AWS Connections
Connect your AWS accounts to Orkestia using secure cross-account IAM roles. This enables Orkestia to orchestrate deployments in your AWS account without ever storing your credentials.
What are AWS Connections?
AWS Connections allow Orkestia to interact with your AWS account through a secure cross-account IAM role. Instead of storing AWS access keys, Orkestia uses AWS Security Token Service (STS) to temporarily assume a role in your account.
This architecture ensures:
- Zero credential storage on Orkestia's side
- Full audit trail in your AWS CloudTrail
- Instant revocation by deleting the IAM role
Connection is reused by every AWS-backed capability — deployments, runners, networking, registries, and Bedrock — without a second setup step. It follows the same connect-once model as every other provider; see the Integrations Catalog for the full surface, Cloud Connections for the other providers, and the workflow reference for the aws.* workflows it powers.Benefits
No Credentials Stored
We never store your AWS access keys. All access is through temporary STS credentials.
Granular Permissions
You control exactly what permissions Orkestia has in your account using standard IAM policies.
Easy Revocation
Delete the IAM role at any time to immediately revoke all Orkestia access.
Full Audit Trail
All actions are logged in AWS CloudTrail under the assumed role for complete transparency.
Connection Scopes
Organization-wide (Recommended)
An organization-wide connection is available to all sites in your organization. This is the recommended approach when you want to use the same AWS account for all deployments.
Site-specific
Coming SoonSite-specific connections will allow you to connect different AWS accounts to individual sites for isolation or compliance requirements.
How It Works
You create an IAM role in your AWS account
The role includes a trust policy that allows Orkestia to assume it, plus a permission policy for the required AWS services.
You provide the Role ARN to Orkestia
Enter the IAM Role ARN in the Orkestia connection wizard. No secrets or access keys are shared.
Orkestia validates the connection
We verify we can assume the role, check required permissions, and analyze for security best practices.
Deployments run in your account
When deploying, Orkestia uses STS to get temporary credentials and orchestrates resources directly in your AWS account.
Connection Statuses
| Status | Description |
|---|---|
| Active | Connection is valid and ready to use |
| Pending | Connection created, awaiting validation |
| Invalid | Validation failed - check IAM role configuration |
| Suspended | Too many validation failures |
Required Permissions
The IAM role needs permissions for the AWS services Orkestia will use:
| Service | Purpose |
|---|---|
| S3 | Store and serve static website files |
| CloudFront | CDN distribution management |
| Route53 (optional) | DNS record management |
| CloudWatch Logs | Build and deployment logs |
