Connecting an AWS account
Overview
To connect your AWS environment to DigiUsher, you create a cross-account IAM role. This role needs read-only access to your cost, usage, resource, and security metadata. This page gives the permissions, the reason for each permission, and the credentials that you give to DigiUsher.
Summary of Access Required
| Component | Details |
|---|---|
| Identity type | Cross-account IAM Role (no credentials stored in your account) |
| Authentication | STS AssumeRole with ExternalId. Temporary session tokens only |
| Trust relationship | Cross-account IAM role trusting DigiUsher AWS account 058264546051 with ExternalId |
| Base permissions | Read-only across cost, compute, database, storage, networking, security, and organizational metadata |
| Optional permissions | EC2 start and stop, commitment purchases, tag management, and automation. All of these are off by default |
| Data access | The S3 bucket with the Cost and Usage Reports. DigiUsher reads the CUR data only |
| Scope | Single AWS account (root or linked) |
| Capability | What It Provides |
|---|---|
| Billing data | Cost analytics, chargeback and showback, budgeting, forecasting, anomaly detection |
| Resource inventory | Asset discovery, idle resource detection, tag-based cost allocation |
| Optimization recommendations | Rightsizing, commitment analysis (RI/SP), idle resource cleanup |
| Utilization metrics | CPU, memory, network, disk usage for rightsizing analysis |
DigiUsher cannot create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself.
If the policies of your organization need a setup by hand, use the manual steps on this page.
Prerequisites
Information to Gather
| Item | How to Find |
|---|---|
| AWS Account ID | AWS Console > Account Settings, or aws sts get-caller-identity |
| External ID | A unique secret string that you select. A UUID is a good value. You use it in the trust policy of the role, and you enter the same value in the External ID field in DigiUsher. |
| Region | All billing resources, which are the S3 bucket and the CUR exports, must be in us-east-1 |
Roles Required by the Person Performing Setup
| Role | Why |
|---|---|
| IAM Administrator | To create IAM roles and policies |
| S3 Administrator (root accounts only) | To create S3 buckets and bucket policies |
| Billing Administrator (root accounts only) | To create CUR exports |
About the External ID
The External ID is a secret string that you select. Set it as the condition sts:ExternalId in the trust policy of the role. Then enter the same value in the External ID field when you connect the account in DigiUsher. The External ID is optional, but DigiUsher recommends it. It prevents the confused deputy problem.
Network & Email Access (For Regulated Environments)
If your organization restricts outbound internet access or email domains, make sure that these two items are in place before you start:
- Domain allowlist. Add
*.digiusher.comto the allowlist of your network and your firewall. The users of your organization can then open the DigiUsher platform in their browsers. - Email allowlist. Add
digiusher.comas a permitted sender domain in your email security gateway. DigiUsher sends onboarding confirmations, alerts, and reports from@digiusher.comaddresses.
Linked Account Setup
A linked account, which AWS also calls a member account, needs an IAM role only. It needs no S3 bucket and no CUR export. The CUR of the root account, which is the payer account, covers all linked accounts.
Create the IAM Role
Create an IAM role that DigiUsher can assume with your ExternalId.
- Go to IAM → Roles → Create role
- Select Another AWS account
- Enter Account ID:
058264546051 - Check Require external ID and enter your External ID
- Click Next. Do not attach a managed policy.
- Give the role a name, for example
DigiUsher-ReadAccess - Add a tag:
ManagedBy=DigiUsher - Create the role
Attach the Core Permissions Policy
Attach the read-only policy. It gives DigiUsher access to the cost, usage, and resource metadata.
- Go to IAM → Roles → select your DigiUsher role
- Click Add permissions → Create inline policy
- Change to the JSON tab
- Paste the policy JSON from this page
- Give the policy the name
DigiUsherCorePermissions
Note on non-read actions
The core policy has one action that is not read-only: compute-optimizer:UpdateEnrollmentStatus. This action enrolls the account one time, and it enables the recommendations of Compute Optimizer. It does not create, change, or delete your resources.
Note the Role ARN
After you create the role, copy its ARN. You enter this ARN in DigiUsher to complete the connection.
- Go to IAM → Roles → select your DigiUsher role
- Copy the Role ARN from the summary section, for example
arn:aws:iam::123456789012:role/DigiUsher-ReadAccess
A linked account needs no more steps. Enter the Role ARN in DigiUsher to complete the setup. The section Connect in DigiUsher gives the fields.
