Minimum Permissions Required for Cloud Connect
The least-privilege access SeqOps needs for AWS, Azure, and GCP, and the exact values to enter when connecting.
SeqOps needs read-only access to each cloud environment. The table below summarizes the minimum access per provider; the sections that follow give the exact setup steps.
Summary by Provider
| Provider | What you create | Access granted | Values you enter in SeqOps |
|---|---|---|---|
| AWS | IAM user with an access key, and an IAM role in the same account | SecurityAudit + ViewOnlyAccess (or ReadOnlyAccess) on the role; sts:AssumeRole for the user | Account Tag, Access Key ID, Secret Access Key, Default Region, Role ARN |
| Azure | App registration with a client secret | Reader on the target subscription | Account Tag, Client ID, Client Secret, Tenant ID, Subscription ID |
| GCP | Service account with a JSON key | Viewer, plus two APIs enabled | Project ID, Service Account Email, Private Key (JSON) |
AWS
- Create an IAM user with an access key. When asked for the use case, choose Third-party service.
- Create an IAM role in the same account:
- •Trusted entity: AWS account → This account
- •Leave Require external ID unchecked
- •Name the role SeqOpsRole
- Attach
SecurityAuditandViewOnlyAccess(orReadOnlyAccess) to the role. - Add an inline policy to the IAM user that allows
sts:AssumeRoleon the role's ARN. - In SeqOps, enter the Account Tag, Access Key ID, Secret Access Key, Default Region, and Role ARN.
This is a same-account role. SeqOps does not use cross-account role assumption or a CloudFormation template.
Azure
- Sign in to the Azure Portal.
- Register an application in Azure AD named SeqOps Integration.
- Under Certificates & Secrets, create a client secret and set an expiry.
- Grant the app the Reader role on the target subscription: Access control (IAM) → Add role assignment.
- In SeqOps, enter the Account Tag, Client ID, Client Secret, Tenant ID, and Subscription ID.
When the client secret expires, the connection stops working. Note the expiry date so the secret can be renewed before it lapses.
GCP
-
In the GCP Console, go to IAM & Admin → Service Accounts and create a service account named seqops-integration.
-
Grant it the Viewer role.
-
Create and download a JSON key: Keys → Add Key → Create new key.
-
Enable the Cloud Resource Manager API and the Compute Engine API. Both are off by default on new projects, and the Viewer role does not enable them — if you skip this step, a valid key still fails the connection test. Use the enable buttons in SeqOps, or run:
gcloud services enable cloudresourcemanager.googleapis.com compute.googleapis.com --project=YOUR_PROJECT_ID
-
In SeqOps, enter the Project ID, Service Account Email, and Private Key (JSON).
After You Connect
Click Test Credentials, then Save Details once the test succeeds. Each AWS account, Azure subscription, or GCP project counts as one cloud environment on your plan — see What Counts as a Cloud Environment.
Need Help?
If the connection test fails after you've checked every step, contact support@seqops.io or use the Contact Us page with the provider name and the exact validation error.