---
title: Hyperglance Guide for AWS
description: This guide brings together various articles and information for you to deploy Hyperglance into your AWS cloud.
---

[Skip to content](https://support.hyperglance.com/knowledge/aws-guide#main-content)

English

Show submenu for translations

[More support](https://support.hyperglance.com/knowledge/kb-tickets/new?hsLang=en)

![](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=100&height=75&name=hyperglance.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [More support](https://support.hyperglance.com/knowledge/kb-tickets/new)
- [Contact Us](https://www.hyperglance.com/contact/)

[Contact Us](https://www.hyperglance.com/contact/)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Hyperglance Support](https://support.hyperglance.com/knowledge?hsLang=en)
2. [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en)
3. [AWS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#aws)

# Hyperglance Guide for AWS

## This guide brings together various articles and information for you to deploy Hyperglance into your AWS cloud.

**Why Choose Hyperglance?**

✔️ Automatic diagrams & inventory  
✔️ Cost optimization & alerting  
✔️ Security & compliance monitoring  
✔️ Automatic policy enforcement

Hyperglance can be deployed in only **10 minutes** from the AWS Marketplace using a CloudFormation template.

### What you need to get started:

- AWS Account, with a VPC & subnet, to launch the Hyperglance instance into
- Any additional AWS Accounts you want Hyperglance to monitor
- Some knowledge of IAM to [set up account access](https://support.hyperglance.com/knowledge/aws-guide#iam) and CloudFormation (don't worry we'll walk you through it in our step-by-step guides, see below).

### Get Started Guides

[> Get Started Step by Step Guide](https://support.hyperglance.com/knowledge/getting-started-in-the-aws-marketplace?hsLang=en)

[> Setup Additional Accounts Access](https://support.hyperglance.com/knowledge/adding-new-aws-accounts-to-hyperglance?hsLang=en)

[> More about deployment options & deployment architecture diagrams](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en)

[> Product Architecture Diagram](https://support.hyperglance.com/knowledge/deployment-architecture-overview?hsLang=en)

### Security

**Tip: Use a non-root IAM User.**

It is best security practice **not** to use your AWS account's root user to manage resources and deployments. You should use a non-root IAM User at all times.

#### **IAM Policies & Roles**

Hyperglance needs an IAM role/policy to access the AWS APIs in order to gather inventory, create diagrams, and evaluate cost-saving, compliance, and security rules.

Find our latest up-to-date recommended policy permissions here:

- [For Commercial Accounts ](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements?hsLang=en)
- [For GovCloud Accounts](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements-for-govcloud?hsLang=en)

By the ***principle of least privilege*** we provide multiple policy options: Read-only vs read-write as well as fine-grained detailed permissions.

A cross-account Role (with the above policy attached) is required in each account that you wish to connect to Hyperglance. Hyperglance will connect to your accounts using STS AssumeRole.

Read More: [How To Add AWS Accounts To Hyperglance](https://support.hyperglance.com/knowledge/adding-new-aws-accounts-to-hyperglance?hsLang=en)

#### Public Resources?

Hyperglance does **NOT** deploy any public resources (such as public S3 buckets) by default.

The CloudFormation template does provide the option to allocate a Public IP Address (see [deployment options](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en)).

#### Stored Secrets

As shown in our [Product Architecture Diagram](https://support.hyperglance.com/knowledge/deployment-architecture-overview?hsLang=en) Hyperglance comprises a PostgreSQL database that is stored on a 'data' EBS Volume (that **YOU** control).

On this volume Hyperglance will store:

- All IAM Roles [you add](https://support.hyperglance.com/knowledge/adding-new-aws-accounts-to-hyperglance?hsLang=en) to connect into accounts using STS AssumeRole.
- Any Access/Secret keys [you add](https://support.hyperglance.com/knowledge/add-aws-account-credentials-to-hyperglance?hsLang=en) to connect into accounts (encrypted) 
    - **Note:** This does **NOT** apply to AWS Marketplace deployments where Hyperglance only permits assume

- [SAML configuration](https://support.hyperglance.com/knowledge/saml-support-in-hyperglance?hsLang=en)
- [SMTP configuration](https://support.hyperglance.com/knowledge/how-to-add-smtp-settings?hsLang=en)
- Any [rules / advanced-searches](https://support.hyperglance.com/knowledge/rules?hsLang=en) that you save (including their search queries and alert configuration).

