Connect your AWS account to Yasu using our secure CloudFormation template. This one-click deployment creates a read-only IAM role that enables Yasu to analyze your cloud costs and provide optimization recommendations.Documentation Index
Fetch the complete documentation index at: https://docs.yasu.cloud/llms.txt
Use this file to discover all available pages before exploring further.
Prerequisites
Before connecting your AWS account, ensure you have:- Administrative access to your AWS account (or permissions to create IAM roles and CloudFormation stacks)
- Cost Explorer enabled in your AWS account
- Access to the AWS Console
Security First: Yasu uses a cross-account IAM role with read-only permissions. We cannot modify or delete any of your AWS resources.
Quick Setup via CloudFormation
The fastest way to connect your AWS account is through our pre-configured CloudFormation template.Navigate to Integrations
- Log in to your Yasu dashboard at app.yasu.cloud
- Go to Settings → Integrations
- Click Connect AWS
Deploy the CloudFormation Stack
You’ll be redirected to AWS CloudFormation with our template pre-loaded.
- Review the stack name — A unique name is generated for you (e.g.,
YasuIntegration-abc123) - Review the parameters — These are automatically filled in:
YasuCustomerId— Your unique Yasu customer IDYasuExternalId— A secure token for cross-account accessBucketName— S3 bucket for Cost and Usage ReportsReportName— Name for your AWS CUR report
- Scroll to the bottom and check the acknowledgment box:
☑️ I acknowledge that AWS CloudFormation might create IAM resources.
- Click Create stack
Wait for Stack Creation
The CloudFormation stack typically completes in 2-3 minutes. You can monitor the progress in the AWS Console:
- CREATE_IN_PROGRESS — Stack is being created
- CREATE_COMPLETE — Stack created successfully
What the CloudFormation Template Creates
Our template creates the following resources in your AWS account:1. Cross-Account IAM Role
A read-only IAM role that allows Yasu to access your cost and resource data:2. IAM Policies with Read-Only Permissions
The role includes two policies. The main policy (YasuCostOptimizationPolicy) grants read-only access across AWS services:
| Service | Permissions | Purpose |
|---|---|---|
| Cost Explorer | ce:Describe*, ce:Get*, ce:List* | Cost and usage data |
| Compute Optimizer | compute-optimizer:Describe*, compute-optimizer:Get* | Right-sizing recommendations |
| EC2 | ec2:Describe*, ec2:List* | Instance, volume, and snapshot info |
| RDS | rds:Describe*, rds:List* | Database instance details |
| EKS | eks:Describe*, eks:List* | Kubernetes cluster info |
| Lambda | lambda:Get*, lambda:List* | Function configurations |
| S3 | s3:GetBucketLocation, s3:GetBucketTagging, s3:List* | Storage bucket information |
| CloudWatch | cloudwatch:Get*, cloudwatch:List*, cloudwatch:Describe* | Utilization metrics |
| Organizations | organizations:Describe*, organizations:List* | Account structure |
| Savings Plans | savingsplans:Describe* | Savings plan coverage |
| Trusted Advisor | trustedadvisor:Get*, trustedadvisor:List*, support:* | AWS recommendations |
YasuCloudWatchMetricsReadOnly) grants read access to Container Insights logs and Auto Scaling metrics.
View full IAM policies
View full IAM policies
The policies below are from template version YasuContainerInsightsReadOnly — Container Insights log access:YasuContainerMetricsAccess — Auto Scaling and CloudWatch metrics:
v0.0.1. For the latest version, see the CloudFormation template.Key statements:YasuBillingReadOnly — Read-only access to billing, cost, and resource data:3. Cost and Usage Report (CUR)
An S3 bucket and CUR configuration for detailed billing data:- Bucket:
yasu-cur-{unique-id} - Report granularity: Daily
- Format: Parquet (optimized for analysis)
What Yasu Will Scan
Once connected, Yasu analyzes your AWS environment for optimization opportunities:Cost Optimization Insights
- Idle EC2 Instances — Running instances with low CPU/network utilization
- Oversized Instances — Instances that can be downsized based on usage patterns
- Unattached EBS Volumes — Volumes not connected to any instance
- Old EBS Snapshots — Snapshots older than retention policies
- Unused Elastic IPs — Static IPs not associated with running resources
- Idle RDS Instances — Databases with minimal connections or queries
- Underutilized Lambda — Functions with excess memory allocation
- S3 Storage Classes — Buckets that could benefit from lifecycle policies
Savings Opportunities
- Reserved Instance Coverage — Recommendations for RI purchases
- Savings Plans — Compute and EC2 Savings Plan opportunities
- Spot Instance Candidates — Workloads suitable for Spot pricing
Data Sync Schedule
| Data Type | Initial Sync | Ongoing Sync |
|---|---|---|
| Cost data | Last 12 months | Daily |
| Resource inventory | Current state | Every 6 hours |
| Utilization metrics | Last 14 days | Daily |
| Recommendations | Within 24 hours | Weekly |
Troubleshooting
Stack creation failed
Stack creation failed
Common causes:
- Insufficient permissions — Ensure you have
cloudformation:*,iam:*, ands3:*permissions - S3 bucket name conflict — The bucket name must be globally unique; try again to generate a new name
- Service limits — Check if you’ve hit IAM role limits
Connection shows as pending
Connection shows as pending
What to check:
- Verify the CloudFormation stack status is
CREATE_COMPLETE - Check that the stack wasn’t rolled back
- Ensure the callback URL is accessible (no VPN/firewall blocking)
Missing cost data
Missing cost data
What to check:
- Cost Explorer is enabled — Go to AWS Billing → Cost Explorer → Enable
- Sufficient history — Cost Explorer needs ~24 hours to populate after first enable
- IAM permissions — Verify the role has
ce:*permissions
Incomplete resource scan
Incomplete resource scan
What to check:
- Regional coverage — Some resources may be in regions not yet scanned
- API rate limits — Large accounts may take longer to fully scan
- Missing permissions — Verify all Describe permissions are in place
Connecting Multiple AWS Accounts
If you have multiple AWS accounts (e.g., production, staging, development), you can connect each one:- Go to Settings → Integrations
- Click Connect AWS for each additional account
- Deploy the CloudFormation stack in each account
Next Steps
Connect GCP
Add your Google Cloud accounts for multi-cloud visibility.
Connect Azure
Add your Microsoft Azure accounts for multi-cloud visibility.