- |
| Availability Set             |
| Network Interface            |
| Network Security Group       |
| Public IP                    |
| Virtual Machine Extension    |
| Virtual Machine Scale Set    |

When Hava creates your diagram it can also display network connections based on the meta data returned with the resource. So long as one resource has an explicit link to another resource, Hava will display a connection when a resource is selected, or using the Connections toggle in the view options.

| Supported Connections                            |
| ------------------------------------------------ |
| Batch Account to Batch Pool                      |
| Private Endpoint to Batch Account                |
| Private Endpoint to Redis                        |
| Private Endpoint to PostgreSQL                   |
| Private Endpoint to MariaDB                      |
| Private Endpoint to MySQL                        |
| Private Endpoint to Event Hub                    |
| Private Endpoint to Application Gateway          |
| Private Endpoint to ServiceBus                   |
| Private Endpoint to SQL Server                   |
| Private Endpoint to Storage Account              |
| Virtual Machine to Application Gateway           |
| Virtual Machine to Load Balancers                |
| Virtual Network Gateway to Local Network Gateway |
| Storage Account to Application Gateway           |

To view a comprehensive list of the visualised and non visualised resources imported from your cloud infrastructure, use the "List View" function while viewing your interactive diagram

<figure><img src="/files/5QP5n2ETtNu9dPu4nNnQ" alt=""><figcaption><p>Azure Diagram View Options</p></figcaption></figure>

This will detail all of the Azure resources Hava has imported.

![Azure List View](/files/XWxA1HXU0sGNHNpppGcv)


# Azure Views


# Infrastructure

<figure><img src="/files/VIe8nmFOsrRJhp7Fw8XP" alt="Hava auto generated Azure Architecture Diagram"><figcaption><p>Azure Infrastructure View</p></figcaption></figure>

<figure><img src="/files/U35bq6qXrdSzOoHOUpcP" alt="Hava auto generated extended architecture diagram for Azure"><figcaption><p>Azure Extended Infrastructure View</p></figcaption></figure>


# Azure Security View

Visualise Azure Network Security Groups

Hava auto generates Azure security diagrams.

<figure><img src="/files/ypsMQ0SXXWlrZs0quC8D" alt="Auto generated security group diagram for Azure"><figcaption><p>Hava Azure Security Group Group</p></figcaption></figure>

Each Azure security group is represented by the large blue rectangle and the connected destinations shown horizontally.

Traffic and rules are represented with arrows with the green and red horizontal arrows displaying inbound and outbound rules, ports, protocols and source/destination and the vertical arrows showing traffic between different sources and destinations.

<figure><img src="/files/FmdBIvttjkQ30bSTIDn5" alt=""><figcaption><p>Azure Security Group Rule Diagram</p></figcaption></figure>

With a Network Security Group selected on the diagram the attribute pane to the side of the diagram will show :

* NSG Name
* Region
* Provisioning State
* Inbound Rules
* Outbound Rules
* Connected Network Interfaces
* Connected Subnets


# List

![Azure Auto Generated List View](/files/XWxA1HXU0sGNHNpppGcv)

Shows all the discovered resources in your Azure network whether they have been visualised on the infrastructure diagram or not.

Sort, filter and export a summary of everything running in your Azure environment.


# Google Cloud

{% content-ref url="/pages/-M2pjoZqG\_j8VLGRohDG" %}
[Getting Started with GCP](/importing/google-cloud/getting-started-google-cloud-platform)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZpyuH9bgh1I7wO" %}
[GCP Supported Resources](/importing/google-cloud/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/KMi2RCPMDAzVy6Ds4xXh" %}
[GCP Views](/importing/google-cloud/views)
{% endcontent-ref %}


# Getting Started with GCP

Getting started with Google Cloud Platform.

The first time importing into Hava, you will be presented with a welcome screen with a container displaying "Import your own environments".

![Getting Started with Google Cloud](/files/pSYyfVAQDl2E2LSZeixU)

If you've imported before, there will be a different container, same as the image below.

![](https://codahosted.io/docs/cYayXS-HlE/blobs/bl-qFkqQQ2yp1/876f968c83f712f76bb64a5ee6a5668fb7406795c4ab8bac33ac9dd45a82c1dfc1829d4dd1370e2d6059aa4fdd666a5b85d4a953d7c2d17300c6bed493e5f031f8638733a8dffc730160504abcf1f77230202254264c5ee2d5cfce1cb1ef1bd8a56afc8e)

### 1. Add Environment

Simply click on the ADD ENVIRONMENT button.

### 2. Select Google Cloud

From the left hand menu select Google Cloud.

![](/files/GSKJy969WTVxdVZBDdMC)

### 3. Create A Service Account

To connect to your Google Cloud Platform (GCP) you will need to create a "Read Only Service Account" for your project and download the JSON key file to import into Hava.

{% content-ref url="/pages/0svQmZFbdqeJ9avKVyqC" %}
[Service Account](/importing/google-cloud/getting-started-google-cloud-platform/service-account)
{% endcontent-ref %}

If you are using a shared network from a separate project, you will need to follow the below guide on how to import multiple projects.

{% content-ref url="/pages/l6MFR7l8oiRH7pLQQ7B8" %}
[Import Multiple Projects](/importing/google-cloud/getting-started-google-cloud-platform/import-multiple-projects)
{% endcontent-ref %}

Depending on the service, you may require to enable certain APIs for Hava to access these, you can learn more about this using the below guide.

{% content-ref url="/pages/BdudqRe4Ig9D5PtgJe1F" %}
[Enabling APIs](/importing/google-cloud/getting-started-google-cloud-platform/enabling-apis)
{% endcontent-ref %}


# Service Account

To connect to your Google Cloud Platform (GCP) you will need to create a "Read Only Service Account" for your project and download the JSON key file to import into Hava.

### Create a new service account

Log in to your Google Cloud Console. In the IAM & Admin menu, select "Service Accounts" :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_01.jpg)

Then select "**+Create Service Account**" :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_02.jpg)

Give the account a memorable **service account name** and an optional description :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_03.jpg)

Select **Create**, then in the Select a Role dialogue, Select **Project** and **Viewer**

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_04.jpg)

### Create Service Account Key

On the next page select **+Create Key**

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_05.jpg)

Select the Key Type : **JSON** and **Create**

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_06.jpg)

This will download the private key to your computer.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_GCP_07.jpg)

From the Hava Environments dashboard - select **Add Environments**

![Add a new GCP Environment for Auto Diagram Generation](/files/4vcXdF7MWLDkNd0TzXEj)

In the Import an Environment dialogue, select the Google Cloud Tab and Select Choose File and select the file containing the Private Key JSON file

![Enter the Credential File for GCP and import data to create your diagrams](/files/6y2z01VkAg9HZgqTPLke)

Hava will then connect to your GCP Project, import the resources and create the interactive diagram.


# Minimum IAM Role

### How to Create a Role for Hava (Google Cloud Platform)

This guide explains how to create a **minimal-permission custom IAM role** in Google Cloud for securely importing your resources into **Hava**.

\
The role provides read-only access across supported services, enough for Hava to map your environment without granting modification rights.

***

### Step 1: Create the Policy File

Create a new JSON or YAML file named `resource_importer_role.yaml` (you can also use `.json`).

Paste the following:

```yaml
title: "Resource Importer Role"
description: "Custom role for importing GCP resources"
stage: "GA"
includedPermissions:
- compute.instances.get
- compute.instances.list
- compute.disks.get
- compute.disks.list
- compute.diskTypes.get
- compute.diskTypes.list
- compute.networks.get
- compute.networks.list
- compute.subnetworks.get
- compute.subnetworks.list
- compute.firewalls.get
- compute.firewalls.list
- compute.routes.get
- compute.routes.list
- compute.routers.get
- compute.routers.list
- compute.addresses.get
- compute.addresses.list
- compute.globalAddresses.get
- compute.globalAddresses.list
- compute.forwardingRules.get
- compute.forwardingRules.list
- compute.globalForwardingRules.get
- compute.globalForwardingRules.list
- compute.backendServices.get
- compute.backendServices.list
- compute.regionBackendServices.get
- compute.regionBackendServices.list
- compute.backendBuckets.get
- compute.backendBuckets.list
- compute.healthChecks.get
- compute.healthChecks.list
- compute.regionHealthChecks.get
- compute.regionHealthChecks.list
- compute.httpHealthChecks.get
- compute.httpHealthChecks.list
- compute.httpsHealthChecks.get
- compute.httpsHealthChecks.list
- compute.instanceGroups.get
- compute.instanceGroups.list
- compute.instanceGroupManagers.get
- compute.instanceGroupManagers.list
- compute.autoscalers.get
- compute.autoscalers.list
- compute.urlMaps.get
- compute.urlMaps.list
- compute.regionUrlMaps.get
- compute.regionUrlMaps.list
- compute.targetPools.get
- compute.targetPools.list
- compute.targetInstances.get
- compute.targetInstances.list
- compute.targetHttpProxies.get
- compute.targetHttpProxies.list
- compute.targetHttpsProxies.get
- compute.targetHttpsProxies.list
- compute.targetGrpcProxies.get
- compute.targetGrpcProxies.list
- compute.targetTcpProxies.get
- compute.targetTcpProxies.list
- compute.targetSslProxies.get
- compute.targetSslProxies.list
- compute.regionTargetHttpProxies.get
- compute.regionTargetHttpProxies.list
- compute.regionTargetHttpsProxies.get
- compute.regionTargetHttpsProxies.list
- compute.sslCertificates.get
- compute.sslCertificates.list
- compute.regionSslCertificates.get
- compute.regionSslCertificates.list
- compute.sslPolicies.get
- compute.sslPolicies.list
- compute.vpnGateways.get
- compute.vpnGateways.list
- compute.targetVpnGateways.get
- compute.targetVpnGateways.list
- compute.vpnTunnels.get
- compute.vpnTunnels.list
- compute.externalVpnGateways.get
- compute.externalVpnGateways.list
- compute.interconnects.get
- compute.interconnects.list
- compute.interconnectAttachments.get
- compute.interconnectAttachments.list
- compute.networkEndpointGroups.get
- compute.networkEndpointGroups.list
- compute.globalNetworkEndpointGroups.get
- compute.globalNetworkEndpointGroups.list
- compute.regionNetworkEndpointGroups.get
- compute.regionNetworkEndpointGroups.list
- compute.securityPolicies.get
- compute.securityPolicies.list
- compute.packetMirrorings.get
- compute.packetMirrorings.list
- compute.serviceAttachments.get
- compute.serviceAttachments.list
- compute.nodeGroups.get
- compute.nodeGroups.list
- container.clusters.get
- container.clusters.list
- storage.buckets.get
- storage.buckets.list
- cloudsql.instances.get
- cloudsql.instances.list
- pubsub.topics.get
- pubsub.topics.list
- pubsub.subscriptions.get
- pubsub.subscriptions.list
- run.services.get
- run.services.list
- run.routes.get
- run.routes.list
- run.configurations.get
- run.configurations.list
- run.domainmappings.get
- run.domainmappings.list
- run.jobs.get
- run.jobs.list
- dns.managedZones.get
- dns.managedZones.list
- redis.instances.get
- redis.instances.list
- resourcemanager.projects.get
- compute.regionHealthCheckServices.list
- compute.regionNotificationEndpoints.list
- resourcemanager.projects.getIamPolicy
- compute.regions.list
- compute.zones.list
```

Save the file in your working directory.

***

### Step 2: Create the Custom Role in GCP

You can create the role **at the project or organization level**.

#### Option A — Create at the Project Level

Run:

```bash
gcloud iam roles create resourceImporter \
  --project=YOUR_PROJECT_ID \
  --file=resource_importer_role.yaml
```

#### Option B — Create at the Organization Level

If you want the same role available across all projects:

```bash
gcloud iam roles create resourceImporter \
  --organization=YOUR_ORG_ID \
  --file=resource_importer_role.yaml
```

This creates a reusable, read-only “Resource Importer” role.

***

### Step 3: Assign the Role to Your Hava Service Account

Replace the placeholders and run:

```bash
gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \
  --member="serviceAccount:hava-import-service-account@YOUR_PROJECT_ID.iam.gserviceaccount.com" \
  --role="projects/YOUR_PROJECT_ID/roles/resourceImporter"
```

Or if you created it at the org level:

```bash
gcloud organizations add-iam-policy-binding YOUR_ORG_ID \
  --member="serviceAccount:hava-import-service-account@YOUR_PROJECT_ID.iam.gserviceaccount.com" \
  --role="organizations/YOUR_ORG_ID/roles/resourceImporter"
```

***

### Step 4: Enable Required APIs

Hava can only import resources from APIs that are **enabled**.\
At minimum, enable these services:

```bash
gcloud services enable \
  compute.googleapis.com \
  sqladmin.googleapis.com \
  storage.googleapis.com \
  pubsub.googleapis.com \
  run.googleapis.com \
  dns.googleapis.com \
  redis.googleapis.com \
  container.googleapis.com \
  cloudresourcemanager.googleapis.com
```

***

### Step 5: Connect to Hava

Once the service account is ready and the APIs are enabled:

1. Download the service account key (JSON).
2. In **Hava → Integrations → Google Cloud**, upload the key.
3. Hava will automatically begin mapping your resources.


# Import Multiple Projects

How to Import Multiple GCP Projects using the same Service Account.

Hava has support for importing multiple projects using the same service account, provided the account has access to them.

**The first step is to make sure the necessary API is enabled.**

Navigate to your GCP account API library and enable - "Cloud Resource Manager API"

**Give your service account access to other projects.**

If your service account can access the resource manager API and has access to other projects, then Hava will automatically import them.

One way to achieve this is to manually add your service account as a member for other projects.

* Select the project you want to add access to from the drop-down menu at the top of your GCP console.
* Navigate to "IAM & Admin" > IAM
* Click "Add" at the top of the page
* In the "New Members" field, add the email address of your Hava service account
* Make sure the new member has the "Project Viewer" role
* Save

Now you can manually sync, or wait for the next auto import and you will see resources for both projects.

{% hint style="info" %}
Please note: Although you can add as many GCP projects as you want to each service account, the more you add, the longer each import will take. If your projects are especially large and the import takes more than an hour, the import may time out.

It may be better to create multiple service accounts and then use the [search/custom](https://docs.hava.io/features/defining-custom-environments) diagrams function to create diagrams with resources from both projects.
{% endhint %}


# Enabling APIs

If you are not seeing all the resources you were expecting, it may be possible that a related or required API is not enabled in your projects.

Please ensure the following APIs are enabled in your GCP account:

* Cloud DNS API
* Cloud Functions API
* Cloud Pub/Sub API
* Cloud Resource Manager API
* Cloud Run
* Cloud SQL
* Cloud Storage
* Compute Engine API
* Container Registry API
* Google Cloud Memorystore for Redis API
* Kubernetes Engine API

These will need to be enabled for each project you wish to import.

This can done manually via the [Google Cloud Console](https://console.cloud.google.com/apis) or you can run the following commands in the CLI:

```
gcloud services enable cloudfunctions.googleapis.com \
  cloudresourcemanager.googleapis.com \
  compute.googleapis.com \
  container.googleapis.com \
  containerregistry.googleapis.com \
  dns.googleapis.com \
  pubsub.googleapis.com \
  redis.googleapis.com \
  run.googleapis.com \
  sql-component.googleapis.com \
  storage-component.googleapis.com
```

Once these are enabled, perform a manual sync and the resources will be added to your diagrams.

You can follow the below guide if you're unsure how to perform a manual sync.

{% content-ref url="/pages/-M-lsaBlWdE0i5Pb3MIG" %}
[Manual Sync](/discover/manual-sync)
{% endcontent-ref %}

###


# GCP Supported Resources

Which Google Cloud resources are visualized on Hava interactive network topology diagrams.

Hava imports and visualises the key resources in your GCP Cloud Infrastructure projects.

Below is a list of the resources visualised. The resources that are not visualised can be found in the contextual attributes tab and are also visible when viewing the Hava List View

| Resources Visualised    |                                                                                                                      |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------- |
| Compute Backend Service | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Backendservice.png" alt="" data-size="line">     |
| External VPN Gateway    | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_ExternalVpnGateway.png" alt="" data-size="line"> |
| Compute Instance        | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Instance.png" alt="" data-size="line">           |
| Compute Interconnect    | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Interconnect.png" alt="" data-size="line">       |
| Compute Nat Gateway     | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Natgateway.png" alt="" data-size="line">         |
| Compute Network         | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Network.png" alt="" data-size="line">            |
| Compute Router          | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Router.png" alt="" data-size="line">             |
| Compute Subnetwork      | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Subnetwork.png" alt="" data-size="line">         |
| Compute URL Map         | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_Urlmap.png" alt="" data-size="line">             |
| VPN Gateway             | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Compute_VpnGateway.png" alt="" data-size="line">         |
| DNS Managed Zone        | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Dns_Managedzone.png" alt="" data-size="line">            |
| Memory Store Instance   | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Memorystore_Instance.png" alt="" data-size="line">       |
| SQL Instance            | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Memorystore_Instance.png" alt="" data-size="line">       |
| Storage Bucket          | <img src="https://www.hava.io/hubfs/documentation/Icons/GCP_Storage_Bucket.png" alt="" data-size="line">             |
| Cloud Run Service       | <img src="/files/BsxjxZI5L8ReSzT3s1xg" alt="" data-size="line">                                                      |
| PubSub Topic            | <img src="/files/OtFk1cIphpA4EVVcGawv" alt="" data-size="line">                                                      |
| PubSub Subscription     | <img src="/files/Q7tKVmYXqrfIpr4QgwUD" alt="" data-size="line">                                                      |

Imported resources not visualised on your automated interactive cloud infrastructure diagram will appear within the attributes tab and on the Hava List View

| Non Visualised Resources |
| ------------------------ |
| Compute Address          |
| Compute Autoscaler       |
| Compute Backend Bucket   |
| Disk                     |
| Firewall                 |
| Forwarding Rule          |
| Forwarding Rule Targets  |
| Instance Group           |
| Interconnect Attachment  |
| Network Endpoint Group   |
| Node Group               |
| Packet Mirroring         |
| Route                    |
| Security Policy          |
| SSL Certificate          |
| SSL Policy               |
| VPN Tunnel               |

When Hava creates your diagram it can also display network connections based on the meta data returned with the resource. So long as one resource has an explicit link to another resource, Hava will display a connection when a resource is selected, or using the Connections toggle in the view options.

| Supported Connections                      |
| ------------------------------------------ |
| Backend Service to Instances               |
| Backend Service to Cloud Run               |
| External VPN Gateway to Target VPN Gateway |
| External VPN Gateway to VPN Gateway        |
| Router to NAT Gateway                      |
| Router to Interconnect                     |
| Pub/Sub to Cloud Run                       |
| URL Map to Bucket                          |
| URL Map to Backend Service                 |
| URL Map to Instances                       |
| Target Pool to Instances                   |

To view a comprehensive list of the visualised and non visualised resources imported from your GCP Project, use the "List View" while viewing your interactive diagram.

