Skip to content
    Onboarding

    Minimum Permissions Required for Cloud Connect

    The least-privilege access SeqOps needs for AWS, Azure, and GCP, and the exact values to enter when connecting.

    SeqOps needs read-only access to each cloud environment. The table below summarizes the minimum access per provider; the sections that follow give the exact setup steps.

    Summary by Provider

    ProviderWhat you createAccess grantedValues you enter in SeqOps
    AWSIAM user with an access key, and an IAM role in the same accountSecurityAudit + ViewOnlyAccess (or ReadOnlyAccess) on the role; sts:AssumeRole for the userAccount Tag, Access Key ID, Secret Access Key, Default Region, Role ARN
    AzureApp registration with a client secretReader on the target subscriptionAccount Tag, Client ID, Client Secret, Tenant ID, Subscription ID
    GCPService account with a JSON keyViewer, plus two APIs enabledProject ID, Service Account Email, Private Key (JSON)

    AWS

    1. Create an IAM user with an access key. When asked for the use case, choose Third-party service.
    2. Create an IAM role in the same account:
      • •Trusted entity: AWS account → This account
      • •Leave Require external ID unchecked
      • •Name the role SeqOpsRole
    3. Attach SecurityAudit and ViewOnlyAccess (or ReadOnlyAccess) to the role.
    4. Add an inline policy to the IAM user that allows sts:AssumeRole on the role's ARN.
    5. In SeqOps, enter the Account Tag, Access Key ID, Secret Access Key, Default Region, and Role ARN.

    This is a same-account role. SeqOps does not use cross-account role assumption or a CloudFormation template.

    Azure

    1. Sign in to the Azure Portal.
    2. Register an application in Azure AD named SeqOps Integration.
    3. Under Certificates & Secrets, create a client secret and set an expiry.
    4. Grant the app the Reader role on the target subscription: Access control (IAM) → Add role assignment.
    5. In SeqOps, enter the Account Tag, Client ID, Client Secret, Tenant ID, and Subscription ID.

    When the client secret expires, the connection stops working. Note the expiry date so the secret can be renewed before it lapses.

    GCP

    1. In the GCP Console, go to IAM & Admin → Service Accounts and create a service account named seqops-integration.

    2. Grant it the Viewer role.

    3. Create and download a JSON key: Keys → Add Key → Create new key.

    4. Enable the Cloud Resource Manager API and the Compute Engine API. Both are off by default on new projects, and the Viewer role does not enable them — if you skip this step, a valid key still fails the connection test. Use the enable buttons in SeqOps, or run:

      gcloud services enable cloudresourcemanager.googleapis.com compute.googleapis.com --project=YOUR_PROJECT_ID

    5. In SeqOps, enter the Project ID, Service Account Email, and Private Key (JSON).

    After You Connect

    Click Test Credentials, then Save Details once the test succeeds. Each AWS account, Azure subscription, or GCP project counts as one cloud environment on your plan — see What Counts as a Cloud Environment.

    Need Help?

    If the connection test fails after you've checked every step, contact support@seqops.io or use the Contact Us page with the provider name and the exact validation error.

    permissionsiamawsazuregcpleast privilegecloud connect

    We use cookies

    We use essential cookies to run this site. With your permission, we'd also like to use analytics cookies to see how the site is used, and functional cookies for chat and videos. Change your choice any time under Cookie settings. Read our Cookies Policy