{% extends "base.html" %} {% block title %}Settings{% endblock %} {% block content %}
Snapshots, the IP list, the Visual page and suggestions always show the active account (selector in the top bar). Rules are shared and can be limited to one account.
| Account | Region | Auth | Credentials | Scheduled refresh | |
|---|---|---|---|---|---|
| {{ c.label }}
{% if active_account and a.id == active_account.id %}active{% endif %}
{% if a.aws_account_id %} AWS {{ a.aws_account_id }} {% endif %}
{% if a.identity_warning %}Warning: {{ a.identity_warning }} {% endif %} |
{{ a.region }} | {{ a.mode_label }}{% if a.auth_mode == 'profile' %} {{ a.profile }}{% endif %} | {% if a.auth_mode == 'env' %}process environment {% elif a.auth_mode == 'profile' %}~/.aws profile {% else %} {% if a.access_key_id %}{{ a.access_key_id }}{% endif %} {% if a.memory_only %}memory only{% else %}encrypted{% endif %} {% if a.problem %}{{ a.problem }} {% elif a.auth_mode == 'temporary' %}{{ a.status }}{% endif %} {% endif %} | Edit | |
| No accounts yet — add one. | |||||
Test calls sts:GetCallerIdentity and ec2:DescribeVpcs with the account's saved credentials. A scheduled refresh runs while IPLens is running, as a background job like the Refresh button (skipped while the account already has a job running).
Load one or more .tfstate files or terraform show -json outputs, each as a named root. IPLens reads them locally and never modifies them. Only resource ids, addresses and types are kept (for {{ tf_types | join(', ') }}); attribute values, outputs and sensitive data are discarded while reading. The IP List, ENI pages and the Visual page then show which root manages each resource.
| Root | Source | Resource ids | Loaded | |
|---|---|---|---|---|
| {{ r.name }} | {{ r.source }}{% if r.origin == 'repo' %} repo sync{% elif not r.source_path %} upload{% endif %} | {{ r.resources }} | {{ r.loaded_at | localtime }} | {% if r.source_path %} {% endif %} |
| No Terraform roots loaded. | ||||
Add a local Terraform repository. IPLens scans its .tf / .tfvars files (without running terraform) for roots, environments (env folders, *.tfvars, workspaces) and backends, and guesses each environment's AWS account. After you confirm the mapping, Sync (and every Refresh of a mapped account) runs only terraform init -input=false -lockfile=readonly, terraform workspace select and terraform show -json with the mapped account's credentials and TF_DATA_DIR in the IPLens data directory: the repository is never modified, and plan / apply / import are never run. Only resource ids, addresses and types are kept. See Ownership for sync status and drift. Terraform is an optional ownership source: enable the Terraform enrichment under Ownership to use it (and to re-sync mapped repos with every Refresh).
| Repository | Roots | Root × env | Synced pairs | Scanned | |
|---|---|---|---|---|---|
| {{ p.path }} | {{ p.roots }} | {{ p.envs }} | {{ p.confirmed }} | {{ p.discovered_at | localtime }} | Review mapping |
| No Terraform repos added. | |||||