<figure><img src="/files/-MQBPM0OZbVbPnK79geI" alt="Diagram showing the different GCP Diagram types available in Hava"><figcaption><p>Hava GCP View Options</p></figcaption></figure>

<figure><img src="/files/Hu7FpFyKe2q7IwkDBfPa" alt="List View showing GCP resources"><figcaption><p>Hava GCP List View</p></figcaption></figure>

New resources are being added to Hava automated interactive diagrams all the time. Make sure to check back on your diagrams regularly. The diagrams poll your source data continuously and automatically update diagrams and record any changes in the **Version History** as they happen.


# GCP Views


# Infrastructure

### Infrastructure View

By default, the infrastructure view has no labels or connections displayed. All the example screenshots below are taken from the Infrastructure View.

![Google Cloud Infrastructure Diagram - no names or connections](/files/giy1nuzGiqmldNIC3k47)

### You can optionally display names and connections.

<figure><img src="/files/BShe23TU60vQtAFABGed" alt=""><figcaption><p>GCP Infrastructure Diagram Display Options - Diagram shows names and connections and is zoomed in</p></figcaption></figure>

### Extended Infrastructure View

The extended Infrastructure view displays key information relating to the visualised resource.

![Google Cloud Extended Infrastructure Diagram](/files/wAkoL2uWoQRbcr2zvQbd)


# List

![Google Cloud List View](/files/Hu7FpFyKe2q7IwkDBfPa)

This view shows all the resources discovered when syncing your Google Cloud config. List view will detail resources and components that may not be shown on the infrastructure view due to the nature of the resource.


# Kubernetes

{% hint style="warning" %}
Kubernetes import is in private beta at the moment

if you are interested in testing this out, please reach out to the support team, and we will enable it on your account
{% endhint %}

{% content-ref url="/pages/1H5rpnlqfmxwvSRjLK7y" %}
[Getting Started with Kubernetes](/importing/kubernetes/getting-started-with-kubernetes)
{% endcontent-ref %}


# Getting Started with Kubernetes

Connecting your Kubernetes clusters to Hava

{% hint style="warning" %}
Kubernetes import is in private beta at the moment

if you are interested in testing this out, please reach out to the support team, and we will enable it on your account
{% endhint %}

The first time importing into Hava, you will be presented with a welcome screen with a container displaying "Import your own environments".

![Getting Started with Google Cloud](/files/pSYyfVAQDl2E2LSZeixU)

If you've imported before, there will be a different container, same as the image below.

![](https://codahosted.io/docs/cYayXS-HlE/blobs/bl-qFkqQQ2yp1/876f968c83f712f76bb64a5ee6a5668fb7406795c4ab8bac33ac9dd45a82c1dfc1829d4dd1370e2d6059aa4fdd666a5b85d4a953d7c2d17300c6bed493e5f031f8638733a8dffc730160504abcf1f77230202254264c5ee2d5cfce1cb1ef1bd8a56afc8e)

### 1. Add Environment

Simply click on the ADD ENVIRONMENT button.

### 2. Select Kubernetes

From the left hand menu select Kubernetes.

![](/files/i1ekvBRUYHEBLryu7XJn)

### Create a Kubeconfig File

To connect to your Kubernetes cluster you will need to obtain a copy of your existing kubeconfig, or create one.

We recommend creating a new read-only service account for Hava to access your cluster. Follow the link below for a guide on how to set that up.

{% content-ref url="/pages/CL4BVF6mn0JvwMr6MVC6" %}
[Read Only Kubeconfig](/importing/kubernetes/getting-started-with-kubernetes/read-only-kubeconfig)
{% endcontent-ref %}

### Automatic Detection of Managed Clusters

Hava also supports automatic detection and import of your managed clusters running in AWS, Azure, and GCP. As long as your source has the permissions to access the cluster and the Kubernetes API is public Hava will create and import Kubernetes sources for you.

For more details on how to configure your source for automatic imports follow the steps in the following guide.

{% content-ref url="/pages/FLHUb19CQCahvyxZdUf3" %}
[Automatic Import of Managed Kubernetes](/importing/kubernetes/getting-started-with-kubernetes/automatic-import-of-managed-kubernetes)
{% endcontent-ref %}


# Read Only Kubeconfig

Guide to set up a new Service Account with Read only access to a K8s cluster

{% hint style="warning" %}
Kubernetes import is in private beta at the moment

if you are interested in testing this out, please reach out to the support team, and we will enable it on your account
{% endhint %}

To connect to your Kubernetes clusters you will need to create or obtain a copy of your [kubeconfig](https://kubernetes.io/docs/concepts/configuration/organize-cluster-access-kubeconfig/) configuration and import it into Hava.

We recommend creating a new service account that has read only access to the resources in the kubernetes cluster, and use that to provide access to Hava.

### Supported kubeconfig authentication methods

Hava does not support authentication methods that require access to external files or programs, such as use of the `client-certificate` or `cmd-path` values in your users section, or the `certificate-authority` value in the clusters section.

If you make use of certificate files you can [convert them to the corresponding -data fields](/importing/kubernetes/getting-started-with-kubernetes/converting-certificate-files-to-certificate-data-fields).

Unfortunately there is no replacement for `cmd-path` and `cmd-arg` values.

### Creating a read-only kubeconfig access file

The best practice when creating a kubeconfig file for Hava is to create a new read-only role that can be attached to a service account for Hava to access. We'll also create it in a separate 'hava' namespace so that removing access is as simple as removing the namespace.

#### Creating the role and service account

We'll use the following manifest to create the role and service account in your current context using kubectl, so make sure you have the correct context selected by running `kubectl config current-context`.

Create the following file as `hava-role-manifest.yml`:

```
---
kind: Namespace
apiVersion: v1
metadata:
  name: hava
  labels:
    name: hava
---
apiVersion: v1
kind: ServiceAccount
metadata:
  name: hava-reader
  namespace: hava
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  annotations:
    rbac.authorization.kubernetes.io/autoupdate: "true"
  labels:
  name: hava-read-only
  namespace: hava
rules:
  - apiGroups:
      - ""
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
  - apiGroups:
      - extensions
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
  - apiGroups:
      - apps
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: hava-reader-binding
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: hava-read-only
subjects:
  - kind: ServiceAccount
    name: hava-reader
    namespace: hava
```

Now run `kubectl apply -f hava-role-manifest.yml` to create your role and service account.

This will allow Hava access to read data from all resource types across all namespaces. If this is still too open you can lock it down further by limiting it by namespace or resource types - Hava will ignore anything it doesn't have access to.

#### Use the service account details to create your kubeconfig

You can now run the following shell script to output a kubeconfig configuration file to allow Hava to access and import your cluster:

{% hint style="info" %}
This script depends on`kubectl`, `jq`, and `base64`

It has been tested on MacOS, `jq` and `base64` might require slight modifications to the commands on linux and Windows
{% endhint %}

```
#!/bin/bash

server=$(kubectl config view --minify --output jsonpath='{.clusters[*].cluster.server}')
name=$(kubectl get secrets --namespace=hava -o json | jq -r '.items[] | select(.metadata.name | test("hava-reader-token-")).metadata.name')
ca=$(kubectl get secret/$name --namespace=hava -o jsonpath='{.data.ca\.crt}')
token=$(kubectl get secret/$name --namespace=hava -o jsonpath='{.data.token}' | base64 --decode)
namespace=$(kubectl get secret/$name --namespace=hava -o jsonpath='{.data.namespace}' | base64 --decode)

echo "
apiVersion: v1
kind: Config
clusters:
- name: default-cluster
  cluster:
    certificate-authority-data: ${ca}
    server: ${server}
contexts:
- name: default-context
  context:
    cluster: default-cluster
    namespace: default
    user: default-user
current-context: default-context
users:
- name: default-user
  user:
    token: ${token}
" > hava-kubeconfig.yml
```

After running this you can now upload the `hava-kubeconfig.yml` file into Hava and click 'Import'.

![](/files/obmXT1yFefWMY1X1rKsD)

Hava will connect to your environment and pull back the resources and relationships between them and build a complete visualisation of your environment.


# Automatic Import of Managed Kubernetes

Guide to configure your source to automatically import your managed Kubernetes clusters

If you host your Kubernetes clusters in AWS, Azure, or GCP you don't need to generate your config from scratch. If your cluster API is public and your credentials allow access then Hava can generate and import for you automatically.

Once the cluster configuration has been created it will be listed as a sub-source of the primary source it's linked to. When the primary source is updated, your cluster resources will also be synced and your diagrams generated. If the cluster is ever removed the source will automatically be removed as well.

![](/files/IljdvgWcjLLn7B3snyba) ![Once your credentials are loaded they will show up as an expandable list under your main source](/files/YTZIDOUAlXhKdfxihsV8)

### AWS (EKS)

Unfortunately AWS IAM does not support giving a role or user access to the EKS clusters from the parent account, so a config change has to be added to each cluster. To allow Hava access to your EKS clusters you need to make sure that the user or role you use to import in Hava is added to the `mapUsers` section in your `aws-auth` ConfigMap within the cluster.

{% content-ref url="/pages/8kbW6s4W3O67eEYJqCy2" %}
[AWS EKS Cluster Configuration](/importing/kubernetes/getting-started-with-kubernetes/automatic-import-of-managed-kubernetes/aws-eks-cluster-configuration)
{% endcontent-ref %}

### Azure (AKS)

To import your AKS clusters you'll simply need to add a role to the Service Principle you've used to import your data in Hava. This step is in the [Powershell](/importing/azure/getting-started-with-azure/powershell) instructions too, but if you created your SP before support was added you simply need to log into Powershell in the Azure Portal and run the following commands:

```
$sp = Get-AzADServicePrincipal -DisplayName <hava-service-principal-name>
New-AzRoleAssignment -ObjectId $sp.Id -RoleDefinitionName "Azure Kubernetes Service Cluster User Role"
```

Once you've added this role simply re-sync your source in Hava to see container diagrams of your public AKS clusters.

### GCP (GKE)

With the default Project Reader role your GKE clusters should be ready to import right away! So long as the cluster is public, or you allow access to your control plane via an external IP address, you should begin to see your clusters once your GCP source is imported.

If you have a limited access service account you just need to make sure you add the **Kubernetes Engine Viewer** role to your service account.


# AWS EKS Cluster Configuration

Guide for configuring AWS EKS for Hava

Unfortunately AWS IAM does not support giving a role or user access to the EKS clusters from the parent account, so a config change has to be added to each cluster. This guide will step you through setting up a clusterrole with the appropriate access, binding it to a Kubernetes group, and connecting it to an AWS role for access using AWS IAM.

In this guide we use `eksctl` to apply changes to the aws-auth config map, you can do this directly as well if you don't have `eksutil` installed. See [Enabling IAM user and role access to your cluster](https://docs.aws.amazon.com/eks/latest/userguide/add-user-role.html) for more information about modifying aws-auth

## 1. Create a read-only cluster role

First we will create a new read-only cluster role and bind it to a group called `hava-ro`, which we will use later.

The below yaml manifest will set up the role and the binding, download it and apply it to your kubernetes cluster using kubectl

`kubectl apply -f <file name>`

```yaml
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  annotations:
    rbac.authorization.kubernetes.io/autoupdate: "true"
  labels:
  name: hava-ro
rules:
  - apiGroups:
      - ""
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
  - apiGroups:
      - extensions
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
  - apiGroups:
      - apps
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
  - apiGroups:
      - networking.k8s.io
    resources: ["*"]
    verbs:
      - get
      - list
      - watch
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: hava-ro
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: hava-ro
subjects:
- apiGroup: rbac.authorization.k8s.io
  kind: Group
  name: hava-ro
```

## 2. Update cluster auth configuration

Next we will use eksctl to update the aws-auth config map to allow your role used for cross account access to the cluster.

Make sure you are logged in to an AWS user that has access to the cluster, and run the following command.

`eksctl create iamidentitymapping --cluster <cluster name> --region=<region name> --arn <cross account role arn> --group hava-ro --username hava-ro`

Replace:

\<cluster name> with the name of the cluster you are updating

\<cross account role arn> is the ARN of the role you provide to Hava to import your data

\<region name> with the name of the cluster

## 3. Trigger sync on your source

Last thing to do is to trigger the synchronization for the source in the hava UI, to import your Kubernetes information and draw a container diagram for your EKS cluster


# Converting certificate files to certificate data fields

{% hint style="warning" %}
Kubernetes import is in private beta at the moment

if you are interested in testing this out, please reach out to the support team, and we will enable it on your account
{% endhint %}

Hava does not support accessing external files within your kubeconfig for authentication using client certificates. Luckily, it's a simple process to convert these to data fields that can be entered directly into your configuration.

The fields that will need to be converted are:

* `certificate-authority` to become `certificate-authority-data`
* `client-certificate` to become `client-certificate-data`
* `client-key` to become `client-key-data`

### Finding and converting the files

For this example we have the following kubeconfig using local certificates files.

```
apiVersion: v1
kind: Config
preferences: {}
clusters:
  - cluster:
      certificate-authority: /Users/example/ca.crt
      server: https://kubeserver:8443
    name: kube
contexts:
  - context:
      cluster: kube
      user: kube
    name: kube
users:
  - name: kube
    user:
      client-certificate: /Users/example/client.crt
      client-key: /Users/example/client.key
```

For each of these external files we need to convert them to base64 and then update the configuration with the base64 string.

Here's an example using the certificate authority file:

#### Linux and MacOS

`cat /Users/example/ca.crt | base64`

#### Windows

`certutil -f -encode "c:/Users/example/ca.crt" "output-file"`

### Update the config to use the new values

Once you've got the base64 data for all 3 values you can update the config file.

```
apiVersion: v1
kind: Config
preferences: {}
clusters:
  - cluster:
      certificate-authority-data: <base64 ca.crt>
      server: https://kubeserver:8443
    name: kube
contexts:
  - context:
      cluster: kube
      user: kube
    name: kube
users:
  - name: kube
    user:
      client-certificate-data: <base64 client.crt>
      client-key-data: <base64 client.key>
```

Your configuration is now ready to import into Hava to connect and display your Kubernetes clusters!


# Kubernetes Supported Resources

What Kuberentes resources are visualized on Hava interactive cloud diagrams and which ones are not.

Hava imports and visualises the key resources in your Kubernetes cluster.

Below is a list of the resources visualised. The Resources that do not make up your automated interactive diagrams are listed in the contextual attributes tab, and also visible when viewing the **Hava List View.**

| Visualised on Container View Diagrams |                                                                 |
| ------------------------------------- | --------------------------------------------------------------- |
| Cluster                               | <img src="/files/aka8dJjJyr6kzt0oN4Dg" alt="" data-size="line"> |
| Daemon Set                            | <img src="/files/No6xIAevk2MWA8euKMMY" alt="" data-size="line"> |
| Deployment                            | <img src="/files/ZDzaC7qJtwrenKCM2WPA" alt="" data-size="line"> |
| Ingress                               | <img src="/files/dTBl4HEjaImFr6PYDVxd" alt="" data-size="line"> |
| Namespace                             | <img src="/files/yOEqHByQ0HY2uYI5XyNw" alt="" data-size="line"> |
| Pod                                   | <img src="/files/expUndDUkgx9bSpt0gle" alt="" data-size="line"> |
| Replica Set                           | <img src="/files/AyJDljatdruSU40g0b1F" alt="" data-size="line"> |
| Service                               | <img src="/files/a21iQ84juPG0WqIZSG2n" alt="" data-size="line"> |
| Stateful Set                          | <img src="/files/pw5szby2Bbl8f8vx4arn" alt="" data-size="line"> |

Imported Resources not visualised on your Container Diagram will appear within the Attributes tab and on the **Hava List View**

| Non Visualised Resources |                                                                 |
| ------------------------ | --------------------------------------------------------------- |
| Node                     | <img src="/files/XVqcjCY5GYsu5S5FsHlO" alt="" data-size="line"> |
| Persistent Volume        | <img src="/files/qazq3VtjGrdYuOpLHIEq" alt="" data-size="line"> |
| Persistent Volume Claim  | <img src="/files/T6wwElIBK6zbDILaFpTj" alt="" data-size="line"> |


# Kubernetes Views

{% content-ref url="/pages/q7QJYGmqdlsIDftPOCdw" %}
[Container](/importing/kubernetes/kubernetes-views/container)
{% endcontent-ref %}

{% content-ref url="/pages/iPHi9T2qRdACW55LzxVM" %}
[List](/importing/kubernetes/kubernetes-views/list)
{% endcontent-ref %}


# Container

The Hava container view for your Kubernetes cluster

The Hava container view gives you an overall diagram of your entire Kubernetes cluster. You can see every workload and pod currently running and the namespace they are in, any services or ingress available to your containers, as well as unused or pending capacity.

