AIVory Architect on AWS Marketplace
You can buy AIVory Architect through AWS Marketplace. The charge appears on your AWS bill. The product is the same web app as at app.aivory.net.
- Subscribe on AWS Marketplace: $228 per user per year
- 30 day free trial, one per AWS account
- Register once and link your organization to the AWS agreement
- Connect your AWS account with a Launch stack button
- One support path: [email protected]
Subscribe
- Open the AIVory Architect listing on AWS Marketplace
- Choose View purchase options
- Pick the number of users
- Choose Try for free to start the 30 day trial, or Subscribe
- Choose Set up your account. AWS sends you to AIVory
Register and link your organization
AWS opens the page app.aivory.net/marketplace/aws/register.
- Sign in, or create an AIVory account
- Choose an existing organization, or create a new one
- Confirm the link. The organization now holds the AWS agreement
The link shows under Billing > Marketplace. One AWS agreement links to one organization.
Assign seats
Each user who works in the organization takes a seat. The seats equal the users in your contract.
- Open Billing > Marketplace > Seats
- Invite a user by email, or choose a member
- Assign a seat
When all seats are taken, the app asks you to free a seat or to add users in AWS Marketplace.
Connect your AWS account
To deploy into your AWS account, Architect needs a role in that account. A CloudFormation stack creates the role.
- Open a design and select the Vault tab
- Under Connect a cloud account, choose Launch stack in AWS console
- AWS opens the CloudFormation console with the template filled in. The parameters
ExternalIdandTrustedAccountIdare set for you - Check the box that allows IAM resources, then choose Create stack
- When the stack is complete, copy
RoleArnfrom the Outputs tab - Paste it into the Role ARN field in the Vault tab and choose Verify. The account shows as connected
The role is named AIVoryArchitectDeployRole and sits under the path /aivory/. Only the AIVory service account can assume it, and only with your ExternalId. The role can do only what its permission policy lists. You can delete the stack at any time. Architect then loses access at once.
IAM permissions
The permissions come from the CloudFormation template. You can read the template before you launch it.
| Service | Actions |
|---|---|
| EC2 | RunInstances, TerminateInstances, StartInstances, StopInstances, ModifyInstanceAttribute, ModifyInstanceMetadataOptions, MonitorInstances, UnmonitorInstances, CreateTags, DeleteTags, CreateSecurityGroup, DeleteSecurityGroup, AuthorizeSecurityGroupIngress, AuthorizeSecurityGroupEgress, RevokeSecurityGroupIngress, RevokeSecurityGroupEgress, ModifySecurityGroupRules, UpdateSecurityGroupRuleDescriptionsIngress, UpdateSecurityGroupRuleDescriptionsEgress, and read-only Describe* calls for instances, images, volumes, network interfaces, security groups, subnets, VPCs, zones, and tags |
| RDS | CreateDBInstance, DeleteDBInstance, ModifyDBInstance, RebootDBInstance, AddTagsToResource, RemoveTagsFromResource, ListTagsForResource, and read-only Describe* calls for instances, subnet groups, parameter groups, engine versions, and instance options |
| Elastic Load Balancing | CreateLoadBalancer, DeleteLoadBalancer, ModifyLoadBalancerAttributes, SetSecurityGroups, SetSubnets, SetIpAddressType, AddTags, RemoveTags, and read-only Describe* calls for load balancers, attributes, listeners, and tags |
| S3 | CreateBucket, DeleteBucket, PutBucketTagging, ListBucket, ListAllMyBuckets, and read-only GetBucket* and Get*Configuration calls that Terraform needs to read a bucket |
| IAM | CreateServiceLinkedRole for RDS and Elastic Load Balancing only; PassRole only for roles under /aivory/ in your account |
Create calls use the resource *, because AWS cannot scope them to a resource that does not exist yet.
The trust policy allows one principal: the AIVory account TrustedAccountId. The condition sts:ExternalId must equal your ExternalId.
Change or cancel
- Add or remove users: open the agreement in AWS Marketplace and choose Modify. AIVory receives the change and updates your seats
- Renewal: the contract renews every 12 months unless you turn off auto renewal in AWS Marketplace
- Cancel the trial: end the agreement in AWS Marketplace before day 30
- After the agreement ends: the seats end. Your designs stay in the organization
- Disconnect the AWS account: delete the CloudFormation stack
Refunds and support
Annual contracts are refundable within 15 days of purchase. Write to [email protected] with your AWS account ID.
For all questions write to [email protected] or open aivory.net/support. See the Terms and the Privacy policy.