Skip to main content
Connect your AWS account to Yasu using our secure CloudFormation template. This one-click deployment creates a read-only IAM role that enables Yasu to analyze your cloud costs and provide optimization recommendations.

Prerequisites

Before connecting your AWS account, ensure you have:
  • Administrative access to your AWS account (or permissions to create IAM roles and CloudFormation stacks)
  • Cost Explorer enabled in your AWS account
  • Access to the AWS Console
Security First: Yasu uses a cross-account IAM role with read-only permissions. We cannot modify or delete any of your AWS resources.

Quick Setup via CloudFormation

The fastest way to connect your AWS account is through our pre-configured CloudFormation template.
1

Navigate to Integrations

  1. Log in to your Yasu dashboard at app.yasu.cloud
  2. Go to SettingsIntegrations
  3. Click Connect AWS
2

Deploy the CloudFormation Stack

You’ll be redirected to AWS CloudFormation with our template pre-loaded.
  1. Review the stack name — A unique name is generated for you (e.g., YasuIntegration-abc123)
  2. Review the parameters — These are automatically filled in:
    • YasuCustomerId — Your unique Yasu customer ID
    • YasuExternalId — A secure token for cross-account access
    • BucketName — S3 bucket for Cost and Usage Reports
    • ReportName — Name for your AWS CUR report
  3. Scroll to the bottom and check the acknowledgment box:
    ☑️ I acknowledge that AWS CloudFormation might create IAM resources.
  4. Click Create stack
Do not modify the parameters — They are pre-configured to work with your Yasu account.
3

Wait for Stack Creation

The CloudFormation stack typically completes in 2-3 minutes. You can monitor the progress in the AWS Console:
  • CREATE_IN_PROGRESS — Stack is being created
  • CREATE_COMPLETE — Stack created successfully
Once complete, Yasu automatically detects the connection and begins syncing your data.
4

Verify Connection in Yasu

Return to your Yasu dashboard. You should see:
  • Connection status: Active
  • AWS Account ID: Your connected account
  • Data sync: In progress
Your first cost-saving insights will appear within 5-10 minutes after connection.

What the CloudFormation Template Creates

Our template creates the following resources in your AWS account:

1. Cross-Account IAM Role

A read-only IAM role that allows Yasu to access your cost and resource data:

2. IAM Policies with Read-Only Permissions

The role includes two policies. The main policy (YasuCostOptimizationPolicy) grants read-only access across AWS services: A second policy (YasuCloudWatchMetricsReadOnly) grants read access to Container Insights logs and Auto Scaling metrics.
The policies below are from template version v0.0.1. For the latest version, see the CloudFormation template.Key statements:YasuBillingReadOnly — Read-only access to billing, cost, and resource data:
YasuContainerInsightsReadOnly — Container Insights log access:
YasuContainerMetricsAccess — Auto Scaling and CloudWatch metrics:

3. Cost and Usage Report (CUR)

An S3 bucket and CUR configuration for detailed billing data:
  • Bucket: yasu-cur-{unique-id}
  • Report granularity: Daily
  • Format: Parquet (optimized for analysis)

What Yasu Will Scan

Once connected, Yasu analyzes your AWS environment for optimization opportunities:

Cost Optimization Insights

  • Idle EC2 Instances — Running instances with low CPU/network utilization
  • Oversized Instances — Instances that can be downsized based on usage patterns
  • Unattached EBS Volumes — Volumes not connected to any instance
  • Old EBS Snapshots — Snapshots older than retention policies
  • Unused Elastic IPs — Static IPs not associated with running resources
  • Idle RDS Instances — Databases with minimal connections or queries
  • Underutilized Lambda — Functions with excess memory allocation
  • S3 Storage Classes — Buckets that could benefit from lifecycle policies

Savings Opportunities

  • Reserved Instance Coverage — Recommendations for RI purchases
  • Savings Plans — Compute and EC2 Savings Plan opportunities
  • Spot Instance Candidates — Workloads suitable for Spot pricing

Cost Optimization Hub Recommendations

Yasu surfaces recommendations from AWS Cost Optimization Hub (COH) — AWS’s own consolidated recommendation engine. COH brings rightsizing, idle-resource, Reserved Instance, and Savings Plans recommendations across your organization into one place, each with an estimated monthly saving.
COH recommendations are read through the AWS Cost Optimization Hub API. Enabling it does not add to your AWS bill.
Two things must be true for COH recommendations to appear in Yasu:
  1. Cost Optimization Hub is enabled (opted in) in your AWS account.
  2. The Yasu IAM role has cost-optimization-hub read permissions — included in the current CloudFormation template.

