Skip to main content
Connect AWS and Google Cloud so tag mode can inspect alarms, metrics, logs, and resources when it answers questions. Both use short-lived credentials. Superlog never stores long-lived cloud keys. Automations cannot use AWS or Google Cloud as connectors. CloudWatch alarms can still start automations through Slack. See AWS alarms in Slack.

AWS

Superlog connects to AWS with an IAM role you create from a CloudFormation template. It assumes the role through STS for each request.

What Superlog can read

The role uses the AWS-managed AIOpsAssistantPolicy, which grants read access across the account, including:
  • CloudWatch alarms, alarm history, metrics, and Logs Insights
  • SQS queue attributes
  • Lambda configuration and event source mappings
  • Other read-only AWS API calls
An explicit deny blocks reading Secrets Manager values and SSM parameters, and decrypting with KMS.

Connect AWS

1

Open the AWS dialog

In Integrations, click Add on AWS and enter your 12-digit AWS account ID.
2

Create the stack

Click Create stack to open AWS CloudFormation with the template. Review the role and policy, create the stack, and wait until its status is CREATE_COMPLETE.
3

Verify

Return to Superlog and click Verify connection. Superlog assumes the role to confirm it works.
AIOpsAssistantPolicy grants read access in every region of the account. Review the template before you create the stack.
Only the commercial AWS partition is supported.

AWS alarms in Slack

AWS does not send webhooks to Superlog. Send CloudWatch alarms to a Slack channel with Amazon Q Developer in chat applications. Then:
  • Add a Slack New message in channel trigger on that channel to start an automation, or
  • Mention Superlog in the alarm’s thread to investigate it with tag mode.
Superlog acts only on ALARM notifications. OK and INSUFFICIENT_DATA notifications are ignored.

Google Cloud

Superlog connects to Google Cloud with Workload Identity Federation in your project. It exchanges a short-lived identity for a Google token and impersonates a dedicated service account. No service account key is created.

What Superlog can read

Setup creates a responder-investigation service account with these roles: Superlog uses only tools that Google’s managed MCP servers mark as read-only.

Connect Google Cloud

1

Sign in with Google

In Integrations, click Add on Google Cloud, then Continue with Google. Use an account that can enable APIs, create service accounts and workload identity pools, and change project IAM.
2

Choose a project

Pick the project and click Grant read-only access.
3

Wait for setup

Setup runs in the background and can take up to 15 minutes. It enables the required APIs, creates the service account, and configures Workload Identity Federation. You can close the window. The Google Cloud card shows the progress.
Superlog uses your Google sign-in only for setup and revokes it afterwards. To connect more projects, open Manage on the Google Cloud card and click Add project. Remove disconnects a project from Superlog. It does not delete the service account or IAM bindings in your project.