Connect

Clouds

Connect a cloud account and its resources appear on the topology, kept in sync and checked on a schedule.

A cloud account gives agents the infrastructure behind your system. Polylane syncs its resources into the topology, records every change, and checks each resource on a schedule.

What it does

Connecting an account discovers the resources your credentials can see and adds them to the topology as nodes, with edges for how they relate. Accounts re-sync on their own; the account header shows a Last synced time and a Sync with Cloud action for when you cannot wait. Once the first sync completes, anomaly checks run against every resource at the pace its tier sets, and advisories are computed from the topology as it fills in.

These providers connect as cloud accounts:

Connect an account

Pick a provider

Open Settings > Clouds in the console and choose Connect a cloud account. AWS deploys a CloudFormation stack that creates a role in your account and the page waits until the stack reports back; most other providers take an API token or sign you in through OAuth. Each provider page at /integrations/<type> lists the exact credentials it needs, and from the terminal polylane cloud connect runs the same flow.

If nothing in your environment clicks console links, cloud accounts also connect entirely over the API: every provider page that supports it has a Pipeline tab with the exact calls, starting with /integrations/aws.

Let the first sync finish

The account header shows sync progress. Resources appear on the topology as they are discovered, and Polylane starts watching the account as soon as the first sync completes.

Review what Polylane watches

Open the account's Settings tab to confirm the check frequency and decide whether agents may write to the account. The tabs below show what the account page gives you from then on.

Read-only by default

Accounts start read-only: agents can call the provider's read endpoints, and any write call is refused with the reason. A workspace admin can turn Read-only off in the account's Settings tab, except for Kubernetes clusters connected through the agent, which stay read-only. Even with writes enabled, a direct provider write is held until you confirm it in the thread where you asked for it, and background runs nobody has written to stay read-only.

The account page

TabWhat it shows
Cloud GraphThe account's slice of the topology, filterable by type. Select a node to open its resource page.
ProblemsThe fix runs on issues scoped to this account, one row per run with its severity and outcome, plus the account's recent check evaluations.
AlertsAutomatic triage for the account's alerts: alerts that fire become issues and get a fix run when confirmed. Shown for AWS, Cloudflare, Vercel, Render, Supabase and Convex.
Key questionsThe questions Polylane works out are worth asking about the account, each paired with a query in the provider's own query language and rechecked on a schedule. Shown for AWS, Cloudflare, Vercel, Fly.io, Render, Supabase and Railway.
RepositoriesThe source code behind the account's resources, matched from your connected repositories or added by you. Discovery needs a connected GitHub.
SettingsCredentials, with Verify and Rotate; the Read-only switch; the anomaly check Frequency; Re-classify tiers; and provider-specific options such as AWS regions, Vercel telemetry, and monitoring for preview deployments.
PropertiesThe raw account record.
  • Topology for how to read the graph the account fills in.
  • Integrations for connect methods and what disconnecting removes.
  • Issues for what the scheduled checks raise.