{% extends "base.html" %} {% block title %}Settings{% endblock %} {% block content %}

← Back

Settings

Accounts

Add account

Snapshots, the IP list, the Visual page and suggestions always show the active account (selector in the top bar). Rules are shared and can be limited to one account.

{% for c in accounts %} {% set a = c.account %} {% else %} {% endfor %}
AccountRegionAuthCredentialsScheduled refresh
{{ c.label }} {% if active_account and a.id == active_account.id %}active{% endif %} {% if a.aws_account_id %}
AWS {{ a.aws_account_id }}
{% endif %} {% if a.identity_warning %}
Warning: {{ a.identity_warning }}
{% endif %}
{{ a.region }} {{ a.mode_label }}{% if a.auth_mode == 'profile' %} {{ a.profile }}{% endif %} {% if a.auth_mode == 'env' %}process environment {% elif a.auth_mode == 'profile' %}~/.aws profile {% else %} {% if a.access_key_id %}{{ a.access_key_id }}{% endif %} {% if a.memory_only %}memory only{% else %}encrypted{% endif %} {% if a.problem %}{{ a.problem }} {% elif a.auth_mode == 'temporary' %}{{ a.status }}{% endif %} {% endif %}
Edit
No accounts yet — add one.

Test calls sts:GetCallerIdentity and ec2:DescribeVpcs with the account's saved credentials. A scheduled refresh runs while IPLens is running, as a background job like the Refresh button (skipped while the account already has a job running).

Logging

Snapshot retention

Applied after every Refresh: snapshots older than the window are deleted, and older than the downsample threshold only the newest successful snapshot of each day is kept (Trends stay bounded). The latest successful snapshot of each account is always kept.

Environments

A resource's environment comes from the Terraform repo root × environment that manages it; otherwise from the Ownership environment tag key below, then the first of these tag keys found on the resource, its subnet or its VPC (case-insensitive).

Ownership

Who manages each resource, first match wins: CloudFormation stack (cloudformation:ListStacks / ListStackResources) > IaC tag (the project / repo tag key) > Terraform state (only with the enrichment below) > CloudTrail creator (a CI role → "IaC (unknown repo)", anyone else → "manual") > unmanaged. Tags come from tag:GetResources. Only the values of these tag keys are kept; other tags are kept by key only (for the lists below).

{% for name, label in own_fields.items() %}
{% endfor %}

{% if seen_tag_keys %}{{ seen_tag_keys | length }} tag key(s) seen in the active account's latest snapshot. {% else %}No tag keys seen yet: Refresh the active account to fill these lists.{% endif %} A newly chosen key applies to every resource from the next Refresh.

Glob patterns (case-insensitive), comma or newline separated. A CloudTrail creator whose role / IAM user name matches one is a CI pipeline ("IaC (unknown repo)"); any other creator is "manual".

Opt-in, at most {{ cloudtrail_max }} resources per Refresh. CloudTrail event history only covers the last {{ cloudtrail_days }} days: older resources stay unmanaged. Only the creating role / user name is kept, never its ARN or session name.

Off by default. When on, mapped Terraform repos are also re-synced with every Refresh.

Terraform sync

Applies to terraform init and terraform show -json (default 120) of roots whose backend is not S3. Roots on an s3 backend never run terraform: their state object is read directly (read-only) with the mapped account's credentials, eight at a time; set values CI passes with -backend-config per root on the Terraform repo page. Two terraform root × environment pairs run at a time; providers are cached once in the IPLens data directory, and git module fetches fail instead of prompting for credentials.

Terraform state

Load one or more .tfstate files or terraform show -json outputs, each as a named root. IPLens reads them locally and never modifies them. Only resource ids, addresses and types are kept (for {{ tf_types | join(', ') }}); attribute values, outputs and sensitive data are discarded while reading. The IP List, ENI pages and the Visual page then show which root manages each resource.

{% for r in tf_roots %} {% else %} {% endfor %}
RootSourceResource idsLoaded
{{ r.name }} {{ r.source }}{% if r.origin == 'repo' %} repo sync{% elif not r.source_path %} upload{% endif %} {{ r.resources }} {{ r.loaded_at | localtime }} {% if r.source_path %}
{% endif %}
No Terraform roots loaded.

Loading a root name again replaces it.

Terraform repos

Add a local Terraform repository. IPLens scans its .tf / .tfvars files (without running terraform) for roots, environments (env folders, *.tfvars, workspaces) and backends, and guesses each environment's AWS account. After you confirm the mapping, Sync (and every Refresh of a mapped account) runs only terraform init -input=false -lockfile=readonly, terraform workspace select and terraform show -json with the mapped account's credentials and TF_DATA_DIR in the IPLens data directory: the repository is never modified, and plan / apply / import are never run. Only resource ids, addresses and types are kept. See Ownership for sync status and drift. Terraform is an optional ownership source: enable the Terraform enrichment under Ownership to use it (and to re-sync mapped repos with every Refresh).

{% for p in tf_repos %} {% else %} {% endfor %}
RepositoryRootsRoot × envSynced pairsScanned
{{ p.path }} {{ p.roots }} {{ p.envs }} {{ p.confirmed }} {{ p.discovered_at | localtime }} Review mapping
No Terraform repos added.

IPLens only performs read-only AWS calls (Describe*/List*/Get*). Minimal IAM permissions: ec2:DescribeVpcs, ec2:DescribeSubnets, ec2:DescribeNetworkInterfaces, ec2:DescribeVpcEndpoints, lambda:ListFunctions, elasticloadbalancing:DescribeLoadBalancers. Optional: iam:ListAccountAliases (account name in the header); elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth, ec2:DescribeSecurityGroups (connections and security group names on the Visual page); elasticloadbalancing:DescribeTags, lambda:ListTags (load balancer and Lambda tags); tag:GetResources, cloudformation:ListStacks, cloudformation:ListStackResources (ownership) and, when enabled, cloudtrail:LookupEvents (creator of unowned resources). The Extended view's Kafka nodes need kafka:ListClustersV2 (Amazon MSK clusters) and lambda:ListEventSourceMappings; without them the source is skipped with a warning.
{% endblock %}