arctic parade

← Field guides

MSP cloud operators and internal platform teams

Connect AWS, Azure, Google Cloud and DigitalOcean safely

Choose the supported read-only inventory path for each provider, apply least privilege and understand which lifecycle evidence is available.

Published by Arctic Parade LTD · Updated 2026-09-20 · Sources and editorial process

Keep workspace access separate from cloud access

An Arctic Parade account grants access to the workspace. Each cloud connection is a separate customer-authorised permission mapped to one managed estate. Use a dedicated identity, short-lived or rotatable credentials and the smallest provider scope that contains the inventory being reviewed.

AWS uses a cross-account role

Arctic Parade assumes a customer IAM role with a unique external ID and temporary STS credentials. Enable Resource Explorer, create an aggregator index and view in the region you connect, and grant the role GetView and Search on that view. A search returns at most 1,000 results, so a partial health state requires a narrower view. AWS Health retirement events are not part of the base connector because the API requires an eligible paid AWS Support plan.

Google Cloud uses Cloud Asset Inventory

Enable Cloud Asset Inventory and grant a dedicated service account cloudasset.assets.searchAllResources at the project, folder or organisation being connected. Enter that scope and its JSON credential. The key is encrypted and excluded from exports. Rotate the key in Google Cloud, reconnect, verify a successful scan and revoke the old key.

DigitalOcean uses a scoped token

Create a token for the appropriate team with project:read and the read scopes for resource types you manage, or use the documented Read Only option. Enter the project UUID and token. The project resource API supplies URNs and types; some display detail is unavailable in that endpoint, so the inventory preserves the stable URN as its identity.

Azure retains Advisor evidence

The Azure connector lists subscription resources and Advisor service-upgrade and retirement recommendations. Use Reader or a tested custom role at the selected subscription. Exact provider evidence can confirm a catalogue match; generic inventory from AWS, Google Cloud or DigitalOcean remains a review candidate until provider-specific lifecycle evidence is implemented.

Test and offboard

Run a first sync with a small non-production scope, compare counts with the provider console and inspect resource types and customer mapping. Disconnecting erases the locally stored credential but does not revoke provider access. Revoke the IAM role trust, service-account key, application credential or API token at the provider as a separate offboarding step.

Sources and further reading

Related field guides

Put the process to work.

Explore the current Azure retirement catalogue, then try a small estate scan. Read the coverage limits before acting on a match.