#### EBS Volume Encryption

You control the EBS Volumes that Hyperglance uses and can activate [Encryption-At-Rest.](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html)

#### SSH

The Hyperglance instance has root disabled by default. The default SSH user is **ec2-user**.

#### Network Configuration

The Hyperglance CloudFormation stack will create the following network components:

- EC2 Instance 
    - With a single default ENI
    - Optionally with a Public IP (according to the AssignPublicIP parameter of the CloudFormation stack).

- EC2 Security Group 
    - Allowing Ingress on ports 443 and 22 from the CIDR ranges provided as parameters to the CloudFormation stack.

The stack asks for a VPC ID and a Subnet ID (which must belong to that VPC) so you must create the following components yourself before deploying the stack:

- A VPC
- A Subnet (with an optional Network ACL)
- A RouteTable
- Optional:  Network ACL to control ingress/egress from Subnet (see [deployment option 2](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en#two))
- Optional: Additional Subnet and NAT Gateway (see [deployment option 3](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en#three))
- Access to the AWS APIs via either: 
    - An Internet Gateway, or
    - Virtual Private Cloud Endpoint (VPCEs) (see [deployment option 4](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en#four))

[> See our deployment options.](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en)

### Costs & Pricing Model

There are a few different Hyperglance tiers in the AWS Marketplace. You choose the tier that corresponds best with the number of cloud resources that Hyperglance will monitor.

The cost per hour depends on the number of resources you need. For example, if you run a 500 resource Hyperglance instance in AWS for 20 hours in a month the cost would be 1.23 \* 20 = $24.60 (plus any cloud vendor charges).

Hyperglance is comprised only of EC2 services (EC2 Instance & EBS) so you will only incur platform changes on those resources plus any data-transfer costs in/out of regions.

[> See Current Pricing](https://www.hyperglance.com/pricing/)

[> What Does Hyperglance Count as a Resource?](https://support.hyperglance.com/knowledge/what-does-hyperglance-count-as-a-resource?hsLang=en)

### Instance, Volume & RAM Sizing

Our CloudFormation templates have defaults set to a *typically* suitable EC2 instance size and EBS Volume size (10GB).

If you ingest large amounts of Cost data or if you find performance is poor then you may need to increase the amount of RAM allocated to the internal Java process.

[> Recommended Instance/VM Sizes](https://support.hyperglance.com/knowledge/sizing-guide?hsLang=en)

[> How to increase Java memory allocation](https://support.hyperglance.com/knowledge/memory-usage?hsLang=en)

### **Backup**

The Hyperglance EBS volumes can be snapshotted and backed up to preserve all configuration and custom created rules (or other user content).

[> How to create backups using the AWS Console](https://docs.aws.amazon.com/prescriptive-guidance/latest/backup-recovery/new-ebs-volume-backups.html#manual-snapshots)

[> Automate backups using AWS Backup ](https://docs.aws.amazon.com/prescriptive-guidance/latest/backup-recovery/new-ebs-volume-backups.html#aws-backup)

[> Automate backups using the AWS CLI or SDK](https://docs.aws.amazon.com/prescriptive-guidance/latest/backup-recovery/new-ebs-volume-backups.html#automating)

### Recovery

In the case of instance or AZ failure you will need to:

1) Relaunch the Hyperglance CloudFormation stack

2) [Create EBS volumes from your snapshot backups](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-creating-volume.html)

3) [Replace the stock EBS volume(s) with your restored volume(s)](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-restoring-volume.html)

**Recovery-Time-Objective:** Fastest possible recovery time is 10 minutes. So we recommend an RTO of **1 hour**.

**Recovery-Point-Objective:** A low-frequency backup is sufficient if configuration changes and custom rules are not infrequently made. So we suggest an RPO of **24 hours.**

### Routine Maintenance

You should regularly rotate your user [login password](https://support.hyperglance.com/knowledge/how-to-change-hyperglance-login-password?hsLang=en).

You should regularly check our [release notes](https://support.hyperglance.com/knowledge/hyperglance-release-notes?hsLang=en) for updates and [apply updates](https://support.hyperglance.com/knowledge/upgrading-hyperglance-to-a-newer-version?hsLang=en).