![](/files/oSAMFEw8xxTerdpV7qQZ)

### Service and Capacity Information

The Container View will generally show one main cluster container around one or more namespace containers. Within the namespace containers it will display any services and ingress rules as a row along the top, followed by any workloads and their pods.

Clicking on a service or ingress resource at the top of the namespace will show it's attributes in the right hand panel and will draw a connection to any linked pods on the diagram.

Clicking on the cluster container on the diagram will display a list of all the workloads contained within the cluster, as well as the nodes the cluster is running on. Hovering over the node name will highlight all the pods currently deployed on that node.

![Higlighted pods currently running on the selected node](/files/a6Z2tmCrDd9THBfRnuja)

Each of the pods running within the workloads are shown as a hexagonal icon that can be clicked to see the information for the specific pod. Pods are displayed in different styles depending on their current state:

**Green** pods are running successfully.

**Yellow** pods are in a pending state, usually starting up or shutting down. You can click the pods for more details.

**Red** pods are in a failed state, usually because of an issue in initialization. You can click the pod for more details.

**Dashed** pods are spare capacity in the workload, where the desired count is less than the running count.

### View Options

By clicking the dropdown at the top right of the diagram you can see options for how you wish your view displayed. For the Kubernetes container view there is also an option to hide default namespaces that is enabled by default.

![](/files/4VCBGEZokoPf8gD8VgPi)

Toggling this option will show or hide the default Kubernetes namespaces, such as kube-system. This allows the diagrams to represent only the resources you manage and deploy. This option carries across in exports as well.


# List

The Kubernetes list view gives you a sortable list of all the resources currently running in your Kubernetes cluster.

This includes all the resources that are not visualised on the container view.

![The Kubernetes list view](/files/adP3x8cdOvt5usnSKTTM)


# Import Errors

Here are some common import errors and the reasons behind them

When importing your resources into Hava you may get a notification saying that problems were found in your import. These messages come in two different severity levels:

* **Warning**: these are for your information only and generally mean your import completed successfully.
* **Error**: these are notifications that something has gone wrong and your import has not completed.

### **Warnings** <a href="#hardbreak-warnings" id="hardbreak-warnings"></a>

Warnings are usually reported when Hava encounters permission errors with a specific region or service related to your import. It means that your credentials don't provide the correct access to import the information, but Hava has skipped over it and continued the import.

To stop the warnings being displayed for your account you can add more permissions to your credentials, or you can safely ignore the warnings.

{% hint style="info" %}
Resources that do not have sufficient permissions to access and generate a warning will be omitted from your automatically generated diagrams.
{% endhint %}

### **Errors** <a href="#errors" id="errors"></a>

Errors are reported when Hava has encountered a critical problem and had to terminate the import without saving any of the changes. Sometimes this is an issue with your credentials and you'll need to edit them to get your import working.

Sometimes the error relates to a problem communicating with the remote server and your import will be retried.

### Some common errors:

#### Failed to authenticate. <a href="#failed-to-authenticate" id="failed-to-authenticate"></a>

This is the most common error and usually means that the data source credentials you’ve provided are incorrect. Your import will be re-queued to retry, but if it continues to fail the import will terminate.

You can edit your source by clicking ‘Sources’ on the main menu, and then using the ‘cog’ icon to edit your credentials.

![Edit credentials for a connected cloud account](/files/o2TFrqffQXEFz8OpnybK)

#### &#x20;<a href="#there-was-a-remote-error-and-your-import-is-being-restarted" id="there-was-a-remote-error-and-your-import-is-being-restarted"></a>

<figure><img src="/files/YvQzuqPVaygiIKgcEYUF" alt=""><figcaption></figcaption></figure>

#### There was a remote error and your import is being restarted. <a href="#there-was-a-remote-error-and-your-import-is-being-restarted" id="there-was-a-remote-error-and-your-import-is-being-restarted"></a>

This means there was a network error, a remote server error, or some other problem that means the import couldn’t continue. It will be re-queued and imported again shortly.

#### **Your import has been taking a long time - it's been moved to a dedicated queue.** <a href="#your-import-has-been-taking-a-long-time-its-been-moved-to-a-dedicated-queue" id="your-import-has-been-taking-a-long-time-its-been-moved-to-a-dedicated-queue"></a>

If you have a very large source with tens of thousands of resources it can spend so long in the queue that it ends up being moved to a dedicated queue. This is so that the import has access to more resources and a longer timeout. This means that your source could potentially take over an hour to import - but it will finish!

If you want to lower the time that your source takes to import you can prevent access to services that you don’t necessarily need imported. For instance, some long AWS imports can be made faster by restricting access to Lambda - especially if you have thousands of functions.

### Getting in Touch

If these steps haven't helped you can report issues or concerns to us using the in-app support located in the bottom right of the page, or by sending an email to <support@hava.io>.


# Importing


# Searching

{% content-ref url="/pages/8zWeYSiZjbLTCaozTVPW" %}
[Search Overview](/discover/searching/overview)
{% endcontent-ref %}

{% content-ref url="/pages/pDBeJa4GuWVPjbF2LqBw" %}
[Search Syntax](/discover/searching/search-syntax)
{% endcontent-ref %}

{% content-ref url="/pages/qLKXn5obN82Ng0wOyyJm" %}
[Search Examples](/discover/searching/examples)
{% endcontent-ref %}


# Search Overview

### Hava Search

Hava's built-in search engine gives you control over your diagrams, meaning you can still create user-defined custom diagrams that are:

* **Automated:** So you don't need to worry about time, effort or human error.
* **Always up-to-date with auto-sync:** So you don't have to worry about updating static diagrams in dynamic environments or making updates for every change you deploy.
* **Capture change over time with version history and tracking**: So you don't need to worry about what was running and where at what point of time or trying to pinpoint a time when something might have gone wrong.

Even if you don't want to create and retain a diagram, you can use the search function to find resources using a variety of search criteria. A single search command will execute against ALL the cloud accounts you have connected irrespective of the platform or how many accounts you have connected.

This means you can simultaneously search through AWS, GCP and Azure accounts using a single command. An MSP with thousands of cloud accounts can potentially find resources, types of resources that need attention or IP addresses causing concern with a single command without leaving Hava or logging into a single cloud console.

![](/files/AZNtwrHGuqZRlH8dgjfo)

Once you define and generate a custom diagram, you can save it and it will be placed on your environment console and kept up to date hands-free.

{% embed url="<https://youtu.be/IGw9LrHaa8A>" %}


# Search Syntax

You can use one or more of the following search syntaxes with the Boolean search operators to create complex search queries.

### Search Syntax

<table><thead><tr><th>Tokens</th><th width="289.66666666666663">Description</th><th>Cloud Platform</th></tr></thead><tbody><tr><td><strong>name:</strong></td><td>add resources with this name.</td><td>All</td></tr><tr><td><strong>region:</strong></td><td>add everything in a region.</td><td>All</td></tr><tr><td><strong>source:</strong></td><td>add everything in the specified source.</td><td>All</td></tr><tr><td><strong>type:</strong></td><td>add a specific resource type.</td><td>All</td></tr><tr><td><strong>subnet:</strong></td><td>add everything in the Subnet matching this ID.</td><td>All</td></tr><tr><td><strong>id:</strong></td><td>add everything with this id: token</td><td>All</td></tr><tr><td><strong>ip:</strong></td><td>add everything that matches or includes an IP.</td><td>All</td></tr><tr><td><strong>Any other value followed by ' : ' (Tags)</strong></td><td>add everything from specified tag.</td><td>All</td></tr><tr><td><strong>resource_group:</strong></td><td>add everything in the Resource Group matching this ID.</td><td>Azure</td></tr><tr><td><strong>virtual_network:</strong></td><td>add everything in the Virtual Network matching this ID.</td><td>Azure</td></tr><tr><td><strong>vpc:</strong></td><td>add everything in the VPC matching this ID.</td><td>AWS &#x26; Google Cloud</td></tr><tr><td><strong>project:</strong></td><td>add everything in this Project.</td><td>Google Cloud</td></tr></tbody></table>

### Search Operators

The search syntax also provides a set of modifiers and operators allowing you to combine the tokens into complex queries to match resources across all providers, allowing you to define exactly what should be on the diagram.<br>

<table><thead><tr><th width="150">Operators</th><th>Description</th></tr></thead><tbody><tr><td><strong>AND</strong></td><td>Allows you to join queries together to limit or expand the results returned.<br><br><strong>Example:</strong> <code>type:"AWS::EC2::Instance</code>" <code>and vpc:vpc-1234</code> will search for all resources that are EC2 Instances AND are within the VPC <code>vpc-1234</code></td></tr><tr><td><strong>OR</strong></td><td>Allows you to join queries together to limit or expand the results returned.<br><br><strong>Example:</strong> <code>region:us-west-1 or region:us-west-2</code> will return resources within <code>us-west-1</code> OR within <code>us-west-2</code></td></tr><tr><td><strong>- (minus)</strong></td><td>By adding a minus ( - ) before your search token you can remove any resources that match a query.<br><br><strong>Example:</strong> <code>vpc:vpc-1234 and -name:dev-*</code> will return resources that are in the VPC <code>vpc-1234</code> and don’t have a <code>name</code> starting with <code>dev-</code><br></td></tr><tr><td><strong>( brackets )</strong></td><td>Grouping queries with brackets, a set of tokens together to create more complex queries by surrounding them with brackets.<br><br><strong>Example:</strong> <code>vpc:vpc-1234 and (CostCenter:dev or CostCenter:test)</code> will return all resources within the VPC vpc-1234 that have the tag CostCenter with a value of either dev or test.</td></tr><tr><td><strong>@</strong></td><td>Doing a Deep Search using <code>@</code> sometimes you not only want to see the matched resources but anything connected to them as well.<br><br><strong>Example:</strong> <code>@type:"AWS::EC2::Instance"</code> will return all instances, as well as connected resources such as load balancers and ECS clusters.</td></tr><tr><td>*</td><td>Wildcard</td></tr></tbody></table>

<br>


# VPC Search

By default, Hava builds your diagrams at a VPC level. A single diagram is generated for each VPC within your cloud provider account.

However, you might want to combine multiple VPC into one diagram view. For instance, a common use case is creating a single diagram view of all the VPC connected via a VPC peering connection.

### **Basic Examples**

| Search                         | Result                                                                                         |
| ------------------------------ | ---------------------------------------------------------------------------------------------- |
| `vpc:vpc-1234`                 | This would return everything in `vpc-1234` and be the same as the default VPC created by Hava. |
| `vpc:vpc-1234 or vpc:vpc-5678` | This would return both `vpc-1234` and `vpc-5678` using the or operator.                        |

### Locating VPC ID

If you don’t already know the VPC id, this can be found in several locations within Hava in the attribute panel.

**The most common way to find it is:**

1. Open up the VPC you want.
2. Click anywhere within the VPC container.
3. In the attribute panel under the VPC name, you will find the ID.

![](https://codahosted.io/docs/cYayXS-HlE/blobs/bl-iCj_CsDI6F/a1048fad9a9a681e15ee8eb94b6e3164325bc2ccece98468504a9e12cf9753dd5e3ca3d015e1d08b91f5a0ceafca31910e627acff9124b16a821d1f0ba1f5041464e8201e64131ab4d13d5451111d59b13f30c18ff4b26f25649d989513120b4d70fc48d)

### Incorrect Syntax Errors

Hava requires the correct syntax if forgotten or edited, this will cause a syntax error. For example, when searching for a VPC it must include `vpc:` followed by the VPC id with no (space) in between

#### Space between vpc: and the VPC id

* Correct use: <mark style="color:green;">`vpc:vpc-1234`</mark>
* Incorrect use: <mark style="color:red;">`vpc: vpc-1234`</mark>

![](/files/FxWGac2HTUhK3EMwUzlr)

**No vpc: before the VPC id**

* Correct use: <mark style="color:green;">`vpc:vpc-1234`</mark>
* Incorrect use: <mark style="color:red;">`vpc-vpc-1234`</mark>

![](/files/FyR0CLVkxAmzlXMBvPIk)

**No Boolean operator between query**

* Correct use: <mark style="color:green;">`vpc:vpc-123 or vpc:vpc-abcd`</mark>
* Incorrect use: <mark style="color:red;">`vpc:vpc-1234 or vpc-abcd`</mark>

![](/files/CCs2gifgRfg8dz0mR5ld)

### Use Cases

* VPC Peering Connections


# Wildcard Search

The wildcard `*` adds flexibility to your search term to maximise your search results. By default, the Hava search expects an exact match and is case sensitive.

For example, to create a custom environment made up of all VPCs in the `region us-east-2`.

* One way to create this would be to add each `vpc:id` to the search like in the below example.\
  \
  `region:us-east-2 and (vpc:123 or vpc:abc or vpc:456 or vpc:xyz`<br>
* This can be simplified using the wildcard like in the below example.\
  \
  `region:us-east-2 and vpc:*`

### **Common reasons the wildcard search returns empty**.

#### Incorrect Position

The wildcard search is only a single wildcard character at the end of the string.

* **Correct use:** <mark style="color:green;">`region:us-east-2 and vpc:*`</mark>
* Incorrect use: <mark style="color:red;">`region:us-*-2 and vpc:*`</mark>
* Incorrect use: <mark style="color:red;">`subnet:10.145.*.*`</mark>

#### Modifying Type Search

Trying to modify the type search syntax.

* Incorrect use: <mark style="color:red;">`type:"AWS::ElasticLoadBalancingV2::*"`</mark>


# Tag Search

Tag search can be powerful but a little frustrating when Hava returns no results when in fact, resources contain those tags.

### **The tag search contains three parts.**

1. The tag `name`
2. The colon <mark style="color:red;">`:`</mark> that separates the name from the value.
3. The tag `value`

### **Common reasons the tag search returns empty.**

#### **Case Sensitive**

The search string is case sensitive and expects an exact match, so `name:production` would only match something with that exact name.

#### Incorrect use of wildcard

The search supports a single wildcard character and has to be at the end of the string.

* **Correct use:** <mark style="color:green;">`name:production*`</mark>
* Incorrect use: <mark style="color:red;">`name:*-production*`</mark>

#### Incorrect tag name

Using the incorrect tag name is easily overlooked and depending on the tagging convention used, this would vary, for example:

Using a common default name such as `name:production` when in fact it is `Environment:production`

#### Special characters

The tag value contains any space or special characters, spaces or other special characters must be surrounded by "double-quotes".

* **Correct use:** <mark style="color:green;">`name:"production us-west"`</mark>
* Incorrect use: <mark style="color:red;">`name:production us-west`</mark><br>
* **Correct use:** <mark style="color:green;">`name:"production #1"`</mark>
* Incorrect use: <mark style="color:red;">`name:production #1`</mark><br>
* **Correct use:** <mark style="color:green;">`name:"production:app"`</mark>
* Incorrect use: <mark style="color:red;">`name:production:app`</mark>

### Tips & Caveats

#### Case sensitive matches

Using or with/or without a wildcard `*`, you can account for any case-sensitive matches similar to the example below.

`(name:analytics* or Name:analytics* or name:Analytics* or Name:Analytics)`

#### Finding missing tags

A common question asked is if there is a way to identify and diagram resources with missing tags. Currently, Hava can only identify known tags. Therefore, it cannot search for any resource with no tags. The good news is it's on our roadmap.\ <br>


# Deep Search

Sometimes you want to see the matched resources and anything connected to them as well. You may want to find your instances and see their load balancers without having to specify them. Or perhaps you want to see your ECS clusters as well as the instances they are running on.

## Doing a Deep Search using `@`

Below are some example use-case you can use to define custom environments.

### Resource Type

`@type:"AWS::EC2::Instance"` will return all:

* Instances as well as connected resources
* Such as Load balancers and ECS clusters.

### Tags

`@CostCenter:dev and vpc:vpc-1234` will return all resources with the:

* Tag `CostCenter` and value `dev`
* In the VPC `vpc-1234`
* It will then also return any resources connected to them as well.

\
Any resources returned with the **deep search** operator will be returned after the search is complete and will not be matched against the query itself.

\
If you search for a specific tag with the deep search operator, it may return resources without that tag, for instance.


# Search Examples


# Discover Resources From Regions

Discover resources from multiple data sources that exist in the same region using Hava query

Hava draws diagrams by default at a VPC or virtual network level, but sometimes your project spans multiple VPCs or cloud providers, so hava allows you to create custom diagrams to display these resources on the same diagram.

There are multiple ways to discover everything in a region using the `region:<region_name>`search syntax.

![Custom Search](/files/YTFlCvUxKMEMYQEI7QjK)

### Discover everything in a region

For this example we will search for everything in `us-east-1` simply click on the search bar in step 1.

#### Select region

Clicking on region will take you to a list of all the regions within your accounts or you can type `region:<region name>` in the search bar. `region:us-east-1`

<div align="left"><img src="/files/-LvORLzCFN7PKYnq_hzW" alt=""></div>

Select a region from the list

<div align="left"><img src="/files/-LvOSboor6BM0h4CWLdS" alt=""></div>

{% hint style="info" %}
Note: You can use one or more search parameters to create a diagram. Build time can vary depending on the size and amount of resources within the VPCs and imported accounts.
{% endhint %}

### Build, Name & Save Environment

Once you've selected the region you want on the right in the attribute pane you will see 2 sources and parameters, which makes up this environment diagrams.

1. Sources: Because there was no source specified it has pulled all VPC located in us-east-1
2. Parameters: region:us-east-1

Once the diagram has been named and save, it will act as any other imported environment within Hava and by default with sync and update any changes every hour.

![](/files/3TTXEXNhBYUK9n9uybZY)

{% hint style="info" %}
Note: Not all views are available with custom diagrams.
{% endhint %}

### Other regional searches

Other regional search use cases commonly used are

`region:<region name> source:<source id>`

`region:<region name> ip:<ip address>`

## Discover resources from regions that do not have any VPCs

Some things don't have a place on a VPC diagram or they might belong within the region and not a VPC, to discover these resources you can view this in our List View.

