Orkestia
Blog
AWS Connections

AWS Connections

Connect your AWS accounts to Orkestia using secure cross-account IAM roles. Your cloud, your code, your control.

Connect your AWS accounts to Orkestia using secure cross-account IAM roles. This enables Orkestia to orchestrate deployments in your AWS account without ever storing your credentials.

Orkestia never stores your AWS access keys. All access is through temporary STS credentials that you control.

What are AWS Connections?

AWS Connections allow Orkestia to interact with your AWS account through a secure cross-account IAM role. Instead of storing AWS access keys, Orkestia uses AWS Security Token Service (STS) to temporarily assume a role in your account.

This architecture ensures:

  • Zero credential storage on Orkestia's side
  • Full audit trail in your AWS CloudTrail
  • Instant revocation by deleting the IAM role
AWS is the foundational connection: once linked, the same Connection is reused by every AWS-backed capability — deployments, runners, networking, registries, and Bedrock — without a second setup step. It follows the same connect-once model as every other provider; see the Integrations Catalog for the full surface, Cloud Connections for the other providers, and the workflow reference for the aws.* workflows it powers.

Benefits

No Credentials Stored

We never store your AWS access keys. All access is through temporary STS credentials.

Granular Permissions

You control exactly what permissions Orkestia has in your account using standard IAM policies.

Easy Revocation

Delete the IAM role at any time to immediately revoke all Orkestia access.

Full Audit Trail

All actions are logged in AWS CloudTrail under the assumed role for complete transparency.

Connection Scopes

An organization-wide connection is available to all sites in your organization. This is the recommended approach when you want to use the same AWS account for all deployments.

Connections are scoped to your organization — the same tenancy unit that scopes every workflow run. See Organizations & identity for how scoping works.

Site-specific

Coming Soon

Site-specific connections will allow you to connect different AWS accounts to individual sites for isolation or compliance requirements.

How It Works

You create an IAM role in your AWS account

The role includes a trust policy that allows Orkestia to assume it, plus a permission policy for the required AWS services.

You provide the Role ARN to Orkestia

Enter the IAM Role ARN in the Orkestia connection wizard. No secrets or access keys are shared.

Orkestia validates the connection

We verify we can assume the role, check required permissions, and analyze for security best practices.

Deployments run in your account

When deploying, Orkestia uses STS to get temporary credentials and orchestrates resources directly in your AWS account.

Connection Statuses

StatusDescription
ActiveConnection is valid and ready to use
PendingConnection created, awaiting validation
InvalidValidation failed - check IAM role configuration
SuspendedToo many validation failures

Required Permissions

The IAM role needs permissions for the AWS services Orkestia will use:

ServicePurpose
S3Store and serve static website files
CloudFrontCDN distribution management
Route53 (optional)DNS record management
CloudWatch LogsBuild and deployment logs
See the Setup Methods guide for the complete IAM permission policy.

Getting Started

Prerequisites and creating your first connection.

Setup Methods

Manual, CloudFormation, or Terraform setup guides.

Managing Connections

View, validate, and delete your connections.

Security Best Practices

Least privilege recommendations and security features.

Troubleshooting

Common issues and solutions.