Resource & Metric Collection
Connect AWS accounts to KubeSense for read-only inventory and CloudWatch metrics — one account at a time, or every account in an AWS Organization.
Overview
KubeSense observes an AWS account using read-only credentials, discovering your
resources and pulling their metrics from CloudWatch so the cloud estate appears alongside
the Kubernetes telemetry KubeSense already collects. Nothing is created, changed or
deleted in the account — every call is a Describe, List, Get or GetMetricData.
This section is what connects an account. The log integrations elsewhere in this section are separate: they stream log data into KubeSense and do not need any of this.
Choose a path
Single Account Setup
Multi-Account Setup
| Single Account | Multi-Account | |
|---|---|---|
| Use it when | You have one account, or a few you would rather add by hand | Your estate spans an AWS Organization |
| How the role gets there | One CloudFormation stack, or a role you create yourself | A StackSet across your OUs, covering accounts added later |
| Accounts added later | You add each one | Enrolled automatically |
| Extra steps | None | A discovery preview you approve before anything is created |
Both use read-only cross-account roles and store no long-lived AWS keys. Every account is verified against its own identity before any data is ingested, so a misconfigured role fails closed rather than attributing one account's resources to another.
What gets collected
Every AWS resource type KubeSense discovers, and every CloudWatch metric it collects for each, is listed in the AWS resource and metric reference — worth a look before choosing resource types on either path.
Common to both
Whichever path you take, the KubeSense controller needs an identity of its own — an EKS IRSA role or an EC2 instance profile — and every account you observe trusts that identity to assume its read-only collector role. Confirm the identity before you start:
kubectl exec -n kubesense <controller-pod> -- \
aws sts get-caller-identity --query Arn --output textIf it prints an assumed-role ARN, convert it to the plain IAM role form —
arn:aws:iam::111111111111:role/kubesense-controller — and use that everywhere.