If you're within you the diagram on the bottom right there is a menu to select the different views available.

![](/files/-MQB2_qJw8tHkEkxz8SD)

Or you can view a list of all VPC and custom diagrams from the main dashboard

![Filter Environments by List View](/files/9rVLtiIhLzzoE7SyJIJX)

{% hint style="info" %}
Find a list of all the resources that Hava currently imports and displays for AWS. We make a distinction between resources that we visualise on the diagram and those that are only shown as attributes.\
\
For instance, Autoscaling Groups are shown as an icon on the diagram, but their Launch Configuration will only be displayed as a link in the Autoscaling Group attributes.
{% endhint %}

### Using List View

List view is a great way to discover all resources within an environment. There are multiple ways to search and filter through the list and the ability to export to CSV or JSON file format.

Filter options.

1. Filter by Type - Resource groups you can select one or more.
2. Sort By - Name, Price or Type
3. Sort list - <img src="/files/-LvOh19jsJNOEk42OKcH" alt="" data-size="line"> A ---> Z or Z ---> A

![](/files/BFgbXQJgzulSFWkOz0VK)

The list view shows all the resources detected in your configuration, including the ones that are not visualised on your infrastructure view. With the list view you can sort resources by price estimate to easily see the most expensive resources deployed and then export that list to csv for accounting and management purposes.

### View Resource Attributes

You can click on any of the resources and on the right panel will display all their attributes.

![](/files/9XqeAORMoFEHYxt328Wz)

###

## Export

There are two export options for list view

{% file src="/files/-LvOo7Px1puzHP791gmC" %}
CSV Export Example
{% endfile %}

{% file src="/files/-LvOoI8OSkX02gpPNas2" %}
JSON Export Example
{% endfile %}

![List View Export Options](/files/9emJBOdTjcqrhppXMlvM)

### <br>


# Create a multiple VPC diagram

Using Hava Query, you have the flexibility to create multiple VPC diagrams from the same or even different cloud accounts and vendors.

By default, Hava builds diagrams at a VPC level, with the Search and Filter function, you can create custom diagrams.\
This approach makes it possible to integrate multiple VPC's across accounts and resources, building one diagram view which can be saved. Great for displaying peered VPCs on the same diagram.

### **Follow these steps to create a multiple VPC diagram.**

1. Identify the VPC
2. Create the diagram
3. Name and save diagram

### **Choose you VPCs**

![multiple\_vpc\_diagram\_1](/files/9CI5qWbV3mZfWdR6t48q)

### Step 1: Identify the VPC

To begin, you need to have the individual VPC ID, navigate to the particular VPC, click the tile, and this will open the VPC in Hava Infrastructure View.

* Click on or within the outer green container, which makes up the VPC.
* Navigate to the Attribute pane to the right
* Copy the VPC ID (example: vpc-fd2341c2b)

Now you have one VPC ID you can navigate back to the main dashboard by clicking on 'Environments' in the top left corner and repeat these steps for the next VPC.

![Get the VPC id](/files/82x3lChuAD29gXCqyfnH)

{% hint style="info" %}
**Tip**: You can view other diagrams to find ID's even if you've already clicked search. Hava remembers your ongoing search - so go back to environments, click on something in a diagram, copy it's ID, and carry on!
{% endhint %}

![VPC search in the Hava Search Tool](https://www.hava.io/hubfs/search-start-1.png)

### Step 2: Create the diagram

Now you have the VPC IDs, to create the diagram, navigate to the top search bar in Hava next to 'Environments' towards the top left corner.

* Click on the search bar to view a drop-down menu or type vpc:first-vpc-id-here
* Add the second VPC by typing "or" plus vpc:second-vpc-id or select again from the drop-down menu
* You can add two or more VPCs or another search syntax.
* Note - There is no space between vpc: and the id.

![Multi VPC Search](/files/5Fh5JDxA6D3HAZnXDMna)

### Step 3: Name and save diagram

Once the diagram has finished rendering, you can then click on the 'save' button, enter a name for your new environment, and submit. Hava will redirect to your new environment, and it will also show in the environments list. As you import more resources from your account, Hava will run your custom search again and update the environment to match.

Hava will also capture version history whenever changes are automatically detected to the components of your custom diagrams.

![Save a Multi VPC Diagram](/files/JCHSjh92pkEgGOsS0GGx)


# Defining Custom Environments

Create custom network topology diagrams using Hava's flexible search and query method.

Hava contains the functionality to create custom diagrams using key environment parameters you specify.

This enables you to customise diagrams to just include the key information that is dynamic and ready to view at a glance.

Custom Environment Diagrams can be used to:

* Filter and diagram only the specific components of your environment you are interested in viewing
* Combine data from separate environments into one diagram
* Combine data from separate cloud providers into one diagram
* View specific components from multiple sources on the one diagram

The search and filter box at the top of the environments dashboard is the starting point for creating a custom diagram and contains prompts for the available filters.

![](/files/YTFlCvUxKMEMYQEI7QjK)

Select or type the required filter followed by the ID of that resource (no spaces).

The filters are separated by a space. Typing a space after the first resource ID will prompt for the next filter.

You can nominate a single value or stack multiple filters to produce fine tuned custom diagrams.

{% embed url="<https://youtu.be/IGw9LrHaa8A>" %}

### **Search Tokens**

#### **ip:**

Returns anything with the matching IP

ip:10.1.1.1 will match the exact IP

ip:10.1.\* will match the range

**name:**

Returns anything with the matching name

name:MyInstance will match the exact name\
name:My\* will match anything starting with ‘My’\
name:”My Other Instance” will match a name with spaces or other special characters

**project:**

Returns everything in the project - works for Google Cloud

**region:**

Returns anything in the region - works for AWS, Azure, and Google Cloud.

```
region:us-west-1 or region:us-west-2
```

**resource\_group:**

Returns everything in the resource\_group - (works for Azure)

**source:**

Returns anything in this source.\
The source needs to be selected from the suggestion list.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Custom_Diag_003.jpg)

<br>

**subnet:**

\
Returns everything in the subnet - works for AWS, Azure and Google Cloud<br>

**type:**<br>

Returns anything matching the type.\
The type name needs to be selected from the suggestion list as the format needs to match allowed values.

![](https://www.hava.io/hubfs/documentation/TypeSearch.jpg)

<br>

**virtual\_network:**

\
Return everything within the Virtual Network for Azure<br>

**vpc:**

\
Search for everything in a VPC - (works for Google Cloud and AWS)

\
vpc:vpc-1234 will return everything in vpc-1234

\
vpc:vpc-1234 or vpc:vpc-5678 will return both VPCs<br>

**Any other value followed by ' : ' (Tags)**

\
Any other token is considered a tag and works across AWS, Azure and Google Cloud<br>

CostCenter:dev will return everything with the tag named CostCenter with the value dev

"aws:deployment:name”:”Test Deployment” will handle tag names and values with spaces or special characters

Location:US\* will search for a tag called **Location** with any values starting with **US**

### Search Syntax

The search syntax also provides a set of modifiers and operators allowing you to combine the tokens into complex queries to match resources across all providers, allowing you to define exactly what should be on the diagram.

#### Joining queries with ‘and / or’

Allows you to join queries together to limit or expand the results returned.

type:”AWS::EC2::Instance” and vpc:vpc-1234 will search for all resources that are EC2 Instances AND are within the VPC vpc-1234

region:us-west-1 or region:us-west-2 will return resources within us-west-1 OR within us-west-2

#### Excluding matches with '-' (minus)

By adding a minus ( - ) before your search token you can remove any resources that match a query.

vpc:vpc-1234 and -name:dev-\* will return resources that are in the VPC vpc-1234 and don’t have a name starting with ‘dev-’

#### Grouping queries with brackets

You can also group a set of tokens together to create more complex queries by surrounding them with brackets.

vpc:vpc-1234 and (CostCenter:dev or CostCenter:test) will return all resources within the VPC vpc-1234 that have the tag CostCenter with a value of either dev or test.

#### Doing a Deep Search using @

Sometimes you not only want to see the matched resources, but anything connected to them as well. You may want to find your instances but also see their load balancers without having to specify them. Or perhaps you want to see your ECS clusters as well as the instances they are running on.

@type:”AWS::EC2::Instance” will return all instances, as well as connected resources such as load balancers and ECS clusters.

@CostCenter:dev and vpc:vpc-1234 will return all resources with the tag CostCenter and value dev that are in the VPC vpc-1234. It will then also return any resources connected to them as well.

Any resources returned with the **deep search** operator will be returned after the search is complete, and will not be matched against the query itself. If you search for a specific tag with the deep search operator it may return resources without that tag, for instance.

### Complex Queries

Using these operators and tokens a range of complex queries can be created.

```
(vpc:vpc-1234 and ((CostCenter:dev and !Owner:"Jim Smith") or (CostCenter:test and !Owner:"Jim Smith"))) or
(vpc:vpc-4567 and (@type:"AWS::EC2::Instance or type:"AWS::RDS::DBInstance"))
```

What you should get in this case is a diagram with two VPCs:

vpc-1234 containing any resources with a CostCenter of either dev or test and aren’t owned by Jim Smith\
vpc-4567 containing all the databases within it, all the instances within it, and any resources connected to the instances.

### Creating a Multiple Source Diagram.

Lets say you have two environments set up in separate source AWS accounts and you need a way to easily see the total monthly estimated cost.

We can do this by creating a custom cloud architecture diagram that pulls in environments from the two source accounts.

Click in the Search & Filter box and choose the 'source:' filter from the drop down menu :

![](/files/qmEZ7BsFRVrannwjWilo)

Hava will then present you with the available data sources to select from - Select your first source:

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Custom_Diag_003.jpg)

Once this is entered, Hava will prompt you for another source. You can keep adding sources or other filters until you have covered all the data you wish to include. In this example, we will add another source :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Custom_Diag_004.jpg)

Select "source:" again, followed by the required second source :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Custom_Diag_005.jpg)

Once the search and filter box has the two required filter parameters, press enter and the new diagram will be created.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Custom_Diag_006.jpg)

Once the new diagram is created, if the results are as you expected, save the diagram by clicking the "save" button next to the filter box and give the new custom cloud environment diagram a meaningful name :

![Save](/files/3TTXEXNhBYUK9n9uybZY)

Once saved, the environment view of the new diagram will display a combined visualisation and attribute list.

In this example that includes an attribute list that shows the combined cost estimate that we were interested in viewing.

![](/files/YVDuJ3mtfPN7GzB5jfe4)

The data within this new diagram is dynamic and will change as the respective source data changes.

As with all Hava automated interactive diagrams, any major resource changes will trigger a new version of the diagram to be created automatically and the pre state change diagram will be saved in the version history for audit and troubleshooting purposes.

### Creating a Multiple VPC Diagram

By default, Hava builds diagrams at a VPC or Virtual Network level.

Using the Search and Filter function, you can create custom diagrams. This approach makes it possible to integrate multiple VPC's across accounts and resources, building one diagram view which can be saved.

An example use within AWS architecture would be to display peered VPCs on the same diagram.

‌

To create a multiple VPC diagram, follow these steps :

1. Identify the VPC ID's you wish to include on the custom diagram.
2. Create the diagram
3. Name and save diagram

‌

### Identify your VPCs

#### Step 1: Identify the VPC ID's

From the Environments Dashboard, select the environment that contains the first VPC you wish to include on the custom diagram.

Open the diagram by clicking on the relevant tile.

![Select two VPCs and obtain](/files/9CI5qWbV3mZfWdR6t48q)

Click on or within the green outer container of the VPC and copy the VPC ID that is displayed on the Attribute Tab underneath the VPC name.

![Select the bounding VPC box on the Diagram to find the VPC ID](/files/82x3lChuAD29gXCqyfnH)

Repeat this process to obtain the second VPC ID

#### Search and Filter using the two VPC ID's

From the top Search and Filter box enter or select **vpc:** followed by the first VPC ID

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_Custom_Diag_011.png)

Enter a \[space] after the first VPC ID and enter **vpc:** followed by the second VPC ID

Press Enter to create the new custom diagram :

![](/files/JCHSjh92pkEgGOsS0GGx)

Once the diagram has finished rendering, you can then click on the 'save' button, enter a meaningful name for your new environment, and submit.

Hava will redirect to your new environment.

As you import more resources from your account, Hava will run your custom search again and update the environment content to match.

![](/files/gkcKKxEFxtpte31ogzou)

Your new diagram will now appear on the Environments Dashboard.

The above methodology can be replicated for all of the available search operators.

Some operators are platform specific and more are likely to be added as additional cloud platforms are added to Hava.

#### Current Operators are:

* **region:** include everything in the specified region (AWS, Azure, GCP)
* **vpc:** include everything in the corresponding AWS or GCP Virtual Private Cloud
* **subnet:** include everything within the specified subnet id (AWS, GCP, Azure)
* **virtual\_network:** include everything in the specified Azure Virtual Network
* **resource\_group:** include everything in the specified Azure Resource Group
* **source:** include everything from the source selected from a dropdown (connected cloud account)
* **ip:** include everything that matches or includes the nominated IP (use the full IP and port of the environment ie 10.0.0.0/21 )
* **name:** returns anything with a matching name
* **project:** returns everything in the matching GCP Project
* **tag:value:** Any non reserved text preceding a : will be searched as a tag with the value that follows the : ie CostCenter:Dev finds any resource tagged as "Costcenter" with a value of "Dev"
* **type:** returns resources matching the type selected from a dropdown list


# Versioning

See the changes to your cloud environments in a full version history.

### Versioning your interactive cloud infrastructure diagrams.

Possibly one of the most powerful features of Hava especially from a fault analysis and governance perspective, versioning is built in and active from the moment you connect your cloud infrastructure and start building your interactive diagrams.

Hava polls your cloud infrastructure regularly for changes.

Once a resource change is detected, a new version of the interactive diagram is created and the state change is recorded.

![Cloud Configuration Version History](/files/kTMVzneSowUmOJVk6LXI)

The Versions Tab can be found adjacent to the Attributes Tab.

The date/time represents the time that the revision diagram was created due to the live diagram being superseded due to a state change.

To view an archived diagram, simply select it from the versions list.

Having the version history readily to hand enables your engineering team, security team or compliance audit reports to accurately see the state of play at any point in time. Need to see how your cloud infrastructure was configured 6 months ago ? Hava has you covered.

### Comparing Revisions

You can visually compare any two Hava diagrams using the "Compare Revisions" button.

This will generate a diff diagram highlighting the differences between the two diagrams including resources that were either added or removed.

<figure><img src="/files/hVpBQo42tiX5gbCwCdIJ" alt=""><figcaption></figcaption></figure>

{% embed url="<https://youtu.be/_luv01RBMAg>" %}


# Tracking Changes in Cloud Architecture

Using Hava's cloud architecture version history to track changes in your AWS, GCP, and Azure cloud environments.

One of the less obvious but most powerful features of Hava is the Version history.

Cloud environments are rarely static. Autoscaling will add and remove instances, load balancers might reconfigure, security groups and rules could be refined.

The nature of cloud environments gives us a huge amount of flexibility in the way we configure and deploy solutions.

With new services, options and attributes being added all the time, keeping your environment diagrams up to date and your stakeholders informed of the current 'state of play' can be time consuming and costly if tackled manually.

Of course when things go wrong, knowing what has changed within your cloud environment gives you the ability to quickly identify and resolve the issue. This can be a massive time and cost saving strategy for mission critical environments.

Once you connect your cloud account to Hava, your cloud resources are polled continuously and when changes are detected your current diagram is updated to reflect the change and the previous diagram is archived into the "Versions" tab

![Version History](/files/kTMVzneSowUmOJVk6LXI)

To view previous versions of your cloud infrastructure, open up your infrastructure diagram, navigate to the "Versions" tab on the right hand side.

This will display a list of the previous state changes.

The date of each version indicates when the revision diagram was created due to a state change.

The Compare Revisions feature allows you to compare any two diagrams.

This can be the current state vs a previous diagram, or any other two historical versions.

<figure><img src="/files/hVpBQo42tiX5gbCwCdIJ" alt=""><figcaption><p>Hava Diff Diagram</p></figcaption></figure>

Run a programmatic comparison at a granular level you can export the JSON data from both diagrams.

{% embed url="<https://youtu.be/_luv01RBMAg>" %}

## FAQ's

**How long do you keep versions?**

The amount of versions in your list can vary depending on how often your architecture is amended and synchronised. The Teams retains versions for 6 months.

You can extend data retention by adding additional retention months to your plan.

**How often do you import new versions?**

Your sources will sync every 24 hours. You can manually sync if you have just made configuration changes that you want to see right away or you can trigger a sync in your CI/CD pipelines using the Hava API or CLI.

**Can I compare my versions within Hava?**

Yes - use the Compare Revisions tool.

**Can I be notified when changes trigger a new diagram revision?**

Yes - you can set up Architectural Monitoring Alerts that will email you a diff diagram as new revisions are created. This shows you exactly what just changed.


# Manual Sync

How to refresh your automated cloud diagrams using the Hava Manual Sync function.

Hava automatically synchronizes your sources on a schedule. This schedule differs based on the type of account you have (see our [pricing](https://www.hava.io/pricing) page for details).

In the cases where need to synchornize more often or to reflect new changes that recently deployed, you can manually trigger a source to synchronize by using the web UI or the API.

### **Sync a Single Data Source**

To sync an individual data source, click the cog to the left of the source name and take the "Sync" option

![Manually Sync Connected Cloud Accounts](/files/ECLs1GnYEghaFSOVh6bd)


# Listing Environments


# Filtering Environments

Which search/filter box should you use

On the Hava environments dashboard there are 2 input boxes that enable you to find specific diagrams or resources.

### **Search Query**

The first search box is found on the top nav bar.

![](/files/AZNtwrHGuqZRlH8dgjfo)

This search relates to building custom environment diagrams. Entering values in this search box will render a new diagram based on the custom parameters.

