Data Connections

Connecting an AWS account

Overview

To connect your AWS environment to DigiUsher, you create a cross-account IAM role. This role needs read-only access to your cost, usage, resource, and security metadata. This page gives the permissions, the reason for each permission, and the credentials that you give to DigiUsher.

Summary of Access Required

ComponentDetails
Identity typeCross-account IAM Role (no credentials stored in your account)
AuthenticationSTS AssumeRole with ExternalId. Temporary session tokens only
Trust relationshipCross-account IAM role trusting DigiUsher AWS account 058264546051 with ExternalId
Base permissionsRead-only across cost, compute, database, storage, networking, security, and organizational metadata
Optional permissionsEC2 start and stop, commitment purchases, tag management, and automation. All of these are off by default
Data accessThe S3 bucket with the Cost and Usage Reports. DigiUsher reads the CUR data only
ScopeSingle AWS account (root or linked)
CapabilityWhat It Provides
Billing dataCost analytics, chargeback and showback, budgeting, forecasting, anomaly detection
Resource inventoryAsset discovery, idle resource detection, tag-based cost allocation
Optimization recommendationsRightsizing, commitment analysis (RI/SP), idle resource cleanup
Utilization metricsCPU, memory, network, disk usage for rightsizing analysis

DigiUsher cannot create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself.

Use CloudFormation for the fastest setup

DigiUsher recommends the CloudFormation template. One deployment covers a root account and a linked account. The template creates all resources, and it makes the maintenance simpler.

At the deployment of the template, select the correct AccountType parameter.

Launch Stack

Source: github.com/digiusher/digiusher-iac

If the policies of your organization need a setup by hand, use the manual steps on this page.


Prerequisites

Information to Gather

ItemHow to Find
AWS Account IDAWS Console > Account Settings, or aws sts get-caller-identity
External IDA unique secret string that you select. A UUID is a good value. You use it in the trust policy of the role, and you enter the same value in the External ID field in DigiUsher.
RegionAll billing resources, which are the S3 bucket and the CUR exports, must be in us-east-1

Roles Required by the Person Performing Setup

RoleWhy
IAM AdministratorTo create IAM roles and policies
S3 Administrator (root accounts only)To create S3 buckets and bucket policies
Billing Administrator (root accounts only)To create CUR exports

About the External ID

The External ID is a secret string that you select. Set it as the condition sts:ExternalId in the trust policy of the role. Then enter the same value in the External ID field when you connect the account in DigiUsher. The External ID is optional, but DigiUsher recommends it. It prevents the confused deputy problem.

Network & Email Access (For Regulated Environments)

If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:

  • Domain allowlist. Add *.digiusher.com to the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers.
  • Email allowlist. Add digiusher.com as a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from @digiusher.com addresses.

Linked Account Setup

A linked account, which AWS also calls a member account, needs an IAM role only. It needs no S3 bucket and no CUR export. The CUR of the root account, which is the payer account, covers all linked accounts.

Create the IAM Role

Create an IAM role that DigiUsher can assume with your ExternalId.

  1. Go to IAM → Roles → Create role
  2. Select Another AWS account
  3. Enter Account ID: 058264546051
  4. Check Require external ID and enter your External ID
  5. Click Next. Do not attach a managed policy.
  6. Give the role a name, for example DigiUsher-ReadAccess
  7. Add a tag: ManagedBy = DigiUsher
  8. Create the role

Attach the Core Permissions Policy

Attach the read-only policy. It gives DigiUsher access to the cost, usage, and resource metadata.

  1. Go to IAM → Roles → select your DigiUsher role
  2. Click Add permissions → Create inline policy
  3. Change to the JSON tab
  4. Paste the policy JSON from this page
  5. Give the policy the name DigiUsherCorePermissions

Note on non-read actions

The core policy has one action that is not read-only: compute-optimizer:UpdateEnrollmentStatus. This action enrolls the account one time, and it enables the recommendations of Compute Optimizer. It does not create, change, or delete your resources.

Note the Role ARN

After you create the role, copy its ARN. You enter this ARN in DigiUsher to complete the connection.

  1. Go to IAM → Roles → select your DigiUsher role
  2. Copy the Role ARN from the summary section, for example arn:aws:iam::123456789012:role/DigiUsher-ReadAccess

A linked account needs no more steps. Enter the Role ARN in DigiUsher to complete the setup. The section Connect in DigiUsher gives the fields.