Root (Payer) Account Setup
The setup of a root account contains all steps of the linked account setup. It also adds an S3 bucket and an export of the Cost and Usage Report (CUR). Select the scenario that matches your infrastructure.
Important
CAUTION: Create all billing resources, which are the S3 bucket and the CUR exports, in the region us-east-1. In another region the export does not work.
Use this scenario when you have no CUR and no billing bucket.
Create the S3 Bucket
- Go to S3 → Create bucket
- Bucket name: enter a globally unique name, for example
acme-corp-digiusher-cur - Region: US East (N. Virginia) us-east-1
- Block all public access: enabled, which is the default
- Bucket Versioning: Enable
- Create the bucket
- After the creation, go to the bucket → Management tab → Create lifecycle rule:
- Rule name:
DeleteOldVersions - Apply to all objects
- Under Noncurrent version expiration: set to
90days
- Rule name:
- Create another lifecycle rule:
- Rule name:
TransitionToIntelligentTiering - Apply to all objects
- Under Transition current versions: Transition to Intelligent-Tiering after
180days
- Rule name:
- Add tags:
ManagedBy=DigiUsher,Purpose=CostAndUsageReports
Add the Bucket Policy
The bucket policy lets the AWS billing services write the CUR data to your bucket.
- Go to S3, select your bucket, and open the Permissions tab
- Under Bucket policy, click Edit
- Paste the policy from this page. Replace
YOUR_BUCKET_NAMEandYOUR_ACCOUNT_ID - Save the changes
Create the CUR Export
Select CUR 2.0 or CUR 1.0. DigiUsher recommends CUR 2.0.
- Go to Billing and Cost Management → Data Exports
- Click Create export
- Export type: Standard data export
- Export name:
DigiUsher_CUR_Export - Select the table COST_AND_USAGE_REPORT
- Time granularity: Daily
- Include resource IDs: Yes
- Include split cost allocation data: Yes
- S3 bucket: select your bucket
- S3 prefix:
reports/cur2 - File format: Parquet
- Compression: Parquet
- Overwrite: Overwrite existing report
- Create the export
Create the IAM Role
Use the same instructions as Linked Account — Step 1 and Step 2.
Attach the S3 CUR Access Policy
The role of the root account needs a second policy. This policy reads the CUR bucket.
- Go to IAM → Roles → select your DigiUsher role
- Click Add permissions → Create inline policy
- Change to the JSON tab and paste the policy from this page
- Give the policy the name
DigiUsherS3CURAccess
Note the Role ARN
Use Linked Account — Step 3 to get the Role ARN. Then enter it in DigiUsher.
Optional Permissions
These permissions are off by default. If you need one of them, add it as a separate inline policy on the DigiUsher IAM role.
Carbon Footprint Export (Optional)
To track the carbon emissions of your AWS account, create a second data export beside your CUR.
- Go to Billing and Cost Management → Data Exports
- Click Create export
- Export type: Standard data export
- Export name:
DigiUsher_Carbon_Export - Select the table CARBON_EMISSIONS
- S3 bucket: the bucket of your CUR
- S3 prefix:
reports/carbon-footprint - File format: Parquet
- Compression: Parquet
- Overwrite: Overwrite existing report
- Create the export
Connect in DigiUsher
After you complete the setup, go to Connectors > Add Source and select Amazon Web Services. On the Configure step, enter the values in the table, then click Review. On the Connect step, click Connect source.
| Field | Required | Where to Find |
|---|---|---|
| Display Name | Yes | Any label you prefer (for example AWS Production) |
| Management Role ARN | Yes | IAM > Roles > DigiUsher-ReadAccess > ARN |
| External ID | Recommended | The value from the trust policy of the role |
| CUR S3 Bucket | Root only | The name of the S3 bucket of the CUR data |
| CUR Report Path | Root only | The S3 prefix of the export (for example reports/cur2) |
| Report Name | Root only | The name of your CUR export (for example DigiUsher_CUR_Export) |
You do not enter the CUR version. DigiUsher reads the file layout in the bucket and finds CUR 1.0 or CUR 2.0 by itself.
Security Note
CAUTION: Keep your External ID secret. Do not publish it.
For an automatic deployment, DigiUsher recommends the CloudFormation template. One deployment does all of these steps.
