RESOURCES · CLOUD MAP

See your cloud as it really is.

Cloud Map reads your AWS and Google Cloud accounts and draws their resources, the connections their settings prove, internet exposure and known cost. Azure and DigitalOcean are coming next.

Included in Free
AWSGoogle Cloud
What you are seeing
  1. 01Reading your AWS account
  2. 02Every resource becomes a box
  3. 03Lines only where a setting proves them
  4. 04What is open to the internet
  5. 05The proof behind a line
  6. 06Cost on every box
  7. 07Honest about gaps

Example data. From an AWS account.

How it works

From read-only scan to map

01

Connect your clouds

Connect AWS or Google Cloud through keyless federation. Azure and DigitalOcean Cloud Map support is coming next.

ZaysaReadOnly
federated · no stored keysConnected read-only

Example data.

02

Zaysa reads, read-only

See every service and region read, including denied and unavailable reads.

eu-west-2
EC2✓
ELB✓
RDS✓
ElastiCache✓
S3✓
Lambda✓
VPC endpoints · denied

Example data.

03

Search and explore

Find a resource by name, id, IP or tag, then inspect its settings and proven connections.

Search by name, id, IP or tag
web[0]10.0.3.24

Example data.

Proven connections

Two kinds of lines, never guessed

Configured: A setting points here. Allowed: Network rules allow this. It does not prove that traffic actually flows.

Allowed appears only when network rules permit a path. It shows the port. If only some placements are reachable, the map says “Only some placements are reachable.” You can switch each line kind on and off.

Example map · line kindsshop-prod
Internet
eu-west-2 · region
VPC · 10.0.0.0/16
public subnets ×2
shop-alb
Load balancer
$22.27/mo
internet-facing
private subnets ×2
web ×3
Compute stack
$210.24/mo
vol-0a1
orders-db
PostgreSQL
$187.61/mo
sessions
Cache
$150.38/mo
Regional services
assets
S3 bucket
$12.40/mo
thumbs
Lambda function
Not priced.

sg-db ingress 5432 from sg-web

network ACL rule 100 allow 5432

route local 10.0.0.0/16

Example data.

Exposure

Open to the internet, with the ports

See which resources are open to the internet and the ports involved. Private resources stay distinct from internet exposure.

Internet
eu-west-2 · region
VPC · 10.0.0.0/16
public subnets ×2
shop-alb
Load balancer
$22.27/mo
internet-facing
private subnets ×2
web ×3
Compute stack
$210.24/mo
vol-0a1
orders-db
PostgreSQL
$187.61/mo
sessions
Cache
$150.38/mo
Regional services
assets
S3 bucket
$12.40/mo
thumbs
Lambda function
Not priced.

shop-alb · 443 · from 0.0.0.0/0

web · not reachable from the internet

orders-db · not reachable from the internet

sessions · not reachable from the internet

Example data.

Evidence

Every line has its proof

Click a box to see where it lives, its cost, proven connections and settings. Click a line for the exact settings and values that prove it. Search by name, id, IP or tag.

web →orders-db

Allowed · port 5432

Network rules allow this. It does not prove that traffic actually flows.

sg-web egress all → sg-db

sg-db ingress 5432 from sg-web

network ACL rule 100 allow 5432

route local 10.0.0.0/16

Example data.

Permissions

Read-only by design

Cloud Map reads your connected accounts through provider-specific read-only paths. Choose a cloud to see the connection and request limits.

A keyless (federated) connection is required because stored keys cannot be restricted to read-only.

ReadOnlyAccess✓

Explicit deny

× log events× queue messages× stream records× secret values× function code× container images× templates

tag values that look like secrets → [redacted]

The session has an explicit deny on reading data and secrets: log events, queue messages, stream records, secret values, function code, container images and templates. Only display-safe metadata is kept; tag values that look like secrets are redacted.

Example data.

Coverage

Honest about what it could not read

Every service and region read has a count and a status: read, denied, error, timeout or not enabled. Unreadable is not empty. Anything that could not be proven is listed with a reason, never drawn as a line or shown as clean.

What Zaysa read · eu-west-2
EC2✓ 3
ELB✓ 1
RDS✓ 1
ElastiCache✓ 1
S3✓ 1
Lambda✓ 1
Redshiftnot enabled · 0
VPC endpointsdenied · 0

Not proven

thumbs → outbound: VPC endpoint policy could not be read (denied)

Example data.

INCLUDED IN FREE

See your cloud on every plan

Questions

Frequently asked questions

AWS and Google Cloud. Azure and DigitalOcean are coming next.

More in Resources

See what you run, and what it costs.

Free plan, no card needed.