Root (Payer) Account Setup

The setup of a root account contains all steps of the linked account setup. It also adds an S3 bucket and an export of the Cost and Usage Report (CUR). Select the scenario that matches your infrastructure.

Important

CAUTION: Create all billing resources, which are the S3 bucket and the CUR exports, in the region us-east-1. In another region the export does not work.

Use this scenario when you have no CUR and no billing bucket.

Create the S3 Bucket

  1. Go to S3 → Create bucket
  2. Bucket name: enter a globally unique name, for example acme-corp-digiusher-cur
  3. Region: US East (N. Virginia) us-east-1
  4. Block all public access: enabled, which is the default
  5. Bucket Versioning: Enable
  6. Create the bucket
  7. After the creation, go to the bucket → Management tab → Create lifecycle rule:
    • Rule name: DeleteOldVersions
    • Apply to all objects
    • Under Noncurrent version expiration: set to 90 days
  8. Create another lifecycle rule:
    • Rule name: TransitionToIntelligentTiering
    • Apply to all objects
    • Under Transition current versions: Transition to Intelligent-Tiering after 180 days
  9. Add tags: ManagedBy = DigiUsher, Purpose = CostAndUsageReports

Add the Bucket Policy

The bucket policy lets the AWS billing services write the CUR data to your bucket.

  1. Go to S3, select your bucket, and open the Permissions tab
  2. Under Bucket policy, click Edit
  3. Paste the policy from this page. Replace YOUR_BUCKET_NAME and YOUR_ACCOUNT_ID
  4. Save the changes

Create the CUR Export

Select CUR 2.0 or CUR 1.0. DigiUsher recommends CUR 2.0.

  1. Go to Billing and Cost Management → Data Exports
  2. Click Create export
  3. Export type: Standard data export
  4. Export name: DigiUsher_CUR_Export
  5. Select the table COST_AND_USAGE_REPORT
  6. Time granularity: Daily
  7. Include resource IDs: Yes
  8. Include split cost allocation data: Yes
  9. S3 bucket: select your bucket
  10. S3 prefix: reports/cur2
  11. File format: Parquet
  12. Compression: Parquet
  13. Overwrite: Overwrite existing report
  14. Create the export

Create the IAM Role

Use the same instructions as Linked Account — Step 1 and Step 2.

Attach the S3 CUR Access Policy

The role of the root account needs a second policy. This policy reads the CUR bucket.

  1. Go to IAM → Roles → select your DigiUsher role
  2. Click Add permissions → Create inline policy
  3. Change to the JSON tab and paste the policy from this page
  4. Give the policy the name DigiUsherS3CURAccess

Note the Role ARN

Use Linked Account — Step 3 to get the Role ARN. Then enter it in DigiUsher.


Optional Permissions

These permissions are off by default. If you need one of them, add it as a separate inline policy on the DigiUsher IAM role.


Carbon Footprint Export (Optional)

To track the carbon emissions of your AWS account, create a second data export beside your CUR.

  1. Go to Billing and Cost Management → Data Exports
  2. Click Create export
  3. Export type: Standard data export
  4. Export name: DigiUsher_Carbon_Export
  5. Select the table CARBON_EMISSIONS
  6. S3 bucket: the bucket of your CUR
  7. S3 prefix: reports/carbon-footprint
  8. File format: Parquet
  9. Compression: Parquet
  10. Overwrite: Overwrite existing report
  11. Create the export

Connect in DigiUsher

After you complete the setup, go to Connectors > Add Source and select Amazon Web Services. On the Configure step, enter the values in the table, then click Review. On the Connect step, click Connect source.

FieldRequiredWhere to Find
Display NameYesAny label you prefer (for example AWS Production)
Management Role ARNYesIAM > Roles > DigiUsher-ReadAccess > ARN
External IDRecommendedThe value from the trust policy of the role
CUR S3 BucketRoot onlyThe name of the S3 bucket of the CUR data
CUR Report PathRoot onlyThe S3 prefix of the export (for example reports/cur2)
Report NameRoot onlyThe name of your CUR export (for example DigiUsher_CUR_Export)

You do not enter the CUR version. DigiUsher reads the file layout in the bucket and finds CUR 1.0 or CUR 2.0 by itself.

Security Note

CAUTION: Keep your External ID secret. Do not publish it.

For an automatic deployment, DigiUsher recommends the CloudFormation template. One deployment does all of these steps.


