> For the complete documentation index, see llms.txt.
Skip to main content

Check out Port for yourself ➜ 

AWS

AWS iconAWS icon
Loading version...

Port's AWS integration imports your AWS resources into Port, with flexible deployment options to match your needs. The integration syncs your AWS resources on a schedule and can optionally process live events so your Port catalog stays up to date with your AWS infrastructure.

Port's AWS integration is open source. View the source code here.

Custom kinds not supported

AWS only syncs the resource kinds listed above. Unlike the AWS Legacy integration, it does not support defining custom kinds for other Cloud Control API resources yet.

Deployment options​

The integration can be deployed using one of the following methods:

  • Hosted by Port: Fully managed by Port with zero maintenance required. Simply create IAM roles via CloudFormation, and Port handles the rest.
  • Self-hosted: Deploy the integration in your own infrastructure using ECS, EC2, EKS, or as a one-off Docker run for complete control.

For detailed information about the IAM role architecture, see the IAM role architecture section of the installation page.

Live events​

You can optionally enable live events to update supported resource kinds in real time between resyncs. Live events use CloudTrail management events forwarded by EventBridge to Port.

Deploy live events with a separate CloudFormation stack after the integration is installed. Follow the Live events (optional) step in the installation wizard. Not every resource kind supports live events yet. See supported and unsupported resource kinds on the live events page.

GovCloud and on-premises support

The integration supports AWS GovCloud.
When running a self-hosted GovCloud integration, it is recommended to run using the AssumeRole mode.

If you run in StaticCredentials mode, you will need to set the OCEAN__INTEGRATION__CONFIG__AWS_PARTITION environment variable to specify your AWS partition (for example, aws-us-gov for GovCloud).

Common use cases​

Easily fill your software catalog with data directly from your AWS Organization, for example:

  • Map all the resources in your AWS Accounts, including ECS Clusters, S3 Buckets, and EC2 Instances with zero maintenance required.
  • Keep your Port catalog synchronized with your AWS infrastructure through periodic updates and optional live events.
  • Use relations to create complete, easily digestible views of your AWS infrastructure inside Port.
  • Enjoy a fully managed experience with no infrastructure to maintain or updates to apply.
Multi-account support

The integration supports syncing resources across multiple AWS accounts using automatic account discovery via AWS Organizations. See the account discovery section of the installation page for details.

Key advantages​

AWS provides several advantages over the AWS Legacy integration:

  • Fully hosted: No infrastructure to maintain, update, or monitor.
  • Simplified installation: Just deploy CloudFormation templates to create IAM roles.
  • Complete data: Ensures no missing or incomplete resource information.

Configuration​

Port integrations use a YAML mapping block to ingest data from the third-party api into Port.

The mapping makes use of the JQ JSON processor to select, modify, concatenate, transform and perform other operations on existing fields and values from the integration API.

Property naming conventions

The AWS integration returns all resource properties in PascalCase (for example: Arn, BucketName, CreationDate). When writing mappings and JQ expressions, reference properties using PascalCasing as shown in the examples below.

Default mapping configuration​

This is the default mapping configuration you get after installing AWS.

Default mapping configuration (click to expand)
deleteDependentEntities: true
createMissingRelatedEntities: true
enableMergeEntity: true
resources:
- kind: AWS::Account::Info
selector:
query: 'true'
port:
entity:
mappings:
identifier: .Properties.Id
title: .Properties.Name
blueprint: '"awsAccount"'
- kind: AWS::S3::Bucket
selector:
query: 'true'
port:
entity:
mappings:
identifier: .Properties.Arn
title: .Properties.BucketName
blueprint: '"s3Bucket"'
properties:
arn: .Properties.Arn
region: .Properties.LocationConstraint
creationDate: .Properties.CreationDate
tags: .Properties.Tags
relations:
account: .__ExtraContext.AccountId
- kind: AWS::EC2::Instance
selector:
query: 'true'
port:
entity:
mappings:
identifier: .Properties.InstanceId
title: .Properties.InstanceId
blueprint: '"ec2Instance"'
properties:
instanceType: .Properties.InstanceType
state: .Properties.State.Name
publicIpAddress: .Properties.PublicIpAddress
privateIpAddress: .Properties.PrivateIpAddress
tags: .Properties.Tags
arn: >-
"arn:aws:ec2:" + .__Region + ":" + .__AccountId + ":instance/" +
.Properties.InstanceId
relations:
account: .__ExtraContext.AccountId
- kind: AWS::ECS::Cluster
selector:
query: 'true'
port:
entity:
mappings:
identifier: .Properties.ClusterArn
title: .Properties.ClusterName
blueprint: '"ecsCluster"'
properties:
status: .Properties.Status
runningTasksCount: .Properties.RunningTasksCount
activeServicesCount: .Properties.ActiveServicesCount
pendingTasksCount: .Properties.PendingTasksCount
registeredContainerInstancesCount: .Properties.RegisteredContainerInstancesCount
capacityProviders: .Properties.CapacityProviders
clusterArn: .Properties.ClusterArn
tags: .Properties.Tags
relations:
account: .__ExtraContext.AccountId

Monitoring and sync status​

To learn more about how to monitor and check the sync status of your integration, see the relevant documentation.

Mapping & selectors per resource​

The following sections show examples of blueprint definitions and mapping configurations for common AWS resources.

Resource and property reference​

Refer to the resource and property reference page for details on available AWS resources, their properties, and mapping examples.