> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superlog.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS and Google Cloud

> Give tag mode read-only access to your AWS account and Google Cloud projects with short-lived credentials.

Connect AWS and Google Cloud so tag mode can inspect alarms, metrics, logs, and resources when it answers questions. Both use short-lived credentials. Superlog never stores long-lived cloud keys.

Automations cannot use AWS or Google Cloud as connectors. CloudWatch alarms can still start automations through Slack. See [AWS alarms in Slack](#aws-alarms-in-slack).

## AWS

Superlog connects to AWS with an IAM role you create from a CloudFormation template. It assumes the role through STS for each request.

### What Superlog can read

The role uses the AWS-managed `AIOpsAssistantPolicy`, which grants read access across the account, including:

* CloudWatch alarms, alarm history, metrics, and Logs Insights
* SQS queue attributes
* Lambda configuration and event source mappings
* Other read-only AWS API calls

An explicit deny blocks reading Secrets Manager values and SSM parameters, and decrypting with KMS.

### Connect AWS

<Steps>
  <Step title="Open the AWS dialog">
    In **Integrations**, click **Add** on AWS and enter your 12-digit **AWS account ID**.
  </Step>

  <Step title="Create the stack">
    Click **Create stack** to open AWS CloudFormation with the template. Review the role and policy, create the stack, and wait until its status is `CREATE_COMPLETE`.
  </Step>

  <Step title="Verify">
    Return to Superlog and click **Verify connection**. Superlog assumes the role to confirm it works.
  </Step>
</Steps>

<Warning>
  `AIOpsAssistantPolicy` grants read access in every region of the account. Review the template before you create the stack.
</Warning>

Only the commercial AWS partition is supported.

### AWS alarms in Slack

AWS does not send webhooks to Superlog. Send CloudWatch alarms to a Slack channel with Amazon Q Developer in chat applications. Then:

* Add a Slack **New message in channel** trigger on that channel to start an automation, or
* Mention Superlog in the alarm's thread to investigate it with tag mode.

Superlog acts only on `ALARM` notifications. `OK` and `INSUFFICIENT_DATA` notifications are ignored.

## Google Cloud

Superlog connects to Google Cloud with Workload Identity Federation in your project. It exchanges a short-lived identity for a Google token and impersonates a dedicated service account. No service account key is created.

### What Superlog can read

Setup creates a `responder-investigation` service account with these roles:

| Role | Access |
| - | - |
| MCP Tool User | Use Google's managed MCP servers |
| Cloud Asset Viewer | Read Cloud Asset Inventory |
| Logs Viewer | Query Cloud Logging |
| Monitoring Viewer | Read Cloud Monitoring |
| Service Usage Consumer | Check which APIs are enabled |

Superlog uses only tools that Google's managed MCP servers mark as read-only.

### Connect Google Cloud

<Steps>
  <Step title="Sign in with Google">
    In **Integrations**, click **Add** on Google Cloud, then **Continue with Google**. Use an account that can enable APIs, create service accounts and workload identity pools, and change project IAM.
  </Step>

  <Step title="Choose a project">
    Pick the project and click **Grant read-only access**.
  </Step>

  <Step title="Wait for setup">
    Setup runs in the background and can take up to 15 minutes. It enables the required APIs, creates the service account, and configures Workload Identity Federation. You can close the window. The Google Cloud card shows the progress.
  </Step>
</Steps>

Superlog uses your Google sign-in only for setup and revokes it afterwards. To connect more projects, open **Manage** on the Google Cloud card and click **Add project**. **Remove** disconnects a project from Superlog. It does not delete the service account or IAM bindings in your project.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.