You would typically use this to create a diagram from a subset of resources in an environment, or to build a diagram using data from multiple cloud accounts, even multiple vendors. So you could for instance, build a hybrid diagram with Azure and AWS resources.

Once saved, the custom diagram will be automatically updated and version history preserved.

See: [Creating Custom Diagrams with Omni Search Queries](https://docs.hava.io/features/defining-custom-environments)

### Filtering Environments

The environment filter box allows you to search for pre existing diagrams that contain specific text.

Where, you have hundreds of environment tiles and saved custom diagrams, the ability to filter the environments enables you to find the specific diagrams you are looking for.

You can search for diagrams with a specific name or region.

Entering "US-East" for instance, will hide all the environments not in an availability zone starting with US-East.

You could type in 'Demo' to filter on any environments with 'demo' in the name.

![Filter environments shown on the dashboard](/files/Ui4J4BUuLHvtalwZ7NvX)

You can also use the specific filters in the top menu bar to filter on:

* Environment Type

<figure><img src="/files/UCDzNBeYJcqrHfGCW3XV" alt=""><figcaption><p>Filter Viewable Environments by Diagram Type</p></figcaption></figure>

* Sources (Cloud Accounts)

<figure><img src="/files/bH9yyOJNGrZuqf3IUj6T" alt=""><figcaption><p>Filter Viewable Environments by Cloud Account Source</p></figcaption></figure>

You can check or uncheck to control which sources are visible. You can also type into the filter box to just view any sources whos name matches the search string.

* Providers

<figure><img src="/files/nx3pnpilw2FHoPPe2Wbt" alt=""><figcaption><p>Filter by cloud platform</p></figcaption></figure>

Using the Providers filter, you can just display environments built

{% embed url="<https://youtu.be/epYoB9Y0SZY>" %}


# Favouriting Environments

### Pinned Environments

It's not uncommon for cloud architecture to contain multiple production environments, multiple test environments belonging to different teams and projects.

To make it easy to find the environments you are currently working on, you have the ability to favourite them and then order displayed environments by favourites.

This will bring all the starred environments to the top of your environments dashboard.

It the top left of the environment tile, there is a star icon. Selecting this will toggle the favourite indicator on and off.

![Pinned Environments](/files/ZzJS4qBAzzoBgdg5jRza)

Favourited environments are saved at browser level, so different team members using the same Hava log in credentials can see their own set of starred environments.

To bring your favourited environments to the top of the page so you don't need to scroll through dozens or hundreds of environments you may not be interested in you can use the "Order by" sort function to sort by "Favourites" to bring all the starred environments to the top of your dashboard.

<figure><img src="/files/RP9MJFDjl5NrzsWlzGiv" alt=""><figcaption><p>Environments Sorted by Favourites Brought to the Top of Your Dashboard</p></figcaption></figure>

{% embed url="<https://youtu.be/epYoB9Y0SZY?si=DqRkxNMYpNxqTxP9&t=150>" %}


# Viewing Environments

How to view your AWS, GCP, and Azure auto generated diagrams using Hava

View diagram is the core functionality of Hava and is where you can view all the resources that are both visualised on the diagram and detailed in the Attributes list.

While the initial diagram view will show a simple logically laid out representation of the major resources in your cloud environment, the true power of Hava is the deep analysis of the resources and relationships between them.

Not only can you see the structure of your cloud architecture at a glance, you can drill down into each individual resource and see all the attributes, security, routing, estimated costs for that resource.

{% embed url="<https://youtu.be/E0q6AtUo2Fw>" %}

#### Selecting an Environment Diagram to View

To get started, from the Environments dashboard, select the environment diagram you wish to view by clicking on the tile.

![Select the Visualized Environment Diagram to View](/files/cwZ7DU2mI5uWK7NY0xQT)

This will open up the latest diagram.

*Once connected to Hava, your cloud environment configuration is continuously polled. If there is a structural change detected, a new diagram version is created and the previous diagram is preserved in the Version History.*

![AWS Architecture Diagram](/files/FRjw0CJD2NlzlPotF0bU)

Each interactive diagram is constructed from the source of truth data, being the actual resources that are configured and running in your cloud environment. This eliminates errors or omissions often associated with manually created diagrams.

AWS architecture is laid out based on VPC Containers, availability zones and subnets, with external storage resources and gateways being detailed outside the main VPC containers.

### External Resources

![VPC External Resources](/files/vQY60B7fIO1Bft9rozgy)

Clicking on any resource or box surrounding a VPC, Availability Zone or Subnet will populate the Attributes Tab with the attribute data pertaining to the selected resource.

### AWS VPC Layout

![](/files/hDi2nRknp8V8PnoSjWAh)

Each AWS VPC Container is represented by a green border. Clicking the border or any blank area inside the VPC will change the Attributes tab data to the information pertaining to that VPC.

Building a multiple source diagram will enable multiple VPC containers to be displayed along side other cloud infrastructure such as Microsoft Azure and Google Cloud Platform on the same diagram.

### AWS Availability Zones

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_017.jpg)

Availability zones set up in your AWS architecture are laid out in columns on the Hava interactive diagram.

### AWS Subnets

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_018.jpg)

Subnets within your AWS infrastructure are detailed within the availability zone that they are configured in.

Selecting the subnet by clicking the border or a blank area inside the border will display the subnet attributes such as availability zone, IP's, connected resources and estimated cost.

### Azure Diagrams

Once you connect your Microsoft Azure credentials to Hava the infrastructure is analysed and Hava produces the interactive Diagram. From this point Hava will track changes and preserve a version history for auditing and problem diagnosis.

![](/files/OMBZG0VL7o5iDSkENjqv)

1. Environment - when this top level view is selected, the data source and total monthly estimate is shown
2. Virtual Network - contains resources such as load balancers, subnets etc
3. Subnet - Select a subnet and the attribute tab will display information such as the Network Security Groups the Subnet belongs to and Route Table information.
4. Resources external to a Virtual Network. In this example we have a Virtual Network Gateway, Local Network Gateway, Express Route Circuit and several Storage Accounts.
5. Attribute Tab - this displays attributes and their values that are contextual to the currently selected resource or network segment.

## Interactive Diagram Export

Hava will export your cloud environment diagrams in several major formats.

Select the 'Export" button to open the export dialogue :

![Hava Diagram Export Options](/files/RnyIAIbbeVY5k2tS6mSS)

Select the required output format : Hava will prepare the download - once the "Export Complete" notification is visible, you can download the exported file.

![](/files/-MQAQaAQoIZDnRRcDJlC)

##

## Interactive Diagram View Options

These controls allow you to show or hide detail on your environment diagram.

By default the resource names and connections are suppressed to produce a clean diagram, but you are able to display these as required.

![](/files/TXmloEla5E8Xq8EIN0Qm)

### Display Names/Connections

![](/files/-MQARzAQusTsj5ytIQyt)

### Drawn Connections

When Hava creates your diagram it can also display network connections based on the meta data returned with the resource. So long as one resource has an explicit link to another resource, Hava will display a connection when a resource is selected, or using the Connections toggle in the view options.

For a list of supported connections see the supported resources for each provider:

{% content-ref url="/pages/-M2pjoZsfss1FbXWL5XA" %}
[AWS Supported Resources](/importing/aws/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZoJfhHsIRN73CC" %}
[Azure Supported Resources](/importing/azure/supported-resources)
{% endcontent-ref %}

{% content-ref url="/pages/-M2pjoZpyuH9bgh1I7wO" %}
[GCP Supported Resources](/importing/google-cloud/supported-resources)
{% endcontent-ref %}

### Icon Sets

Hava also has the post 2019 current and pre 2019 AWS icon sets available for selection on the "View Options" dialogue.

## Service and Capacity Information

The Container View will generally show one main cluster container around one or more service containers, showing the individual services that make up the cluster as well as the tasks running inside.

<figure><img src="/files/iaLDVIARvd6wXMDgpuYn" alt=""><figcaption></figcaption></figure>

At the top of the container you can see information about the state of the container as well as it's location, while at the bottom you can see the name and the ID of the service. Clicking anywhere in the service will display all the services attributes in the right hand attributes panel.

Towards the top of the service you will see load balancing information if there are any load balancers connected to your containers. This will show the port and the container the load balancer is connected to for each task. Click the load balancer box to see more information about the target group or class load balancer that is attached.

Each of the tasks running within the service are shown as a hexagonal icon that can be clicked to see the information for the specific task. Tasks are displayed in different styles depending on their current state:

**Green** tasks are running successfully.

**Yellow** tasks are in a pending state, usually starting up or shutting down. You can click the task for more details.

**Dashed** tasks are spare capacity in the service, where the desired count is less than the running count.

## Detailed Resource Information

Clicking on any resource on the diagram will display detailed information about that resources in the attributes bar on the right hand side. This can be used to get more detail on what the diagram is displayed.

From the main cluster you can see what services and tasks are running, as well as the container instances the cluster is spread across. If you are running in an EC2 cluster you will also be able to see the underlying EC2 instances.

From the service you are able to see the task definition it's using as well as deployment and placement information. You can also see a list view of all the tasks running within the services currently, and any load balancing available to those tasks.

In the task attributes you can see the containers running within the task, the container instance it's deployed onto, and the current status of the task.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_DIag_035.png)

## Versioning

Possibly one of the most powerful features of Hava especially from a fault analysis and governance perspective, versioning is built in and active from the moment you connect your cloud infrastructure and start building your interactive diagrams.

Hava polls your cloud infrastructure on an continuous basis.

Once a resource change is detected, a new version of the interactive diagram is created and the state change is recorded.

![Hava versions tab - lets you select historical fully interactive diagrams](/files/kTMVzneSowUmOJVk6LXI)

The Versions Tab can be found adjacent to the Attributes Tab.

The date is the date/time that the diagram was superseded due to a state change.

To view an archived diagram, simply select it from the versions list.

Having the version history readily to hand enables your engineering team, security team or compliance audit reports to accurately see the state of play at any point in time. Need to see how your cloud infrastructure was configured 6 months ago ? Hava has you covered.

You can use the compare revisions tool to instantly compare any diagram including the current one with any historical version. This "Diff Diagram" visually explains exactly what was added or removed from your architecture between the two dates selected/

<figure><img src="/files/hVpBQo42tiX5gbCwCdIJ" alt=""><figcaption><p>Hava Diff Diagram - Revision Comparison of any two diagram versions</p></figcaption></figure>


# Diagram Controls

Control the look and feel of your Hava interactive diagrams with these controls.

The visual controls are found to the left of your interactive diagram.

<figure><img src="/files/0WnWptcGn55BibrJsfrb" alt=""><figcaption></figcaption></figure>

### **Zoom In/Out**

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_003.jpg)

### **Reset View - Fit to Screen**

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_004.jpg)

​

### **Skew**

Changes diagram to a topographical view

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_005.jpg)

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_006.jpg)


# Diagram Layout

## Layout Controls

![Hava\_Diagram\_Layout\_Controls](/files/FLy1f3BWGSDnew8Awo0j)

The "Layout Controls" introduce the ability to stretch or compress the diagram width and/or height and also stretch or compress the subnet columns.

![Hava\_Diagram\_Layout\_Controls-2](/files/Kcp17GuqrQLmVGlECYDI)

The first control "Resource Width" adjusts the width of the canvas.

![Hava Layout Adjustment Resource Width](/files/YaibhNPH1vuZAWbMiIiD)

The screenshot above is a standard AWS VPC. The below diagram is the result of adjusting the diagram canvas using the width adjustment.

![Hava Layout Resource Width After](/files/L9Jm7lb2jeFgE92oPFNR)

This width adjustment results in more distance between resources while keeping the entire environment on screen. This is especially useful when displaying resource names. Just using the zoom option to achieve the same result would scale the diagram so only part of the diagram was visible on screen.

The Resource Height adjustment works in the same manner, increasing the horizontal gap between visualized resources.

![Hava Resource Layout Height](/files/pYFNaprnF9gjiCzBYbKB)

The final control is the Subnet Column adjustment. This control allows you to expand or contract the width of the subnet columns without affecting the distance between resources.

On the initial diagram with default settings, the resources in each subnet are stacked based on the available screen space.

![Hava Layout Default Subnet Diagram](/files/8pZ5P6RyqNbfykqEJ6a0)

By increasing the Subnet Column width, you can increase the number of resources visualized on each row within the subnet, while preserving the original spacing between resources. This is especially useful where you have a large number of resources in one subnet.

![Hava Layout Increased Subnet Width](/files/BnCJYTa9Ryzei4P3Lvvd)

##


# Switch Between Views

## Diagram Views

There are five distinct ways to view your cloud architecture built into Hava.

* Infrastructure View
* Extended Infrastructure View
* List View
* Security Group View
* Container View

### Infrastructure View (AWS, GCP, Azure)

They are selectable from a collapsible drop down menu in the bottom right "Select Your View".

![Select the type of Diagram View](/files/MqOtTvm7QbKGdFaRyHti)

By default when you open your Cloud Architecture Diagram the "Infrastructure" View will be displayed.

Also by default the infrastructure view has no labels or connections displayed. All the example screen shots above are taken from the Infrastructure View.

### Extended Infrastructure View (AWS, GCP, Azure)

The extended Infrastructure view displays key information relating to the visualised resource.

For instance a Nat Gateway visualised on an **Extended Infrastructure View Diagram** will display the Nat Gateway name and both the public and private IP addresses. A visualised RDS Database will display the Database Identifier, Engine type and allocated storage capacity.

The extended information is contextual to the type of resource being visualised and is typically the most useful parameters a security or solutions architect would need to know.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_028.jpg)

### List View (AWS, GCP, Azure)

List view is an alphabetic list of detected resources Hava has detected in your cloud architecture.

This includes all the resources that are not visualised on the two infrastructure views.

The list view toolbar has the option to sort by Name, Price and Type

![Hava List View](/files/9XqeAORMoFEHYxt328Wz)

You can select resources in the list and the detailed attributes are displayed in the Attributes Tab.

At a glance you can also see a cost estimate for the resource.

Some of the unvisualised resources you will find in the **List View** include :

* Elasicache Cluster Nodes
* Network ACLs
* Directory Services
* Workspaces and Workspace Directories
* Storage Volumes
* Elasticache Subnet Groups
* DHCP Options
* Network Interfaces
* WAF Rules

There is a Filter option in the "List View Toolbar" to filter on the type of resource you wish to view.

Place a check mark next to the resources you wish to view. You can select multiple types.

![](/files/BFgbXQJgzulSFWkOz0VK)

## Security Group View (AWS & Azure)

Built with your cloud security engineers in mind, the Security Group View is a visualisation of all the security groups set up within your cloud architecture. It details the ports configured for use and resulting traffic flow.

![AWS Security Group View](/files/DrgpMhiaRUmGe1D68a1c)

Selecting a security group in the visualisation will populate the connected resources for that group in the Attributes Tab to the right.

The attribute data also details the ingress and egress IP addresses, ports in use and port types.

<figure><img src="/files/FmdBIvttjkQ30bSTIDn5" alt=""><figcaption></figcaption></figure>

### Container View

When you have containers configured within your cloud infrastructure and hava detects them, a "Container View" option will appear in the header toolbar and in the "view selection" dropdown menu.

You can also connect a stand alone Kubernetes Cluster.

![Container View](/files/iaLDVIARvd6wXMDgpuYn)

The Hava container view gives you an overall diagram of your entire ECS cluster. You can see every service and task currently running, any load balancing available to your containers, as well as unused or pending capacity.

![Container Tasks](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_DIag_034.png)

## Diff View

The Revision Comparison or Diff View is accessed via the versions tab on your infrastructure diagrams.

Where you have retained diagram versions, you can select any two diagrams and the Diff View will show you all the resources that have been added or removed between the two diagram dates.

<figure><img src="/files/hVpBQo42tiX5gbCwCdIJ" alt=""><figcaption><p>Hava Diff View</p></figcaption></figure>


# Diagram Canvas Resource Filters

Hava now provides the ability to filter exactly what you do and don't want to view on your auto generated cloud architecture diagrams.

There are numerous reasons why Hava users have requested this feature.

In a large complex environment, you may only be interested in a handful of resource types for the immediate project or problem you are trying to solve.

Maybe your environment has thousands of Lambda functions that you have no interest in and you'd like to just see the other resources.

Whatever the scenario, you now have the ability to control exactly what is visible on your diagram canvas.

<figure><img src="https://www.hava.io/hs-fs/hubfs/Hava_Diagram_Canvas_Filters.jpg?width=1222&#x26;height=819&#x26;name=Hava_Diagram_Canvas_Filters.jpg" alt="Diagram showing the Hava canvas resource filters"><figcaption><p>Hava Diagram Canvas Filters</p></figcaption></figure>

The filter controls are found in the accordion menu to the right of your Hava diagrams.

Simply click on the check mark next to a resource type and that resource type will be hidden on the diagram.

If we uncheck EC2 Instances, this is the result:

<figure><img src="https://www.hava.io/hs-fs/hubfs/Hide_EC2_Instances.jpg?width=1223&#x26;height=826&#x26;name=Hide_EC2_Instances.jpg" alt="Diagram Filters showing AWS EC2 instances hidden"><figcaption><p>Hide AWS EC2 Instances</p></figcaption></figure>

As you would expect, checking the EC2 resource brings them all back.

Any resources that are not present on the diagram are greyed out in the filter options.

<figure><img src="https://www.hava.io/hs-fs/hubfs/Hide_Resources_not_on_the_Hava_Diagram.jpg?width=1225&#x26;height=823&#x26;name=Hide_Resources_not_on_the_Hava_Diagram.jpg" alt="toggle on or off filter options"><figcaption><p>Hide Resources not on the Hava Diagram</p></figcaption></figure>

To remove them from the filter options, toggle the "Hide resource types not in this environment" slide button to hide the non present resource options.

