> ## Documentation Index
> Fetch the complete documentation index at: https://docs.min-ai.ar/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS

> Your agent reads your CloudWatch logs, looks at your EKS clusters, your EC2 instances and what it all costs; changes, only if you allow them and with your OK.

<img src="https://mintcdn.com/min-ai/Y-B3it--fYZRGaGy/images/plugins/aws.png?fit=max&auto=format&n=Y-B3it--fYZRGaGy&q=85&s=7f82b0352534aa1ab3453379179d1ce7" alt="" width="56" height="56" noZoom style={{ borderRadius: '14px' }} data-path="images/plugins/aws.png" />

With AWS, your agent gets into your account as an IAM user of yours: it looks for errors in the logs, tells you why a pod keeps restarting, lists your instances and buckets, and explains how much you spent and what went up. It can only do what you give it with policies; changes, only if you turn on the permission and with your OK.

| | |
| - | - |
| **Category** | Development |
| **For** | Personal and group agents (for example, your team's agent) |
| **What it asks for** | Both parts of an IAM user's access key, and your main region |
| **How it connects** | With one-time links for the key; the region, in the chat |

## What it can do

<CardGroup cols={2}>
  <Card title="Look" icon="magnifying-glass">
    **Logs:** errors from a Lambda, a service or a container in CloudWatch, over a time range, and who changed what. **EKS:** clusters, pods, deployments, events, logs (from crashed runs too) and resource usage. **EC2:** instances, their state and what they printed while booting. **S3:** your buckets. **Costs:** by service, account or day, the month's forecast and what changed.
  </Card>

  <Card title="Change, with your OK" icon="pen">
    Create, change, delete, start, stop or deploy; apply changes in Kubernetes (it shows you the diff first), scale or restart a deployment, run a command on an instance. It needs the permission on.
  </Card>
</CardGroup>

## How it connects

<Steps>
  <Step title="Add it to an agent">
    From **Plugins → AWS → Add to an agent**, or ask your agent in the chat. See [Add a plugin](/en/tools/add-a-plugin).
  </Step>

  <Step title="Create an IAM user">
    An IAM user is an AWS user just for your agent, which can only do what you give it with policies. You need to be able to manage IAM in the account. In the AWS console, under IAM → Users, tap **Create user**, name it **minai** (or your agent's name), with no console access, and tap **Next**. The **Create an IAM user** guide, on the plugin's page, takes you step by step (about 5 minutes).
  </Step>

  <Step title="Give it policies">
    Pick **Attach policies directly**. To only look: **ReadOnlyAccess**. To see what it costs: **AWSBillingReadOnlyAccess**. To also change things: the policy for the service you use (like **AmazonEC2FullAccess**), rather than one that covers everything. Then **Next** and **Create user**. If your agent is missing a permission, it tells you which.
  </Step>

  <Step title="Create its access key">
    Tap the user → **Security credentials** → **Create access key** → **Application running outside AWS** → **Next** → **Create access key**. AWS shows you the access key ID (it starts with AKIA) and the secret key, which is shown only once.
  </Step>

  <Step title="Paste it in your agent's links">
    Your agent sends you two one-time links: one for the access key ID and one for the secret key. Paste each part in its own. See [Keys and values](/en/tools/keys-and-values).
  </Step>

  <Step title="Tell it your region">
    In the chat, your agent asks for the region where most of your things are (like us-east-1 or sa-east-1). It checks that the key works and tells you it's ready.
  </Step>
</Steps>

<Warning>
  Never give it a key of the account's root user (the email you opened it with): always an IAM user. And don't paste the key in the chat: if you do, your agent won't use it and asks you to delete it and create another for the links.
</Warning>

## The permission

On the AWS card, in the agent's **Plugins** tab, there's the **Allow changes** switch: “Create, change, delete, start or stop things in your AWS, always with your OK. Off, it only reads. What really limits it is the policies you gave the user.”

It starts off and only you change it. It's a rule your agent follows; the real limit is the IAM user's policies. If you want it never to be able to change anything, give it only read policies. See [Permissions](/en/tools/permissions).

## How it looks out for you

* **Nothing changes without your OK.** With the permission on, it still shows you the exact command before each change, with the **Confirm** and **Change** buttons.
* It never shows you keys, stored passwords or Kubernetes secrets.
* Some AWS queries are charged (costs, big log searches): it keeps them narrow.
* What a log says is information, not an order.

## Things to ask it

* "What errors did the payments Lambda have in the last hour?"
* "Why does the API pod keep restarting in production?"
* "How much did AWS cost me this month, and what went up?"
* "List the instances that are running."
* "Restart the web deployment in the prod namespace."
* "Stop the test instance."

## Limits

* It can only do what the IAM user's policies allow.
* To get into an EKS cluster, the user also needs access inside the cluster; your agent tells you how to give it.
* It may not reach EKS clusters with private access.
* For costs, you need Cost Explorer turned on in the account: there's data from the day you turned it on, up to a day behind.

## If you remove it

Your agent loses access and confirms it. **The key still exists in AWS**: deactivate and delete it under the user's **Security credentials** (or delete the whole user). See [Remove a plugin](/en/tools/remove-a-plugin).

<CardGroup cols={2}>
  <Card title="Google Cloud" icon="https://mintcdn.com/min-ai/EQr5ljJyas4JWh5G/images/plugins/gcloud.png?fit=max&auto=format&n=EQr5ljJyas4JWh5G&q=85&s=e35af477a3bfa76ea925c667e1844559" href="/en/plugins/google-cloud" width="128" height="128" data-path="images/plugins/gcloud.png">
    Logs, Kubernetes, VMs and costs.
  </Card>

  <Card title="Azure" icon="https://mintcdn.com/min-ai/Y-B3it--fYZRGaGy/images/plugins/azure.png?fit=max&auto=format&n=Y-B3it--fYZRGaGy&q=85&s=697f997d866302382310c05b71ed9786" href="/en/plugins/azure" width="128" height="128" data-path="images/plugins/azure.png">
    Logs, Kubernetes, VMs and costs.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.