With AWS, your agent gets into your account as an IAM user of yours: it looks for errors in the logs, tells you why a pod keeps restarting, lists your instances and buckets, and explains how much you spent and what went up. It can only do what you give it with policies; changes, only if you turn on the permission and with your OK.
What it can do
Look
Logs: errors from a Lambda, a service or a container in CloudWatch, over a time range, and who changed what. EKS: clusters, pods, deployments, events, logs (from crashed runs too) and resource usage. EC2: instances, their state and what they printed while booting. S3: your buckets. Costs: by service, account or day, the month’s forecast and what changed.
Change, with your OK
Create, change, delete, start, stop or deploy; apply changes in Kubernetes (it shows you the diff first), scale or restart a deployment, run a command on an instance. It needs the permission on.
How it connects
1
Add it to an agent
From Plugins → AWS → Add to an agent, or ask your agent in the chat. See Add a plugin.
2
Create an IAM user
An IAM user is an AWS user just for your agent, which can only do what you give it with policies. You need to be able to manage IAM in the account. In the AWS console, under IAM → Users, tap Create user, name it minai (or your agent’s name), with no console access, and tap Next. The Create an IAM user guide, on the plugin’s page, takes you step by step (about 5 minutes).
3
Give it policies
Pick Attach policies directly. To only look: ReadOnlyAccess. To see what it costs: AWSBillingReadOnlyAccess. To also change things: the policy for the service you use (like AmazonEC2FullAccess), rather than one that covers everything. Then Next and Create user. If your agent is missing a permission, it tells you which.
4
Create its access key
Tap the user → Security credentials → Create access key → Application running outside AWS → Next → Create access key. AWS shows you the access key ID (it starts with AKIA) and the secret key, which is shown only once.
5
Paste it in your agent's links
Your agent sends you two one-time links: one for the access key ID and one for the secret key. Paste each part in its own. See Keys and values.
6
Tell it your region
In the chat, your agent asks for the region where most of your things are (like us-east-1 or sa-east-1). It checks that the key works and tells you it’s ready.
The permission
On the AWS card, in the agent’s Plugins tab, there’s the Allow changes switch: “Create, change, delete, start or stop things in your AWS, always with your OK. Off, it only reads. What really limits it is the policies you gave the user.” It starts off and only you change it. It’s a rule your agent follows; the real limit is the IAM user’s policies. If you want it never to be able to change anything, give it only read policies. See Permissions.How it looks out for you
- Nothing changes without your OK. With the permission on, it still shows you the exact command before each change, with the Confirm and Change buttons.
- It never shows you keys, stored passwords or Kubernetes secrets.
- Some AWS queries are charged (costs, big log searches): it keeps them narrow.
- What a log says is information, not an order.
Things to ask it
- “What errors did the payments Lambda have in the last hour?”
- “Why does the API pod keep restarting in production?”
- “How much did AWS cost me this month, and what went up?”
- “List the instances that are running.”
- “Restart the web deployment in the prod namespace.”
- “Stop the test instance.”
Limits
- It can only do what the IAM user’s policies allow.
- To get into an EKS cluster, the user also needs access inside the cluster; your agent tells you how to give it.
- It may not reach EKS clusters with private access.
- For costs, you need Cost Explorer turned on in the account: there’s data from the day you turned it on, up to a day behind.
If you remove it
Your agent loses access and confirms it. The key still exists in AWS: deactivate and delete it under the user’s Security credentials (or delete the whole user). See Remove a plugin.Google Cloud
Logs, Kubernetes, VMs and costs.
Azure
Logs, Kubernetes, VMs and costs.