Simple yet effective. Here's a video walkthrough of the feature in action:

{% embed url="<https://youtu.be/syoS7lBm0QY>" %}

<br>


# Draw Custom Connections

When you connect your cloud account to Hava, we automatically generate diagrams showing [**determined connections**](#user-content-fn-1)[^1] that can be directly detected. Because Hava uses read-only permissions and no agents, we cannot confirm or automatically display [**inferred connections** ](#user-content-fn-2)[^2]\(like application logic accessing S3 buckets).

\
To accurately represent your environment, we refrain from guessing or drawing inferred connections. Instead, you can manually create custom connections. These custom connections persist across diagram versions as long as the associated resources are still present. If a resource disappears, you can still review previously drawn custom connections in your diagram’s version history.

### How to draw a custom connection

1\. Right-click on the resource you want to connect to another resource.

2\. Select Connect To and choose the target resource.

{% @arcade/embed url="<https://app.arcade.software/share/3KoDaea7aSNsgBPID9nF>" flowId="3KoDaea7aSNsgBPID9nF" fullWidth="false" %}

### Frequently asked questions

<details>

<summary>What types of connections does Hava display by default?</summary>

Hava displays determined connections, which are directly detectable based on read-only permissions. It does not automatically show inferred connections, such as application-level links, to ensure accuracy and avoid assumptions.

</details>

<details>

<summary>Can I add custom connections to my diagrams?</summary>

Yes! You can manually add custom connections by right-clicking on a resource, selecting Connect To, and choosing the target resource. These connections help visualise inferred relationships.

</details>

<details>

<summary>What resources can I create custom connections between?</summary>

Custom connections in Hava can link a variety of resources, including:

* **Individual Resources:** EC2 instances, S3 buckets, databases, load balancers, etc.
* **Subnets:** To represent communication between specific subnets.
* **VPCs:** To illustrate inter-VPC or peering connections.
* **Availability Zones (AZs):** To show regional dependencies or data flow.
* **Cross-Cloud Resources:** Connections between AWS, Azure, and GCP resources.

These connections allow you to fully customize and enrich your diagrams to represent inferred or hybrid architectures accurately.

</details>

<details>

<summary>Do custom connections persist between diagram versions?</summary>

Custom connections remain in place across versions, provided the connected resources still exist. If a resource is removed, the connections can still be viewed in the diagram’s version history.

</details>

<details>

<summary>Can I visualise multi-cloud or hybrid cloud connections?</summary>

Yes! You can create custom connections between resources in different cloud providers (e.g., AWS, Azure, GCP) or external virtual networks to represent hybrid cloud architectures.

</details>

<details>

<summary>Why doesn’t Hava display inferred connections automatically?</summary>

Hava prioritises accuracy and only displays determined connections. Inferred connections are left to users to add manually, as they may involve assumptions beyond what can be detected via read-only permissions.

</details>

[^1]: Detectable links between resources that Hava identifies using read-only permissions (e.g., a load balancer routing traffic to targets).

[^2]: Indirect or assumed links, such as application logic accessing an S3 bucket, which Hava does not automatically display to ensure accuracy.


# Architectural Monitoring Alerts

Get notifications when architecture changes or new services are deployed.

### How to set up Architectural Monitoring Alerts for AWS, Azure and GCP

You can set up Architectural Monitoring Alerts for any Environments (Cloud Accounts) connected to Hava.

You have the choice of monitoring changes to an entire environment or just new services that are added.

Alerts can go to an entire team (on a teams account), an individual Hava user or an arbitrary email address not connected to your Hava account.

The first step is to select 'Alerts' from the side menu.

![Hava Architectural Monitoring Alerts](/files/l0ZxLi4fKGetwdRfw1Kf)

This will display all the active Architectural Monitoring alerts you have running.

To create a new alert, select 'Add New' in the top right of the Alerts screen.

![Create\_Alert\_Step\_1](/files/RnxsxIhkaow1KRss2Ndx)

You can then name the alert and enter a brief description.

Now you have two options.

**Monitor Environment Change**: This allows you to select a specific diagram and then monitor the changes to to it.

**New Service:** This option allows you to monitor any new services added to a nominated cloud account (Data Source)

**Hava Architectural Monitoring - Environment Change Alerts**

When you select the alert type of Environment Change, you can then select a target from a list of environment diagrams.

![Hava\_Monitor\_Environment\_Change](/files/kveyfUl5ZUjbja6VBM0g)

You may select more than one environment for this alert.

You then select the destination for the alert. Either Team, User or Email Address.

Once you select the recipient type, you can then select the required team or user, or manually enter a value against the email address option.

**Hava Architectural Monitoring - New Service Alerts**

To monitor for new services being added to a cloud account you can use the "New Service" alert.

With this option you select a connected cloud account from the "Target" list.

The recipients list is identical to the first example.

Once set up, as your environments are synced by Hava, any changes covered by an alert will trigger an email to all recipients detailing the changes.

#### Reviewing Architectural Monitoring Alerts.

On top of the diagram and alert details sent during a monitoring event, you can view alert details from the alerts console.

![Hava\_Architectural\_Monitoring\_Alerts\_Console](/files/EUn4l8qVytVd1xzYgscK)

Select "Details" for the alert you are interested in:

In this example we will look at the Environment Change alerts on the 2nd alert.

![Hava\_Alert\_Details](/files/KRTNb773oXcZyFHK0OEB)

This shows the environment generating the alerts and the recipients, followed by a list of event notifications when Architecture changes were detected by the automated Hava sync process.

You can select any previous alert to view the details.

![Hava\_Architectural\_Monitoring\_Event](/files/O7dt7vHbAhi9XRz7Gfye)

You can see the alert event detail followed by the diff diagram highlighting what has been added or removed.

Following the diagram is a detailed list of the resources that have changed.

Selecting any of the resources in the list will open a custom diagram view of the resource where you can investigate the settings of the resource without having to navigate to your cloud console settings.


# Attributes

View the attributes of resources you select on the interactive diagrams.

### Cloud Diagram Attributes Tab

The data displayed in the Attributes Tab is contextual to the resource selected on the interactive diagram.

{% embed url="<https://youtu.be/QxL4Fz7-L-A>" %}

When you first open the diagram and have nothing selected, the attribute tab will display the environment overview.

![AWS Environment View with no Resources selected](/files/EFdCRiA7P0V1VLeXiYsl)

The attributes list will contain expandable lists of information related to the currently selected resource. For the default total environment, the "Monthly Estimate" is displayed as a total, but can be expanded to view the cost estimate breakdown by clicking ![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_013.jpg)

![Example Cost Estimate Breakdown](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_014.jpg)

One of the most powerful features of Hava is the wealth of data that is captured and available for each resource or container within your cloud infrastructure. Instead of flooding the initial visualisation with hundreds of data points, the attributes relating to each resource are available on demand.

#### AWS VPC Attributes

![](/files/QkWVWp5sOxXY5WvOVw1a)

To view the attributes of a VPC, select the border and the Attributes tab will display the VPC attributes. This will detail information such as Security Groups, Route Tables, Network ACL's and S3 Buckets.

The lists are collapsed by default. To reveal the attributes, click the down arrow icon next to the attribute group you would like to view.

Hava analyses the connections and attributes within your cloud environment. For instance, to view which resources belong to a specific security group, expand Security Groups in the Attributes tab and hover over over a security group.

The interactive diagram with display borders around the resources that belong to this security group. ie :

![](/files/FLC9WF9UvBngwFYclLMQ)

#### Resource Attributes

Selecting individual resources on your interactive diagram will display the attributes for that resource in the Attributes Tab and it will also display the connections to and from that resource.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_022.jpg)

Selecting one of the Application Load Balancers in this diagram shows us it is connected to a Web App Firewall and routes traffic to 2 autoscaling groups in separate availability zones.

The attributes tab also tells us all the relevant information about the ALB including the estimated cost.

#### Non Visualised Resources

Hava does not visualise every resource and attribute of your cloud infrastructure. Keeping the infrastructure diagram clean.

Detailing the associated attributes and their values in the attributes tab produces an easily readable diagram but retains all of the important information in a contextual framework that is available to view at any time.

For example, selecting an EC2 Instance you are able to view all of the attributes for the Instance on the right hand Attributes Tab. A number of these attributes are selectable and will allow you to view more details about that attribute :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_023.jpg)

There are a number of items in this attribute list in dark blue text that are selectable. Let's say we want to look at the network interfaces accessing this EC2 instance.

We would select a security group - in this instance "demo-all-servers" which changes the attributes pane to to show the attributes of this security group. In the Infrastructure View diagram this is not visualised, but the attributes for the security group are now shown :

​ ![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_024.jpg)

The Security Group attributes like Ingress / Egress IP addresses and ports and all the connected resources are now visible.

Some of these resources are also selectable so you can view more details pertaining to them.

We can select a Network Interface for instance :

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_025.jpg)

Now we can see all the information relating to the Network Interface even though none of the network interfaces or security groups are visualised on the diagram.


# Cost Estimation

Understanding Hava generated cloud diagram cost estimates.

When viewing hava interactive infrastructure diagrams you will see cost estimates have been calculated and are noted against the environment and detailed in the attributes of individual resources.

These are estimated costs and should only be used as a rough guide to anticipate what your monthly cloud spend is likely to be.

### **How does Hava cost estimation work?**

When you initially view your environment, you will see a Monthly Estimate breakdown displayed next to your diagrams.

![](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_014.jpg)

The cost estimate is also displayed in the attribute pane when individual resources are selected on the diagrams

![In this example an AWS EC2 Instance is selected](https://www.hava.io/hubfs/documentation/getting-started/Getting_Started_View_Diag_023.jpg)

The cost estimates are also displayed alongside every resource in the Hava "List View"

![AWS](/files/AJiG9zXCuOotzPeJ7oBa)

### **How is this cost estimate calculated?**

To estimate the cost of each individual resource, we import the cost price data directly from AWS, Azure and Google Cloud. We then use the attributes of the resources detected in your imported infrastructure to estimate what it would cost to run for 24 hours a day for the entire month.

For example, to get the price for an AWS EC2 Instance, we use the instance type, region and platform to get the "per-hour" pricing which is then extrapolated to give the monthly estimate.

### What is not considered?

Hava currently only matches standard pricing data for the resources detected themselves. Because Hava only detects resources that are present and does not interrogate any data or traffic activity on your network, we cannot estimate or determine the value of data transfer, requests, discounts or other pricing factors that cloud providers will charge for but are not returned in the resource attributes.

We currently estimate costs based on "on-demand" pricing levels and do not take into consideration account reservations or spot pricing.

This means that while the cost estimate provided with your interactive infrastructure diagrams is a good indication of what your environment is likely to cost, the accuracy cannot in any way be considered absolute.

\ <br>


# Diff View - Comparing Diagrams

You can now use Hava to easily identify what has changed in your cloud environments.

Hava monitors connected cloud accounts in the background and updates diagram versions as changes are detected. This is done automatically, no manual intervention or log in is required to update diagrams.

When a change is detected, a new diagram is generated and the superseded diagram is retained in versioning.

{% embed url="<https://www.hava.io/hs-fs/hubfs/versions2023.jpg?width=924&height=634&name=versions2023.jpg>" %}
Hava Diagram Versions
{% endembed %}

The Hava version comparison feature or "Diff View" allows you to select 2 diagrams and using the compare revisions function you can immediately see what changes have been made.

Simply select the first diagram version you wish to compare (Diagram A) and then select 'Compare revisions'

Then from the versions list select the diagram from a point in time you wish to compare diagram A to. This second selection is Diagram B.

<figure><img src="/files/hVpBQo42tiX5gbCwCdIJ" alt=""><figcaption></figcaption></figure>

The diagram you are viewing will temporarily grey out all the resource icons, following that any changed resources will appear on the diagram as either:

* Red - The resource was removed
* Green - The resource was added

This allows you to easily see all the resource changes in seconds.

Diagram A can be any diagram version in the list. As can Diagram B - compare forwards or backwards in time.

Here is a short walkthrough showing the Diff View in action.

{% embed url="<https://youtu.be/_luv01RBMAg>" %}


# Infrastructure

{% content-ref url="/pages/-M-lsaBom0r8BeHhH9sQ" %}
[View Route Tables](/diagnose/infrastructure/view-route-tables)
{% endcontent-ref %}

{% content-ref url="/pages/-M-lsaBpqAU1DzRDf3FO" %}
[View ACLs](/diagnose/infrastructure/view-acls)
{% endcontent-ref %}

{% content-ref url="/pages/-M-lsaBqUkDBZOrU9e--" %}
[View Security Groups](/diagnose/infrastructure/view-security-groups)
{% endcontent-ref %}


# View Route Tables

How to view AWS Route tables and connected resources using Hava interactive network topology diagrams.

Hava gives you the ability to inspect route tables and visualise the connected resources on the diagram.

{% embed url="<https://youtu.be/YBTZYVJoTY4>" %}

To view the route tables, select the cloud icon to the top right of your VPC diagram :

![](https://www.hava.io/hubfs/documentation/How-tos/View_Route_Table.jpg)

This will change the attributes pane to the right of the diagram and show a list of route tables.

![View Route Tables](https://www.hava.io/hubfs/assets/2020UI/View_Route_Tables.png)

To see the connected resources visualised, you can hover your mouse pointer over the desired route table and the connected resources will be highlighted on the diagram.

The background of subnets will change colour and individual connected resources will have a green border.

![](https://www.hava.io/hubfs/documentation/How-tos/Show_Route_Table_Connections.jpg)


# View ACLs

How to find and view your Network Access Control Lists using Hava Diagrams.

**How to view Network Access Control Lists (ACLs)**

{% embed url="<https://youtu.be/bYaN5jX1um8>" %}

To view Network ACLs in an AWS environment, open up an infrastructure view diagram and click the padlock icon at the top right of the VPC.

This will change to attribute pane on the righ&#x74;**-**&#x68;and side to show security groups, route tables, and network ACLs

Hover your cursor over a Network ACL in the list and the attached subnets will be highlighted on the interactive diagram.

![How to View Network ACLs](/files/JatQReBoIyih5GoNCWa6)

You can view more details relating the to the individual ACL by clicking on the ACL name.

The Attribute pane will change to display the ACL details :

![](https://www.hava.io/hubfs/documentation/How-tos/Network_ACL_Details.jpg)


# View Security Groups

How to easily view what resources belong to a security group using Hava automated diagrams.

You are able to visually see all the resources in an AWS VPC by hovering your cursor over the security groups in the attribute pane.

The connected resources belonging to the security group you are hovering over will be highlighted with a green border. In the below interactive diagram, five Elastic Load Balancers and seven EC2 Instances are highlighted when hovering over the 'demo-internal-servers' security group.

![](https://www.hava.io/hubfs/documentation/How-tos/Security_Group_Connections.jpg)

Further details can be viewed by selecting the security group from the list in the attribute pane.

This will display all the resources both visualised and not. For instance EC2 instances contained in autoscaling groups and network interfaces connected to this security group, that are not visualised on the diagram can be viewed in this list.

![](https://www.hava.io/hubfs/documentation/How-tos/Security_Group_Connection-Attributes.jpg)

You are able to continue drilling down through the resource attribute data by clicking on the resource you are interested in.


# Environment Notes

The ability to add notes to each of your auto generated architecture diagrams is provided, so you can add whatever additional information you like to your diagrams.

Notes are accessed in the side panel to the right of each diagram

<figure><img src="/files/gll0Z4t7NqbHL6nnE0bU" alt=""><figcaption></figcaption></figure>

When you select Notes from the accordion side panel menu the latest 10 environment notes are displayed from newest to oldest.

If no notes are present on this diagram you will see this:

<img src="https://www.hava.io/hs-fs/hubfs/No_Notes.jpg?width=356&#x26;height=423&#x26;name=No_Notes.jpg" alt="No_Notes" height="423" width="356">

You can now add a comment and hit the post comment button.

<img src="https://www.hava.io/hs-fs/hubfs/Multiple_Notes.jpg?width=371&#x26;height=576&#x26;name=Multiple_Notes.jpg" alt="Multiple_Notes" height="576" width="371">

To delete a note, click the garbage bin icon.

Once you have more than 10 notes against a diagram, you will get a See More option at the bottom of the notes list. Click that to load the next 10 environment notes.

### User Tagging / Mentions to Email

You can mention team members in notes by typing @ followed by their name. A drop down will appear for you to select the known team member.

<figure><img src="/files/TDuftkWGgo8yyddGXAGL" alt=""><figcaption><p>Mentions in Notes</p></figcaption></figure>

When you mention someone like this, they will receive an email notification that they have been tagged in the environment notes.

<br>

<figure><img src="/files/hc5C1SKuAJeJ6DxvxCnG" alt=""><figcaption><p>Email from Hava when a user is tagged in environment notes</p></figcaption></figure>


# Embed

Embed Hava diagrams anywhere

### Hava allows diagrams to be embedded anywhere that supports iframes or images.

#### No plug-ins, special API access or complex code required.

Hava will allow you to share individual diagram views using code snippets

Typically used for :

* Internal Intranets.
* Wikis and Documentation.
* Development and Support Tickets.
* Dashboards.

One major benefit of embedding your Hava diagrams outside of the application is that viewers do not need a Hava log in in order to view the diagrams. This means you can grant read-only access to diagrams either with or without sensitive metadata and can maintain the protection of other environments or projects being mapped in your Hava account.

There are three options you can choose from to embed your Hava diagrams into other applications or web properties:

**Option 1 : Embed** - This option provides a code snippet that allows you to embed a complete interactive diagram into another web property just as it appears within Hava. It will be fully interactive with the attribute pane and metadata viewable.

{% hint style="info" %}
One word of caution : Since potentially sensitive information like security group information or IP addresses can be viewed on the diagram attributes, you should consider this carefully before embedding your diagrams on publicly accessible web properties using the full embed.
{% endhint %}

**Option 2 : Embed Light** - This provides a complete interactive diagram without the attribute pane or potentially sensitive metadata. This option is a safer option for publicly accessible diagrams.