Setup Checklist
Check with the CLI
# Check the role exists and has the correct trust policy
aws iam get-role --role-name DigiUsher-ReadAccess
# List attached inline policies
aws iam list-role-policies --role-name DigiUsher-ReadAccess
# For root accounts — verify the CUR export:
# CUR 2.0
aws bcm-data-exports list-exports --region us-east-1
# CUR 1.0
aws cur describe-report-definitions --region us-east-1All Accounts
- External ID selected and saved in a safe place
-
*.digiusher.comin the allowlist of the network and the firewall (if your organization restricts this) -
digiusher.comin the allowlist for incoming email (if your organization restricts this) - IAM role created, with a trust policy
- External ID set in the trust policy
- Inline policy
DigiUsherCorePermissionsattached - Role ARN given to DigiUsher
Root/Payer Accounts Only
- S3 bucket created in
us-east-1, or an existing bucket checked - Bucket policy gives access to
billingreports.amazonaws.comandbcm-data-exports.amazonaws.com - Public access blocked, and versioning enabled
- CUR export created, with CUR 1.0 or CUR 2.0
- Inline policy
DigiUsherS3CURAccessattached, with the correct bucket name - CUR S3 bucket, report path, and report name entered in DigiUsher
Optional (if you enable these features)
- EC2 start and stop policy attached (
DigiUsherEC2StartStopPolicy) - Commitment purchase policy attached (
DigiUsherCommitmentPurchasePolicy) - Tag management policy attached (
DigiUsherTagManagementPolicy) - Automation policy attached (
DigiUsherAutomationPolicy) - Carbon footprint export created
Security
What DigiUsher CAN Access (Read-Only)
- The cost data and the usage data in S3, which are the CUR exports
- The resource metadata, such as names, types, regions, and tags, of the compute, database, storage, networking, and security services
- The utilization metrics in CloudWatch
- The optimization recommendations of Compute Optimizer and Trusted Advisor
- The information about the Reserved Instances and the Savings Plans
- The hierarchy of the organization, the accounts, and the organizational units
The core policy contains compute-optimizer:UpdateEnrollmentStatus. This action enrolls the account one time, and it enables the recommendations of Compute Optimizer. It does not create, change, or delete your resources. You can remove this permission. Without it, DigiUsher gives no rightsizing recommendations from Compute Optimizer.
What DigiUsher CANNOT Do
- Create, change, or delete an AWS resource. The only exception is an optional write permission that you enable yourself
- Read application data, databases, or the content of your storage. It reads the CUR data only
- Change an IAM policy or a permission
- Read secrets, credentials, or encryption keys
- Read network traffic or the content of your logs
- Buy a product or change the billing configuration. The only exception is the optional permission for commitment purchases
Monitoring
To monitor the use of the role, open CloudTrail and filter the AssumeRole events of the principal DigiUsher-ReadAccess.
Credential Rotation
- With CloudFormation, change the parameter
ExternalIdof the stack. Then enter the new External ID on the data source in DigiUsher. - By hand, write a new External ID into the trust policy of the IAM role. Then enter the new External ID on the data source in DigiUsher.
Revocation
- With CloudFormation, delete the stack. It removes the IAM role and all policies. It also removes the S3 bucket when the template created that bucket.
- By hand, delete the role
DigiUsher-ReadAccessin IAM > Roles. AWS then immediately stops all access.
BYOC (Bring Your Own Cloud) Deployment
Troubleshooting
"Access Denied" when assuming the role
- Make sure that the trust policy has the correct DigiUsher account ID (
058264546051). - Make sure that the External ID in the trust policy matches the External ID in DigiUsher.
- Make sure that the role ARN is correct, without an extra space or character.
CUR data not appearing
- The first report of a CUR export can take up to 24 hours.
- Make sure that the export exists, in Billing > Data Exports for CUR 2.0, or in Cost & Usage Reports for CUR 1.0.
- Make sure that the S3 bucket is in us-east-1.
- Make sure that the bucket policy permits
billingreports.amazonaws.comandbcm-data-exports.amazonaws.com.
Missing Compute Optimizer recommendations
Compute Optimizer needs an enrollment. With the permission compute-optimizer:UpdateEnrollmentStatus from the core policy, DigiUsher can enroll the account. After the enrollment, the recommendations can take 12 to 24 hours to appear.
Need Help?
If this page does not answer your question, write to DigiUsher support at support@digiusher.com. The team will help you.
DigiUsher Documentation