Architect

AIVory Architect on AWS Marketplace

You can buy AIVory Architect through AWS Marketplace. The charge appears on your AWS bill. The product is the same web app as at app.aivory.net.

  • Subscribe on AWS Marketplace: $228 per user per year
  • 30 day free trial, one per AWS account
  • Register once and link your organization to the AWS agreement
  • Connect your AWS account with a Launch stack button
  • One support path: [email protected]

Subscribe

  1. Open the AIVory Architect listing on AWS Marketplace
  2. Choose View purchase options
  3. Pick the number of users
  4. Choose Try for free to start the 30 day trial, or Subscribe
  5. Choose Set up your account. AWS sends you to AIVory
Note The free trial runs once for each AWS account. The contract term is 12 months.

AWS opens the page app.aivory.net/marketplace/aws/register.

  1. Sign in, or create an AIVory account
  2. Choose an existing organization, or create a new one
  3. Confirm the link. The organization now holds the AWS agreement

The link shows under Billing > Marketplace. One AWS agreement links to one organization.

Assign seats

Each user who works in the organization takes a seat. The seats equal the users in your contract.

  1. Open Billing > Marketplace > Seats
  2. Invite a user by email, or choose a member
  3. Assign a seat

When all seats are taken, the app asks you to free a seat or to add users in AWS Marketplace.

Connect your AWS account

To deploy into your AWS account, Architect needs a role in that account. A CloudFormation stack creates the role.

  1. Open a design and select the Vault tab
  2. Under Connect a cloud account, choose Launch stack in AWS console
  3. AWS opens the CloudFormation console with the template filled in. The parameters ExternalId and TrustedAccountId are set for you
  4. Check the box that allows IAM resources, then choose Create stack
  5. When the stack is complete, copy RoleArn from the Outputs tab
  6. Paste it into the Role ARN field in the Vault tab and choose Verify. The account shows as connected

The role is named AIVoryArchitectDeployRole and sits under the path /aivory/. Only the AIVory service account can assume it, and only with your ExternalId. The role can do only what its permission policy lists. You can delete the stack at any time. Architect then loses access at once.

IAM permissions

The permissions come from the CloudFormation template. You can read the template before you launch it.

Service Actions
EC2 RunInstances, TerminateInstances, StartInstances, StopInstances, ModifyInstanceAttribute, ModifyInstanceMetadataOptions, MonitorInstances, UnmonitorInstances, CreateTags, DeleteTags, CreateSecurityGroup, DeleteSecurityGroup, AuthorizeSecurityGroupIngress, AuthorizeSecurityGroupEgress, RevokeSecurityGroupIngress, RevokeSecurityGroupEgress, ModifySecurityGroupRules, UpdateSecurityGroupRuleDescriptionsIngress, UpdateSecurityGroupRuleDescriptionsEgress, and read-only Describe* calls for instances, images, volumes, network interfaces, security groups, subnets, VPCs, zones, and tags
RDS CreateDBInstance, DeleteDBInstance, ModifyDBInstance, RebootDBInstance, AddTagsToResource, RemoveTagsFromResource, ListTagsForResource, and read-only Describe* calls for instances, subnet groups, parameter groups, engine versions, and instance options
Elastic Load Balancing CreateLoadBalancer, DeleteLoadBalancer, ModifyLoadBalancerAttributes, SetSecurityGroups, SetSubnets, SetIpAddressType, AddTags, RemoveTags, and read-only Describe* calls for load balancers, attributes, listeners, and tags
S3 CreateBucket, DeleteBucket, PutBucketTagging, ListBucket, ListAllMyBuckets, and read-only GetBucket* and Get*Configuration calls that Terraform needs to read a bucket
IAM CreateServiceLinkedRole for RDS and Elastic Load Balancing only; PassRole only for roles under /aivory/ in your account

Create calls use the resource *, because AWS cannot scope them to a resource that does not exist yet.

The trust policy allows one principal: the AIVory account TrustedAccountId. The condition sts:ExternalId must equal your ExternalId.

Change or cancel

  • Add or remove users: open the agreement in AWS Marketplace and choose Modify. AIVory receives the change and updates your seats
  • Renewal: the contract renews every 12 months unless you turn off auto renewal in AWS Marketplace
  • Cancel the trial: end the agreement in AWS Marketplace before day 30
  • After the agreement ends: the seats end. Your designs stay in the organization
  • Disconnect the AWS account: delete the CloudFormation stack

Refunds and support

Annual contracts are refundable within 15 days of purchase. Write to [email protected] with your AWS account ID.

For all questions write to [email protected] or open aivory.net/support. See the Terms and the Privacy policy.