**Option 3: PNG Embed** - This links to a PNG image of your diagram that can be placed almost anywhere. It will export with any configured view options, such as names or connections displayed.

Which ever of the three options you choose, the embedded diagram will self update. So as changes in your environment are detected, Hava updates your diagrams and also the endpoint of the embedded link, even the PNG image. This means you only have to embed the diagram once and whatever application or web property is hosting the embed will always show the latest representation of your cloud environment.

{% embed url="<https://youtu.be/vD1eSwKqHl4>" %}

#### How to embed Hava cloud diagrams

Open the desired diagram (and select the view you wish to embed)

![Embedded\_Viewer](/files/9HShUgQ7BY0cUQcBGk88)

Select the Share button and generate the required code snippet.

![Hava Embed](/files/kZtUQCIu4JWgpMNsyfXR)

Copy the snippet paste the embed code into any property that supports the iframe or html code

To see an example of the embedded viewer in action, [Visit this page](https://www.hava.io/hava-embedded-diagram-viewer)

The use cases for the embedded viewer are many and varied and as long as the target site or application supports iframe embeds then you will be able to embed your fully interactive AWS, GCP Azure and Kubernetes diagrams.

There are currently 3 embed options;

* Embed - place a fully interactive diagram with attribute metadata visible
* Embed Light - interactive diagram with sensitive data redacted
* Embed PNG - a static snapshot of the current diagram canvas.

The embed endpoint always shows the current diagram, so as your architecture changes, so do the diagrams you have embedded (no action necessary)

For example, you can use the embed block in notion.so to place a fully interactive Hava diagram into a page in Notion.

![Hava Interactive Diagram in a Notion Page](/files/NkqttTgqSyqPNDhgQFWS)


# Exporting Diagrams

Any diagrams that are automatically generated or created using the custom search commands can be exported for use outside of the Hava application.

<figure><img src="/files/5K8Var4t43OlACXAIjqB" alt=""><figcaption><p>Export Options</p></figcaption></figure>

Exports will contain the diagram canvas details as they are displayed at the time of the export, so will include or exclude, names, connections and custom layout spacing you have applied using the view options controls.

#### PDF EXPORT

Hava exports to PDF format. By selecting the PDF export option, Hava will generate the PDF file in the background and then when ready a download button will show under the export options allowing you to download your PDF

<figure><img src="/files/qY0W8s86TM4y12EJdVI7" alt=""><figcaption><p>Cloud diagram PDF</p></figcaption></figure>

#### PNG EXPORT

Exporting to PNG is exactly the same process. Select PNG and Hava will prepare the file to download and once ready a download button will appear.

<figure><img src="/files/nRiD2JwCg0hFCPsYTtzl" alt=""><figcaption><p>Hava export to png</p></figcaption></figure>

#### VSDX Export - Edit Hava Diagrams with Visio or Draw\.io

The VDSX export option creates a file you can open with Microsoft Visio. A popular and free alternative draw\.io (diagrams.net) will also open the exported file.

Each resource becomes an editable icon on the drawing canvas. You can move things around, add annotations, and add or remove resources. The VSDX export gives you a head start when doing redesign work, since the base diagram reflects exactly what you have running now without you having to manually draw it.

<figure><img src="/files/Fu3pNU9n0NTq9oC67biD" alt=""><figcaption><p>Hava Diagram Exported to Draw.io</p></figcaption></figure>

CSV and JSON Exports

These two options export the settings data used to create your Hava diagram. You can take the CSV or JSON data and do with it whatever you like.

<figure><img src="/files/mO9flqA3pQ9HzhnelilL" alt=""><figcaption><p>Exported JSON</p></figcaption></figure>


# Edit


# Draw\.io

How to export your automatically generated diagrams to draw\.io for editing.

Out of the box, Hava creates logically laid out network topology diagrams derived from the cloud accounts you connect.

Once you connect your AWS, Google Cloud or Microsoft Azure cloud account credentials to Hava, the diagrams are automatically generated based on the resources and attributes detected in the cloud console configuration.

This provides you with an accurate representation of how your cloud infrastructure is configured.

Sometimes however, you may need to enhance or embellish diagrams for use in a presentation or management report which is why Hava provides the functionality to export diagrams in a number of formats including VSDX (Visio)

Not everyone has access to a Visio licence however, which is why we created the following instructions on using **draw\.io** to import and modify Hava diagrams

{% embed url="<https://youtu.be/jzG_JdWHl90>" %}

### How to create a draw\.io diagram using hava.io

The first step is to export your diagram as a VSDX file.

Open the required diagram, select "Export" from header menu and then select "VSDX"

![Export VSDX Visio formatted file](/files/N4BHE8bCxsDYfVdY2wMy)

Hava will prepare the VDSX template data and prompt you to download.

Download the file to your computer.

Now open up <https://draw.io>

![](/files/5PNzvAkiV9DiW2euGyW8)

Select File > Import From > Device...

![](https://www.hava.io/hubfs/assets/Drawio_import.jpg)

Navigate to the VSDX file you saved and select it. Draw\.io will reconstruct the Hava diagram in editable form.

![Hava Diagram Exported to Draw.io ( Diagrams.net )](/files/Fu3pNU9n0NTq9oC67biD)

You are now able to copy & paste assets already on the diagram, add new ones from the available icon sets within draw\.io, add text or shapes or delete anything already on the diagram.

**One word of caution.** The Hava export function exports a native Visio file. How Draw\.io processes the VDSX import is beyond our control, however the testing we have conducted has always yielded an accurate facsimile of the diagrams generated in Hava.

Should you spot any anomalies please let us know.

This method provides a quick and easy way of providing you with the ability to edit and embellish your AWS, GCP and Azure diagrams without having to draw them from scratch.<br>


# Inviting Users

If you have a Teams plan you can invite other users to your Hava account. By default all invited users are assigned the **Member** [account role](/collaboration/rbac), which gives them basic account access. To give them access to workspace content you will need to either assign them to a [workspace](/collaboration/workspaces) directly or add them to a [team](/collaboration/teams) that is assigned to a workspace.

To invite and add users, click on **Account Settings** using the dropdown at the top right of the page and click on the **Members** link.

### Invite User

Enter the email address of the member you want to invite, select a role, and click **Add**.

![](/files/IeBOdxmta1zU9eZ2dH3i)

**Existing User:** If their email address exists in our database, they'll be sent an email letting them know you've invited them to your account. Once they follow the link in the email they'll be able to access your account.

**New User:** If their email is not in our system, they'll be sent an email inviting them to join Hava. Once they follow the link in the email and set up their account they'll be able to switch between their account and yours.

If the user doesn't receive their invite email you can click **Re-invite** to resend it.

### Assigning an Account Role

After inviting a user you can change their account role from the Members page. Click their current role to open the role selector and choose a new role. See [Roles & Permissions](/collaboration/rbac#account-roles) for a description of each role.

### Assigning Workspace Access

Newly invited users are automatically added to the default workspace as a **Viewer**, so they can see its content straight away. If you have created additional workspaces, you will need to add them to those separately — they won't have access by default.

You can grant access to additional workspaces directly or via a team:

* **Direct:** Go to the workspace in Account Settings and add the user with a workspace role. See [Workspaces](/collaboration/workspaces#adding-a-user-to-a-workspace).
* **Via a team:** Add the user to a team, then assign that team to a workspace. See [Teams](/collaboration/teams).

### Access The Primary Account

In Hava every user has their own personal account with its own default workspace. When you invite a user to Hava and they sign up they will have their own personal account, as well as access to your account.

This can lead to confusion after being invited to your account when you first log in. You can switch between accounts you are a member of from the **Account Settings** area. You can use the workspace dropdown in the top menu to switch between workspaces across any of the accounts you belong to.

### Trial & Upgrade Notification

If you don't already have a paid personal account and you've been invited to a Hava team account as a new user.

**When you first log in, you will see a notification that states**:

* You have X many days left on your trial
* Your trial has expired. Please upgrade.

![Trial Warning on Personal Account](/files/1BfCQjE35eyrXM4D1iaA)

{% hint style="info" %}
This can be ignored as it's associated with your single personal account and not the team account you've been invited to.
{% endhint %}

### Switch Between Accounts and Workspaces

Hava supports belonging to multiple accounts at once. To switch accounts, go to **Account Settings** and select the account you want from the account switcher. From there you can manage workspaces, teams, members and other account settings based on your role.

You can use the **workspace dropdown** in the top menu to move between workspaces. The workspace dropdown shows all workspaces you have access to across the account you are currently viewing.

<figure><img src="/files/zPjUrC9jo063SKxaCRAc" alt="Workspace selector dropdown at the top of the Hava interface"><figcaption><p>Use the workspace dropdown to switch workspaces</p></figcaption></figure>


# Roles & Permissions

Control what each user can do in your Hava account using role-based access control.

Hava uses role-based access control (RBAC) to manage what each user can do. Roles operate at two scopes:

* **Account roles** — govern account-level administration such as managing users, teams, workspaces, billing, and audit logs.
* **Workspace roles** — govern access to workspace content such as sources, environments, projects, reports, and alerts.

Every user has exactly one account role and can have a different workspace role in each workspace they are assigned to.

{% hint style="info" %}
RBAC is available on Teams and Enterprise plans.
{% endhint %}

## Account Roles

When a user is [invited to your account](/collaboration/inviting-users), they are assigned the **Member** role by default. You can change this role at any time from the Members page in Account Settings.

### Role overview

| Role                | Description                                                                                                                                                                                            |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Owner**           | Full control over the account, including all billing, user management, teams, workspaces, and settings.                                                                                                |
| **Account Admin**   | Manages users, teams, and workspaces. Can invite and remove users, create and manage teams, and create workspaces. No billing access.                                                                  |
| **Member**          | Base account role. Can read account information. Workspace access is controlled separately by workspace role.                                                                                          |
| **Billing Manager** | Full access to billing and subscription management. No access to workspace content.                                                                                                                    |
| **Auditor**         | Read-only access to the account audit log, member list, SSO configuration, and job logs. For auditing workspace content, assign a [WorkspaceViewer](/collaboration/workspaces) workspace role as well. |

### What each role can do

| Capability               | Owner | Account Admin | Member | Billing Manager | Auditor |
| ------------------------ | :---: | :-----------: | :----: | :-------------: | :-----: |
| Invite & remove users    |   ✓   |       ✓       |        |                 |         |
| Manage teams             |   ✓   |       ✓       |        |                 |         |
| Create workspaces        |   ✓   |       ✓       |        |                 |         |
| View SSO configuration   |   ✓   |       ✓       |        |                 |    ✓    |
| Update SSO configuration |   ✓   |               |        |                 |         |
| View audit log           |   ✓   |       ✓       |        |                 |    ✓    |
| Export audit log         |   ✓   |               |        |                 |    ✓    |
| Billing & subscriptions  |   ✓   |               |        |        ✓        |         |
| Delete account           |   ✓   |               |        |                 |         |

### Assigning account roles

1. Click the user dropdown in the top right and go to **Account Settings**.
2. Click **Members**.
3. Find the user you want to update and click their current role to open the role selector.

<figure><img src="/files/SetBaVI0EY6VFmNtGTqr" alt="Role selector dropdown showing available account roles"><figcaption><p>Account role selector</p></figcaption></figure>

4. Select the new role and confirm.

{% hint style="info" %}
Only Owners and Account Admins can change account roles.
{% endhint %}

## Workspace Roles

Workspace roles control what a user can do inside a specific workspace. A user (or a [team](/collaboration/teams) of users) can be assigned a different workspace role in each workspace they belong to.

See [Workspaces](/collaboration/workspaces) for how to create workspaces and assign users and teams to them.

### Role overview

| Role           | Description                                                                                                                                                                          |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Admin**      | Full control within the workspace. Can manage workspace settings, members, sources, projects, environments, reports, alerts, and tags. Can delete the workspace.                     |
| **Power User** | Can create and manage sources, environments, and views. Cannot delete the workspace, manage workspace members, delete sources, roll back environment revisions, or manage alerts.    |
| **Editor**     | Can update existing environments and views. Read-only access to sources, reports, and alerts. Can add notes and annotations. Cannot create or delete environments or manage sources. |
| **Viewer**     | Read-only access to all workspace content. Can export environments and views.                                                                                                        |
| **Guest**      | Minimal access. Can only view shared environments.                                                                                                                                   |

### What each role can do

| Capability                      | Workspace Admin |     Power User     |   Editor  |   Viewer  |    Guest    |
| ------------------------------- | :-------------: | :----------------: | :-------: | :-------: | :---------: |
| Delete workspace                |        ✓        |                    |           |           |             |
| Manage workspace members        |        ✓        |                    |           |           |             |
| Create & delete sources         |        ✓        | Create/update only |           |           |             |
| Sync sources                    |        ✓        |          ✓         |           |           |             |
| Manage projects                 |        ✓        |      Read only     | Read only | Read only |             |
| Create & delete environments    |        ✓        |          ✓         |           |           |             |
| Update environments             |        ✓        |          ✓         |     ✓     |           |             |
| View environments               |        ✓        |          ✓         |     ✓     |     ✓     | Shared only |
| Export environments             |        ✓        |          ✓         |     ✓     |     ✓     |             |
| Roll back environment revisions |        ✓        |                    |           |           |             |
| Add notes & annotations         |        ✓        |          ✓         |     ✓     |           |             |
| Manage reports                  |        ✓        |     Read/export    | Read only | Read only |             |
| Manage alerts                   |        ✓        |      Read only     | Read only | Read only |             |
| View cost usage                 |        ✓        |          ✓         |     ✓     |     ✓     |             |
| Manage tags & filters           |        ✓        |    Create/update   | Read only | Read only |             |


# Workspaces

Organise your cloud infrastructure and control access using workspaces.

Workspaces are isolated areas within your Hava account. Each workspace has its own sources, environments, projects, reports, and alerts. Users only see the content of workspaces they have been assigned to.

A default workspace is created automatically when your account is set up. Owners and Account Admins can create additional workspaces and assign users and teams to them with specific [workspace roles](/collaboration/rbac#workspace-roles).

{% hint style="info" %}
Workspaces are available on all Hava plans. Assigning roles to workspace members requires a Teams or Enterprise plan.
{% endhint %}

## Creating a Workspace

1. Click the user dropdown in the top right and go to **Account Settings**.
2. Click **Workspaces**.

<figure><img src="/files/pZN8z1fBt89kvjwGPV8Q" alt="Workspaces list in Account Settings"><figcaption><p>Workspaces in Account Settings</p></figcaption></figure>

3. Click **Create Workspace**.
4. Enter a name and optional description, then click **Create**.

<figure><img src="/files/RsbTI3UVsdkjLqM7zgAJ" alt="Create Workspace dialog with name and description fields"><figcaption><p>Create Workspace dialog</p></figcaption></figure>

## Switching Between Workspaces

A workspace selector appears at the top of the page. Click it to switch to a different workspace. The environment list, sources, reports, and alerts all update to show the selected workspace's content.

<figure><img src="/files/zPjUrC9jo063SKxaCRAc" alt="Workspace selector dropdown at the top of the Hava interface"><figcaption><p>Workspace selector</p></figcaption></figure>

## Managing Workspace Members

Users and [teams](/collaboration/teams) can be assigned to a workspace with a workspace role. A user can belong to multiple workspaces, each with a different role.

### Adding a user to a workspace

1. Open **Account Settings** and go to **Workspaces**.
2. Click the workspace you want to manage.

<figure><img src="/files/nKNpDZlxwg2Uivn0EZxI" alt="Workspace detail page showing members and teams sections"><figcaption><p>Workspace detail page</p></figcaption></figure>

3. Under **Workspace Members**, select the user and choose their [workspace role](/collaboration/rbac#workspace-roles).
4. Click **Add Member**.

<figure><img src="/files/PKpE4CCvaqitGZinC6of" alt="Add Member dialog with user selector and workspace role dropdown"><figcaption><p>Add Member dialog</p></figcaption></figure>

### Adding a team to a workspace

Adding a team assigns all current and future members of that team to the workspace with the selected role.

1. Open **Account Settings** and go to **Workspaces**.
2. Click the workspace you want to manage.
3. Under **Workspace Members**, click **Add Team**, select the team and choose the [workspace role](/collaboration/rbac#workspace-roles) to apply to team members.
4. Click **Add Member**.

If a user belongs to both a team and is also added individually to the same workspace, the highest of their two roles applies.

### Removing a user or team from a workspace

Open the workspace in Account Settings, find the user or team in the list, and click **Delete**. Removing a team from a workspace revokes access for all team members who were granted access through that team.

## Moving Sources Between Workspaces

If you have the appropriate role in two or more workspaces within the same account, you can move a source from one workspace to another. You need at least the **Workspace Power User** role in both the source workspace and the destination workspace.

Moving a source transfers all of its environments, resources, views, and associated data to the destination workspace.

1. Go to **Sources** in the workspace that currently contains the source.
2. Click the '...' options menu next to the source you want to move.

<figure><img src="/files/VPOAbXHQ84e4jtziY0cn" alt="Source options menu with Change Workspace option highlighted"><figcaption><p>Source options menu</p></figcaption></figure>

3. Select **Change Workspace**.
4. Choose the destination workspace from the list, then confirm.

<figure><img src="/files/SWczEYzfJTNhXhYIErOh" alt="Change Workspace dialog with destination workspace selector"><figcaption><p>Move to Workspace dialog</p></figcaption></figure>

Hava will begin moving the source and all of its environments, resources, and views to the destination workspace. While the move is in progress the source cannot be synced or modified. You will be notified in the UI when the move is complete.

{% hint style="info" %}
Sources can only be moved between workspaces within the same account.
{% endhint %}

## Deleting a Workspace

{% hint style="warning" %}
A workspace cannot be deleted while it still contains sources. You must first delete or [move](#moving-sources-between-workspaces) all sources out of the workspace before it can be removed.
{% endhint %}

Only users with the **Workspace Admin** role (or an account **Owner**) can delete a workspace.