Enroll in Cost Optimization Hub

Cost Optimization Hub is an opt-in AWS service. Enable it once from your management (payer) account so recommendations cover your whole organization.
  1. Open the AWS Billing and Cost Management console
  2. In the left navigation, select Cost Optimization Hub
  3. Click Enable Cost Optimization Hub (or Get started)
  4. Confirm the opt-in
Cost Optimization Hub is a global service — its API lives in us-east-1, so run the command with --region us-east-1. After enrolling, AWS can take up to 24 hours to generate the first recommendations.
If you’re a new customer, that’s all you need — the CloudFormation template you deployed already grants Yasu the read permission, so COH recommendations appear automatically once AWS has generated them.

Existing Customers: Add the Cost Optimization Hub Permission

If you connected your AWS account before August 2026, your Yasu IAM role was created from an earlier template that did not include Cost Optimization Hub permissions. The template has since been updated, so you need to refresh your role once to add:
Without these permissions, Yasu cannot read Cost Optimization Hub, and COH recommendations will not appear.
Choose either option below. Update your existing Yasu stack to the latest template. Your parameters and role ARN stay the same; only the permissions change.
  1. Open AWS CloudFormation
  2. Select your existing Yasu stack (named yasu-* or YasuIntegration-*)
  3. Click UpdateReplace existing template
  4. Under Amazon S3 URL, paste:
  5. Click Next through the parameter and options screens — keep all existing parameter values
  6. On the review screen, check I acknowledge that AWS CloudFormation might create IAM resources
  7. Click Update stack
The update completes in 1–2 minutes, ending in status UPDATE_COMPLETE. Nothing else in your account changes — the role keeps the same ARN, and Yasu stays connected throughout.

Option B — Add the permission manually

If you’d rather not update the stack, add the two actions to the role’s policy directly:
  1. Open IAM → Roles and find YasuCostOptimizationRole-*
  2. Open the attached YasuCostOptimizationPolicy-* policy and click Edit
  3. Add these two actions to the Action list:
  4. Click Save changes
A manual edit is overwritten the next time the CloudFormation stack updates. Option A keeps your role in sync with the template going forward.

Then enroll in COH

Adding the permission lets Yasu read Cost Optimization Hub, but AWS only generates recommendations once COH is enabled. If you haven’t already, enroll in Cost Optimization Hub as described above.

Data Sync Schedule

Troubleshooting

Common causes:
  1. Insufficient permissions — Ensure you have cloudformation:*, iam:*, and s3:* permissions
  2. S3 bucket name conflict — The bucket name must be globally unique; try again to generate a new name
  3. Service limits — Check if you’ve hit IAM role limits
Solution: Delete the failed stack and try the connection again from Yasu.
What to check:
  1. Verify the CloudFormation stack status is CREATE_COMPLETE
  2. Check that the stack wasn’t rolled back
  3. Ensure the callback URL is accessible (no VPN/firewall blocking)
Solution: Wait 5 minutes, then refresh. If still pending, delete the stack and reconnect.
What to check:
  1. Cost Explorer is enabled — Go to AWS Billing → Cost Explorer → Enable
  2. Sufficient history — Cost Explorer needs ~24 hours to populate after first enable
  3. IAM permissions — Verify the role has ce:* permissions
Solution: Enable Cost Explorer if needed, then wait 24 hours for data to populate.
What to check:
  1. Regional coverage — Some resources may be in regions not yet scanned
  2. API rate limits — Large accounts may take longer to fully scan
  3. Missing permissions — Verify all Describe permissions are in place
Solution: Wait for the full sync cycle (up to 6 hours for large accounts).

Connecting Multiple AWS Accounts

If you have multiple AWS accounts (e.g., production, staging, development), you can connect each one:
  1. Go to SettingsIntegrations
  2. Click Connect AWS for each additional account
  3. Deploy the CloudFormation stack in each account
AWS Organizations: If you use AWS Organizations, connect the management account first for organization-wide visibility.

Next Steps

Connect GCP

Add your Google Cloud accounts for multi-cloud visibility.

Connect Azure

Add your Microsoft Azure accounts for multi-cloud visibility.