Architecture map, live
Drawn from the account today, not a diagram from two years ago.
Run it hosted, or on your machine · v3.3.1
An AWS operations console. Sign up in the browser at app.cloudeye.dev, or download it and run it on your own machine.
No install for the hosted app. The desktop build is signed and notarized.
The read-only guarantee
Every AWS call runs through one function with an allowlist of read verbs. Try it.
awsCall()
describegetlistlookupfilter
Click a command, or type your own. The mutating verbs are not in the program.
On the hosted app you launch a CloudFormation stack that creates a read-only IAM role. CloudEye assumes it with an external id, and AWS caps every session read-only, so it cannot write even if the role let it. On your machine it uses the profiles already in ~/.aws.
Security posture
One sweep: GuardDuty, Security Hub, CloudTrail forensics, IAM hygiene, open security groups, S3, ECR and your logs. Scored 0 to 100, graded A to F.
Incident timeline
Everything that happened to a service, drawn under its metrics on one axis. Every lane comes from the account itself.
The rest of the console
Drawn from the account today, not a diagram from two years ago.
Bedrock, Anthropic, OpenAI, Gemini or DeepSeek. Your key, grounded in live data.
{
"level": "error",
"msg": "ECONNRESET",
"requestId": "a3f81c2e",
"upstream": "push.provider",
"durationMs": 30014
}Level chips, JSON that expands on click, one search across every log group.
The commit running right now, next to the head of your default branch.
One workspace per account, so metrics, logs, maps, runbooks and findings never cross.
Hosted assumes a read-only role you create; on your machine it uses your own profiles. No long-lived AWS keys, ever.
How it works
Sign up at app.cloudeye.dev, or download the app and run it on your machine.
One CloudFormation click creates a read-only role, or point it at an ~/.aws profile.
Clusters, load balancers, logs, alarms and security, discovered and drawn for you.
Get started
Sign up in the browser and connect an account. Ready in a couple of minutes.
Open app.cloudeye.devRuns on 127.0.0.1 and reads through your own AWS profiles.