1. Open **Account Settings** and go to **Workspaces**.
2. Click the workspace you want to delete.
3. Click **Delete Workspace** and confirm.

## Workspace Roles

See [Roles & Permissions](/collaboration/rbac#workspace-roles) for a full breakdown of what each workspace role can do.

{% content-ref url="/pages/Ff6OolTl8NhPhYkcFohb" %}
[Roles & Permissions](/collaboration/rbac)
{% endcontent-ref %}


# Teams

Group users into teams to simplify assigning them to workspaces.

Teams are groups of users. You can assign a team to a [workspace](/collaboration/workspaces) with a workspace role, which grants every member of that team access to the workspace. This makes it easy to manage access for large groups without adding users one by one.

Teams do not carry permissions on their own — permissions are always determined by the [workspace role](/collaboration/rbac#workspace-roles) assigned when the team is added to a workspace.

{% hint style="info" %}
Teams are available on Teams and Enterprise plans.
{% endhint %}

## Creating a Team

1. Click the user dropdown in the top right and go to **Account Settings**.
2. Click **Teams**.

<figure><img src="/files/5D8cQnRiCLYagrepnxvT" alt="Teams list in Account Settings"><figcaption><p>Teams in Account Settings</p></figcaption></figure>

3. Click **Add Team**, enter a name, and click **Create**.

<figure><img src="/files/GPJPoKaFZPfZJtYgZgyU" alt="Create Team dialog with name field"><figcaption><p>Create Team dialog</p></figcaption></figure>

## Adding Members to Teams

Once your team is created you can assign [previously invited users](/collaboration/inviting-users) to it.

Click the **Select user** dropdown, select the user you want to add, then click **Add User**.

<figure><img src="/files/eHPTlCN1PHbMnscxVmRm" alt="Add user dropdown with a user selected and the Add User button"><figcaption><p>Adding a member to a team</p></figcaption></figure>

## Removing a Member from a Team

Open the team in Account Settings and click the delete button next to the user you want to remove.

Removing a user from a team revokes any workspace access they were granted through that team (unless they were also added to those workspaces individually).

## Assigning a Team to a Workspace

See [Workspaces — Adding a team to a workspace](/collaboration/workspaces#adding-a-team-to-a-workspace) for instructions on how to give a team access to a workspace with a specific role.

{% content-ref url="/pages/H105LqpWS1sOwkKqzKTW" %}
[Workspaces](/collaboration/workspaces)
{% endcontent-ref %}


# Disabling users

To remove a user from your account, go to **Account Settings** using the dropdown at the top right of the page and click **Members**.

Find the user you want to remove and click the delete button next to their email address.

<figure><img src="/files/qqjjlonHSSsQtG9gI7YO" alt="Members list with delete button highlighted next to a user"><figcaption><p>Removing a user from the Members page</p></figcaption></figure>

This removes the user from the account entirely, revoking their access to all workspaces and teams they were a member of. Their personal Hava account remains intact and they will still have access to any other Hava accounts they belong to.


# SSO/SAML


# Overview

Setting up SSO access to your Hava account

You can use SSO to protect access to your organisation's data in Hava. Hava currently supports SAML and OIDC providers.

### **Adding a Provider**

To configure SSO for your account you must have the **Owner** or **Account Admin** account role. Head over to Account Settings and select SSO Config to get started. At the moment Hava supports custom SAML and OIDC providers, but platform specific apps will be available soon.

<figure><img src="/files/V3RsNAzOpeFbtC3dv1cp" alt=""><figcaption></figcaption></figure>

For instructions on setting up your provider you can see the following pages:

* [SAML](/collaboration/sso-saml/saml-setup-for-okta)
* [OIDC](/collaboration/sso-saml/oidc-setup-for-okta)

### **Enabling a Provider**

![](/files/-MknZyZETASlsa0fGdH5)

Once you’ve configured your provider your team members will still be able to login to your account with their standard user and password, as well as the SSO provider. This allows you to test and update the details, or remove them if they are no longer required.

Once you have defined your configuration you can enable your provider - this will prevent users accessing your account unless they are logged in via your SSO provider.

![](/files/F2QbYruvCeDPNSc0N9jB)

Once a provider is enabled all users will need to login through your IDP to access your account, except for users with the **Owner** account role. If you need to modify or delete your configuration you will first need to disable the provider.

### **Disabling and Deleting SSO**

If you no longer require a configured SSO provider, or you’d like to move to a new one, you can delete your existing configuration. Your provider must be disabled for the delete option to appear.

![](/files/zr3wYpfCKFinuqrKF51z)

Once your SSO provider is removed your team members will once again be able to access your account through password login.

## FAQ

#### **Do you support auto-provisioning?**

Not at this time. Any users you wish to use SSO must be first invited to your account. Once they accept the invite they will be able to access your account.

#### **What happens if a user leaves the company?**

You will need to make sure they are removed from your account via the Members page in Account Settings. If they are no longer in your SSO IDP they will not be able to login via SSO to access your account as well.

#### **Can we use multiple SSO providers?**

At the moment Hava only supports a single IDP per account, but we are looking to add support for more in future.

#### **Can I import my groups from my IDP?**

Teams must be created in Hava and users assigned manually at this time.

#### **I can’t see the Single Sign On option in my account**

SSO is currently only available on Business plans and is currently in beta. Contact us at <support@hava.io> if you would like to try it out!


# Azure AD - SAML Setup

Guide for setting up SSO with Azure AD using SAML

The Azure AD SSO integration allows for a centralized and secure login process for businesses that utilise Azure AD as their identity provider.

Azure AD relies on `Enterprise Applications` to configure SSO

## Step by Step Guide

### 1. Go to Account Settings

On the top right, press the account preferences icon <img src="/files/NjXYp0bOGCrZMglWtiQP" alt="" data-size="original"> and select account settings from the drop-down menu

![](/files/dZZ2sQRyx3gV9lpFiJON)

### 2. Select SSO Config

From the menu on the left, select SSO Config to bring up the SSO Configuration screen

![](/files/V3RsNAzOpeFbtC3dv1cp)

### 3. Select SAML

Azure AD uses SAML as the way to integrate their identity platform with Hava. From the two choices ('SAML' and 'OIDC') select SAML

![](/files/Uw6Poumio6ZBkHf5RMx3)

### 4. Take note of the Service provider details

You should be presented with a screen showing you two sections, Identity Provider, and Service Provider. In this case the Identity Provider is represented by Azure AD and the Service Provider is Hava.

Take note of the details in the Service Provider section, as we will use these when setting up Azure AD.

![](/files/ATBDPKrBW2TdzPNP4PoH)

### 5. Navigate to Azure Active Directory

In the Azure Portal, go to the Azure Active Directory service, and select Enterprise applications from the menu on the left side

![](/files/s5EM3vKLImF1CH1qzYkI)

### 6. Start creating a new application

Click the create application button on the top of the screen to start the process for setting up a new Enterprise application.

![](/files/7CNYrtFfPdvvICWTUKiA)

### 7. Select Create your own application

Have is not set up with an easy integration with Azure AD yet (this is coming soon), so we have to create our own application. Press the 'Create your own application' button on the top of the page

![](/files/cicroHFmspDAkRTp9ftO)

### 8. Name your application

A pane will open on the right side of the screen asking you to name the application and select one of 3 choices of what you are looking to do with the application.

* enter `hava.io` as the name
* Select `Integrate any other application you don't find in the gallery (Non-gallery)` from the choices
* Click Create on the bottom of the pane

This will create the application for you and bring you to the resource in Azure AD once it has completed.

![](/files/jTnBIItQcPipYNB3gC5C)

### 9. Go to Single sign-on

On the menu on the left, select `Single sign-on` to open the single sign-on configuration page.

Select SAML as the single sign-on method

![](/files/LXcyIUlhbIGokoQMZUgn)

### 10. Basic SAML Configuration

You should see a page asking you to fill in details to `Set up Single Sign-On with SAML`

In the Basic SAML configuration box, press edit and fill in the details that you took note of earlier in the Hava SAML setup page (Service Provider)

Map the values like this:

| Azure AD Name                              | Hava Name                      |
| ------------------------------------------ | ------------------------------ |
| Identifier (Entity ID)                     | Issuer (Entity ID)             |
| Reply URL (Assertion Consumer Service URL) | Assertion Consumer Service URL |
| Sign on URL                                | Login URL                      |
| Relay State (Optional)                     | n/a                            |
| Logout Url                                 | n/a                            |

{% hint style="warning" %}
When adding the Reply URL and the Sign on URL, please add a `/` before the `?` in the url. Azure AD requires this to map urls correctly.

`https://app.hava.io/users/auth/saml/callback?id=<id>`\
to\
`https://app.hava.io/users/auth/saml/callback/?id=<id>`
{% endhint %}

Once this is complete, press save on the top of the screen and go back to the Single sign-on screen by pressing the `X` in the top right corner

![](/files/hFCvby1ZuvSf9N3s2lW9)

### 11. Set up attributes

Attributes are used to map user details between Azure AD and Hava. We need to change the `Unique User Identifier` to be email, rather than the default of userprinciplename.

Press the edit button, then click on the `Unique User Identifies` to modify the source attribute

Change it to `user.mail`

![](/files/NOAIyoxqFHCDgRYXQQec)

### 12. Download Certificate and take note of the values in the next section

In the 3rd box, download the Certificate (Base 64) to your machine and open it in a text editor to be ready for the next stage

The 4th box contains the values for setting up the SAML configuration for the Identity Provider in Hava.

### 13. Go back to hava and press Add SAML Config

Copy the values from the 4th box into the form in Hava using these mappings

| Hava Value                  | Azure AD Value      |
| --------------------------- | ------------------- |
| Identity Provider Entity ID | Azure AD Identifier |
| Identity Provider SSO URL   | Login URL           |

Last step before testing is to insert the downloaded certificate into the text area. Make sure to copy the whole content of the file, including the `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` lines\
\
Press save.

### 14. Enable and test

On the bottom of the SSO config page in Hava there is a button to enable SAML. Once this is done, you are ready to test your SSO login from Azure AD.

{% hint style="info" %}
Test this in a private browser window to make sure there is no cookies that cause you to be logged in automatically
{% endhint %}

![](/files/y6AJziOdG5sdQkN7dcs4)


# Azure AD - OIDC Setup

Guide for setting up SSO with Azure AD using OIDC

The Azure AD SSO integration allows for a centralised and secure login process for businesses that utilise Azure AD as their identity provider.

OICD allows you to set up an application in AzureAD to manage access to accounts in Hava.

## Step by step guide

### 1. Go to Account Settings

On the top right, press the account preferences icon <img src="/files/NjXYp0bOGCrZMglWtiQP" alt="" data-size="original"> and select account settings from the drop-down menu

![Open Your Account Settings](/files/dZZ2sQRyx3gV9lpFiJON)

### 2. Select SSO Config

From the menu on the left, select SSO Config to bring up the SSO Configuration screen

![Select SSO Config](/files/V3RsNAzOpeFbtC3dv1cp)

### 3. Select OIDC

Azure AD can use SAML or OIDC as the way to integrate their identity platform with Hava. From the two choices ('SAML' and 'OIDC') select OIDC.

![](/files/Uw6Poumio6ZBkHf5RMx3)

### 4. Take note of the Service provider details

You should be presented with a screen showing you two sections, Identity Provider, and Service Provider. In this case the Identity Provider is represented by Azure AD and the Service Provider is Hava.

Take note of the `Sing-in Redirect URL` attribute in the Service Provider section, as we will use these when setting up Azure AD.

<figure><img src="/files/Ek4ZV6IV4yyMC3J3ma0j" alt=""><figcaption></figcaption></figure>

### 5. Navigate to Azure Active Directory

In the Azure Portal, go to the Azure Active Directory service, and select `App registrations` from the menu on the left side.

<figure><img src="/files/B1nJnfK8YN0jC5u2FOhX" alt=""><figcaption></figcaption></figure>

### 6. Start creating a new registration

Click the `New registration` button on the top of the screen to start the process for setting up a new application registration.

<figure><img src="/files/0cIVwUVZrkMS10eV94Fc" alt=""><figcaption></figcaption></figure>

### 7. Register Application

You will be presented with a form where we will configure two values:

* Give the application a name that people will recongnize (e.g. hava.io)
* In the optional `Redirect URI`
  * Select `Web` as the platform
  * And put in the `Sign-in Redirect URL` from the Hava OIDC configuration screen

Finally press `Register` on the bottom of the form. Leave the other values as they are.

<figure><img src="/files/hiSDAfAFx6Jj9wFptqI0" alt=""><figcaption></figcaption></figure>

### 8. Create a secret

Next we need to create a secret to secure the connection between Hava and AzureAD.

On the left menu, select `Certificates & secrets` and then under `Client secrets` click `New client secret`

<figure><img src="/files/ZdQWviZuQMAobNz4OnSu" alt=""><figcaption></figcaption></figure>

### 9. Configure and Save secret

In the pane that opens, give the secret a descriptive name and select the expiry for the key

Press Add to save the secret.

<figure><img src="/files/rRFG7hTb2GkddHhYvxt9" alt=""><figcaption></figcaption></figure>

### 10. Save the secret key

The `value` attribute contains the secret key that we need to provide to Hava, save that. Ignore the `Secret ID` , we will not be using that.

<figure><img src="/files/B8DQb7CacdNNAZBNtUML" alt=""><figcaption></figcaption></figure>

### 11. Get Application Details

On the overview page there are two values we will need.

Save the `Application (client) ID` and the `Directory (tenant) ID` values, we will use those in the next step

<figure><img src="/files/KdBsmN0joWnS9woKXsIr" alt=""><figcaption></figcaption></figure>

### 12. Configure OIDC

Go back to Hava and press the `Add OIDC Config` button

In the form that comes up add these values:

* **Identity Provider Host:** `login.microsoftonline.com/TENANT_ID/v2.0` where `TENANT_ID` is substituted with the `Directory (tenant) ID` from step 11
* **OIDC Client Id:** `Application (client) ID` from step 11
* **OIDC Client Secret:** `value` from step 10

Press `Save` to save the configuration.

<figure><img src="/files/Pf7GV34oKyvOOhDCma4H" alt=""><figcaption></figcaption></figure>

### 13. Enable Configuration

Last step is to press the green `Enable` button on the OIDC Configuration page. Once this is done, you are ready to test the SSO integration from Azure AD.

<figure><img src="/files/F2QbYruvCeDPNSc0N9jB" alt=""><figcaption><p>Enable SSO</p></figcaption></figure>


# Okta - SAML Setup

Guide for setting up SSO with Okta using SAML

This guide will set up a custom Okta SAML Application that will allow your users to login to Hava. These steps can be followed for most SSO identity providers, though the field names may be different. Custom apps will be coming soon.

1. Log into Hava and head to your Account Settings. From there select SSO Config, then click SAML on the protocol selection page. This will show you the Service Provider values you will need to enter into Okta
2. Log into Okta and click Applications → Create App Integration
3. Select SAML 2.0 and click Next
4. Name the app Hava and click Next
5. Use the Service Provider values from the Hava SSO SAML section to complete the fields on this page:
   1. Single Sign on URL is **Assertion Consumer Service URL**
   2. Audience URI is **Issuer (Entity ID)**
   3. Default RelayState is also **Issuer (Entity ID)**
   4. Name ID format is set to EmailAddress
6. Leave the rest as is and click Next
7. Select Okta customer and click Finish
8. Click View Setup Instructions to see the information required for Hava
9. Head back to the Hava SSO SAML config page and select Add SAML Config
10. Enter the config values from the Okta setup instructions:
    1. Identity Provider Entity ID is **Identity Provider Issuer**
    2. Identity Provider SSO URL is **Identity Provider Single Sign-On URL**
    3. Public x509 Certificate is **X.509 Certificate**
11. Click Save to complete the setup

You can now either test the login via your Okta App page, or by heading to the Login URL displayed in the Service Provider details in Hava. Once you have confirmed the configuration works you can then Enable your provider to limit logins to SSO only for your account.


# Okta - OIDC Setup

Guide for setting up SSO with Okta using OICD

This guide will set up a custom Okta OIDC Application that will allow your users to login to Hava. These steps can be followed for most SSO identity providers, though the field names may be different. Custom apps will be coming soon.

1. Log into Hava and head to your Account Settings. From there select SSO Config, then click OIDC on the protocol selection page. This will show you the Service Provider values you will need to enter into Okta
2. Log into Okta and click Applications → Create App Integration
3. Select ‘OIDC - OpenID Connect’ and then ‘Web Application’ for the Application type, then click Next
4. Enter the following details into the settings:
   1. Name should be **Hava**
   2. Grant Type should be **Authorization Code**
   3. **Sign-in redirect URIs** should be set to the value of **Sign-in Redirect URI** from the Service Provider section in Hava
   4. Assignments should be set based on your requirements
5. All other values can be left as the defaults. Click Save to complete the Okta setup.
6. Head back to the Hava SSO OIDC config page and select Add OIDC Config
7. Enter the config values from the Okta setup instructions:
   1. Identity Provider Host should be set to **Okta domain** without any prefix or trailing slash, i.e. **test-oidc.okta.com** and not **<http://test-oidc.okta.com/>**
   2. OIDC client ID should be set to **Client ID**
   3. OIDC client Secret should be set to **Client secret**
8. Click Save to complete the setup


# Trouble Shooting SSO

Trouble shooting Single Sign-On can be difficult as logs are often limited. Hava makes logs available as part of the Account Audit Logs. These can be used to validate and debug configuration issues with the setup.

To access Audit Logs go to your account settings:

<figure><img src="/files/xvePM6vG4z23AIXkvAjo" alt=""><figcaption><p>Account Settings Page</p></figcaption></figure>

Select Audit Logs - Then search for SSO

<figure><img src="/files/z9eieTBPDU22xMWpYZ7K" alt=""><figcaption><p>Example of SSO logs in Audit Logs</p></figcaption></figure>




---

[Next Page](/llms-full.txt/1)

