Projects

AWS connection

Choose how Colonize obtains temporary access

Cross-account role is recommended for a hosted installation. Environment credentials remain available for local or operator-managed hosting.

Not verified

No dashboard-stored AWS credentials.
Colonize assumes this customer role with the generated external ID and receives short-lived credentials.

Add this exact value to the role trust policy.

Access check

Verified capabilities

The selected identity is tested against Colonize-managed outcomes.

Build and deploy

Run scoped CodeBuild jobs and deploy verified artifacts through the trusted deployment role.

Awaiting verification
Optional resources

Provision Object Store, certificate, and routing resources only when enabled.

Awaiting verification

AWS-owned controls

Costs, quotas, and log retention

Colonize does not impose limits or duplicate AWS administration controls.

Budgets and alerts

Set optional spend thresholds and notifications in AWS Budgets.

Service quotas

Review and request Lambda, API Gateway, CodeBuild, and ACM quotas in AWS.

Log retention

Choose CloudWatch retention and exports in AWS; Colonize only reads or downloads.

AWS beginner guideHow do I create the cross-account role?
  1. 1
    Open IAM in the customer account

    Create a custom role and choose custom trust policy.

  2. 2
    Trust the Colonize account and external ID

    Paste the generated external ID exactly; do not use a wildcard principal.

  3. 3
    Attach the Colonize deployment policy

    Grant only the documented build and deployment resource actions.

  4. 4
    Return and verify

    Colonize checks the account ID, Region, and required capabilities before saving.