Orion Platform

Items to consider when adding Amazon Web Services (AWS) Cloud Account for Monitoring

This article shows things to check when adding Amazon Web Services (AWS) Cloud Account failed

First published date

7/13/2021 11:13 PM

Last published date

9/1/2022 9:08 PM

Overview

There are 2 requirements to successfully configure Cloud monitoring:
  1. Orion polling server is able to access AWS HTTPS web API
  2. Cloud account used for monitoring has proper permissions

AWS URLs for Firewall/Proxy Settings Whitelisting:
  • https://amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • https://aws.amazon.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • autoscaling.*.amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • https://*.awsstatic.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • https://*.amazontrust.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • https://ec2.*.amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • https://events.*.amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • monitoring.*.amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
Note: The access to the proxy should be added to the Main Engine.
(Add Cloud Account Wizard and Job is provided by the Main Engine)

Reference: Orion URLs for Firewall Whitelisting

Product section

Orion Platform

Cause

N/A

Resolution

PART 1: Verify if the AWS URLs and APIs are accessible from the Polling Engine:

Format: protocol://service-code.region-code.amazonaws.com

Where to find:
- Region Code (© 2022 Amazon Web Services, available at https://docs.aws.amazon.com/, obtained on September 1, 2022)
- Service Code (© 2022 Amazon Web Services, available at https://docs.aws.amazon.com/, obtained on September 1, 2022)

Example: 
  • region(s): us-west-2 and us-east-1
  • service(s): Amazon Web Services (AWS) EC2

URLs:
  • https://ec2.us-east-1.amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)
  • https://ec2.us-west-2.amazonaws.com (© 2022 Amazon Web Services, available at https://aws.amazon.com/, obtained on September 1, 2022)

APIs: 
  • https://api.ec2.us-east-1.aws 
  • https://api.ec2.us-west-2.aws

PART 2: Account Permissions:

AWS account requires the following resource-level permissions:
  • ec2:DescribeInstances
  • ec2:DescribeAddresses
  • ec2:DescribeVolumes
  • ec2:DescribeVolumeStatus
  • cloudwatch:GetMetricStatistics
  • autoscaling:DescribeAutoScalingInstances

Permission for Actions that can be performed against an instance:
  • ec2:StartInstances
  • ec2:StopInstances
  • ec2:RebootInstances
  • ec2:TerminateInstances

References:
- Configure AWS accounts for cloud monitoring
- Find cloud account credentials

Procedures:
- Add the cloud account to the Orion Platform