Amazon Web Services integration adapter

Prepare the current AWS account inventory connection without using access keys.

Outcome: Authorize WanAware to collect supported AWS account inventory through the released role-based setup.

For: WanAware customer administrators and AWS account administrators
Permission: read integrations and create integrations in WanAware, plus authority to deploy the generated stack in the AWS account
Time: About 10–20 minutes, plus stack deployment time
Changes made: Saves an AWS connection in WanAware and creates provider-side resources through CloudFormation

If you're stuck

  • Use the exact 12-digit account ID from the intended AWS account.
  • Generate the setup from WanAware; do not substitute long-lived access keys.
  • If Test connection fails, compare the Role ARN and stack status before deploying another stack.

Before you start

  • Get approval from the AWS account owner.
  • Confirm the 12-digit account ID without including it in screenshots or support messages unless sanitized.
  • Use the released generated stack; do not substitute long-lived access keys.
  • Review the stack's permissions before deployment.

Field and action guide

UI itemPurposeRequired value or resultSource
Account nameIdentifies the connection in WanAwareUnique, recognizable name with no credential dataYour naming standard
AWS account IDSelects the source accountExactly 12 digitsAWS account administration
Generate AWS setupCreates the released CloudFormation setupOpen only in the intended account and RegionWanAware setup page
Role ARNIdentifies the deployed access roleExact ARN created by the approved stackCloudFormation output
Test connectionChecks the saved role accessAWS connection verifiedWanAware after save
Run inventory crawlStarts inventory collectioncrawl request submittedSaved integration action
Delete integration…Removes the saved WanAware connectionUse only after impact and source-stack reviewIntegration action menu

Complete the adapter fields

  1. Open Administration → Integrations.
  2. Expand Amazon Web Services.
  3. For AWS Account Inventory, select Connect account.

Integrations page showing the available provider adapter, connection count, and Connect account action.
4. Enter a recognizable account name and the 12-digit AWS account ID.

Provider setup showing Connect, Test, and Crawl checkpoints before any account details are entered.
  1. Select Generate AWS setup.
  2. Open the generated CloudFormation setup and review it in the intended AWS account and Region.
  3. Deploy the stack after the account owner approves it.
  4. Return to WanAware and confirm that the Role ARN matches the created role.
  5. Save the integration.

Expected result: The account appears on the integration card with a connected status.

If the stack or role does not match, stop before repeating deployment. Record the stack status and exact error, without copying credential values.

Test and collect

  1. Select Test connection.
  2. Wait for a successful connection result.
  3. Select Run inventory crawl.
  4. Wait for the request confirmation, then verify a known record in Assets → Inventory.

Check your result

Open one imported asset and confirm its AWS account context and source identifier match the intended account.

Undo this change

Removing the WanAware connection does not automatically delete the CloudFormation stack. Coordinate these as separate actions:

  1. Confirm that no one still needs the collected inventory.
  2. Select Delete integration…, read Delete this AWS integration? This removes the saved account connection., and confirm only after approval.
  3. Ask the AWS account owner to review and delete the stack if it is no longer required.

Learn and continue

  • Learn: About integrations
  • In WanAware: Open /administration/integrations in your WanAware workspace.

Next steps

Get help

Email [email protected] with your company, affected user, sanitized integration identifier, failed stage, stack status, page URL, timestamp and time zone, and exact error. Never send an account credential, access key, token, role secret, external ID, or private key.


Did this page help you?