Setup Checklist

Check with the CLI

# Check the role exists and has the correct trust policy
aws iam get-role --role-name DigiUsher-ReadAccess

# List attached inline policies
aws iam list-role-policies --role-name DigiUsher-ReadAccess

# For root accounts — verify the CUR export:
# CUR 2.0
aws bcm-data-exports list-exports --region us-east-1
# CUR 1.0
aws cur describe-report-definitions --region us-east-1

All Accounts

  • External ID selected and saved in a safe place
  • *.digiusher.com in the allowlist of the network and the firewall (if your organization restricts this)
  • digiusher.com in the allowlist for incoming email (if your organization restricts this)
  • IAM role created, with a trust policy
  • External ID set in the trust policy
  • Inline policy DigiUsherCorePermissions attached
  • Role ARN given to DigiUsher

Root/Payer Accounts Only

  • S3 bucket created in us-east-1, or an existing bucket checked
  • Bucket policy gives access to billingreports.amazonaws.com and bcm-data-exports.amazonaws.com
  • Public access blocked, and versioning enabled
  • CUR export created, with CUR 1.0 or CUR 2.0
  • Inline policy DigiUsherS3CURAccess attached, with the correct bucket name
  • CUR S3 bucket, report path, and report name entered in DigiUsher

Optional (if you enable these features)

  • EC2 start and stop policy attached (DigiUsherEC2StartStopPolicy)
  • Commitment purchase policy attached (DigiUsherCommitmentPurchasePolicy)
  • Tag management policy attached (DigiUsherTagManagementPolicy)
  • Automation policy attached (DigiUsherAutomationPolicy)
  • Carbon footprint export created

Security

What DigiUsher CAN Access (Read-Only)

  • The cost data and the usage data in S3, which are the CUR exports
  • The resource metadata, such as names, types, regions, and tags, of the compute, database, storage, networking, and security services
  • The utilization metrics in CloudWatch
  • The optimization recommendations of Compute Optimizer and Trusted Advisor
  • The information about the Reserved Instances and the Savings Plans
  • The hierarchy of the organization, the accounts, and the organizational units

The core policy contains compute-optimizer:UpdateEnrollmentStatus. This action enrolls the account one time, and it enables the recommendations of Compute Optimizer. It does not create, change, or delete your resources. You can remove this permission. Without it, DigiUsher gives no rightsizing recommendations from Compute Optimizer.

What DigiUsher CANNOT Do

  • Create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself
  • Read application data, databases, or the content of your storage. It reads the CUR data only
  • Change an IAM policy or a permission
  • Read secrets, credentials, or encryption keys
  • Read network traffic or the content of your logs
  • Buy a product or change the billing configuration. The only exception is the optional permission for commitment purchases

Monitoring

To monitor the use of the role, open CloudTrail and filter the AssumeRole events of the principal DigiUsher-ReadAccess.

Credential Rotation

  • With CloudFormation, change the parameter ExternalId of the stack. Then enter the new External ID on the data source in DigiUsher.
  • By hand, write a new External ID into the trust policy of the IAM role. Then enter the new External ID on the data source in DigiUsher.

Revocation

  • With CloudFormation, delete the stack. It removes the IAM role and all policies. It also removes the S3 bucket when the template created that bucket.
  • By hand, delete the role DigiUsher-ReadAccess in IAM > Roles. AWS then immediately stops all access.

BYOC (Bring Your Own Cloud) Deployment


Troubleshooting

"Access Denied" when assuming the role

  1. Make sure that the trust policy has the correct DigiUsher account ID (058264546051).
  2. Make sure that the External ID in the trust policy matches the External ID in DigiUsher.
  3. Make sure that the role ARN is correct, without an extra space or character.

CUR data not appearing

  1. The first report of a CUR export can take up to 24 hours.
  2. Make sure that the export exists, in Billing > Data Exports for CUR 2.0, or in Cost & Usage Reports for CUR 1.0.
  3. Make sure that the S3 bucket is in us-east-1.
  4. Make sure that the bucket policy permits billingreports.amazonaws.com and bcm-data-exports.amazonaws.com.

Missing Compute Optimizer recommendations

Compute Optimizer needs an enrollment. With the permission compute-optimizer:UpdateEnrollmentStatus from the core policy, DigiUsher can enroll the account. After the enrollment, the recommendations can take 12 to 24 hours to appear.


Need Help?

If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.

On this page