Kubesense

Resource & Metric Collection

Connect AWS accounts to KubeSense for read-only inventory and CloudWatch metrics — one account at a time, or every account in an AWS Organization.

Overview

KubeSense observes an AWS account using read-only credentials, discovering your resources and pulling their metrics from CloudWatch so the cloud estate appears alongside the Kubernetes telemetry KubeSense already collects. Nothing is created, changed or deleted in the account — every call is a Describe, List, Get or GetMetricData.

This section is what connects an account. The log integrations elsewhere in this section are separate: they stream log data into KubeSense and do not need any of this.

Choose a path

Single Account Setup

Multi-Account Setup

Single AccountMulti-Account
Use it whenYou have one account, or a few you would rather add by handYour estate spans an AWS Organization
How the role gets thereOne CloudFormation stack, or a role you create yourselfA StackSet across your OUs, covering accounts added later
Accounts added laterYou add each oneEnrolled automatically
Extra stepsNoneA discovery preview you approve before anything is created

Both use read-only cross-account roles and store no long-lived AWS keys. Every account is verified against its own identity before any data is ingested, so a misconfigured role fails closed rather than attributing one account's resources to another.

What gets collected

Every AWS resource type KubeSense discovers, and every CloudWatch metric it collects for each, is listed in the AWS resource and metric reference — worth a look before choosing resource types on either path.

Common to both

Whichever path you take, the KubeSense controller needs an identity of its own — an EKS IRSA role or an EC2 instance profile — and every account you observe trusts that identity to assume its read-only collector role. Confirm the identity before you start:

kubectl exec -n kubesense <controller-pod> -- \
  aws sts get-caller-identity --query Arn --output text

If it prints an assumed-role ARN, convert it to the plain IAM role form — arn:aws:iam::111111111111:role/kubesense-controller — and use that everywhere.