Tip: [Setup automatic updates with Cron](https://support.hyperglance.com/knowledge/upgrading-hyperglance-to-a-newer-version?hsLang=en#automatic-updates).

### Emergency Maintenance

If you need to restart Hyperglance for any reason simply stopping and starting the instance will suffice. This will restart all the Docker containers running in the instance.

Restarting the containers can also be achieved by running:

```
sudo docker-compose -f /etc/docker-compose.yml down && sudo docker-compose -f /etc/docker-compose.yml up -d
```

If you need to completely reset the entire setup then can also delete the CloudFormation stack and [redeploy](https://support.hyperglance.com/knowledge/getting-started-in-the-aws-marketplace?hsLang=en) it from the AWS Console.

### Service Health Check

To implement a health-check of the Hyperglance instance:

- Hyperglance is typically active & well if it responds with a login page on HTTPS port 443 at the root URL '/' with HTTP code 200.

To check for other issues:

- Check for any errors in the top-right corner of the Hyperglance UI (a little warning triangle icon/button).
- Check for any errors in the browser or server (see "Features or functionality are not behaving correctly" under **Troubleshooting** section below).

### Troubleshooting

To troubleshoot Hyperglance you must first work out what sort of an issue you are facing:

- Unable to access Hyperglance instance 
    - Check your **AWS Security Group** configuration - does it allow your IP to reach HTTPS/SSH?
- Log-in issue (can't get past login-screen) 
    - Check your password is correct (password defaults to the instance-id)  
      DO: Use the copy-to-clipboard button in the AWS Console next to the instance-id  
      DO NOT: Highlight the instance-id text and copy. (This will often add bad characters to the clipboard).

- Errors are displayed in Hyperglance UI 
    - For permissions issues: Check you are using the right [IAM permissions](https://support.hyperglance.com/knowledge/aws-iam-policy-requirements?hsLang=en).
    - For connectivity issues: Check that Hyperglance [has access to the AWS APIs](https://support.hyperglance.com/knowledge/hyperglance-running-in-highly-secure-aws-environments?hsLang=en).
    - For critical/unknown errors: Click the "Send to Hyperglance" button, enter your email and one of our team will review the errors and reach out to you.
- Hyperglance is slow or intermittently unresponsive 
    - You may need to [increase the amount of RAM allocated](https://support.hyperglance.com/knowledge/memory-usage?hsLang=en) to the Java process.
- Features or functionality are not behaving correctly 
    - In the browser press F12 and look at the Console tab to check for any red error messages from the UI.
    - Download the server logs [via the UI](https://support.hyperglance.com/knowledge/how-to-download-diagnostic-bundle-or-logs?hsLang=en) or find them on-disk at **/var/lib/data/logs **and look for any Java stacktrace exceptions. Or send these logs to Hyperglance support and we will review them for you.

### API Throttling

The various AWS APIs have different limits, when reached, cause throttling ([See here for an explanation and a table showing these limits).](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/throttling.html)

If you see these errors, Hyperglance enables you to set the time between collections to reduce the number of API calls.

To set the time between collection cycles, go to **Settings > Platforms** and click the **Refresh Rate** button:

![](https://support.hyperglance.com/hubfs/image-png-Dec-05-2022-06-02-52-3622-PM.png) and adjust the frequency as desired before pressing **Save Changes**:![](https://support.hyperglance.com/hubfs/image-png-Dec-05-2022-06-03-34-4571-PM.png)

### Support

Support is manned 9-5 GMT. If you require support please email support@hyperglance.com or [raise a ticket](https://support.hyperglance.com/knowledge/kb-tickets/new?hsLang=en) and a support engineer will be in touch to help you resolve any issues.

We aim to respond within 24 hours and usually within 1-2 hours.

- [Before You Start](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#main-content)
  
  
  
  
  
    - [Kubernetes](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#gcp)
    - [AWS](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/before-you-start?hsLang=en#azure)
- [Using Hyperglance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#main-content)
  
  
  
  
  
    - [Automations](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#automations)
    - [Inventory & Diagrams](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#inventory-diagrams)
    - [Rules](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#rules)
    - [Cost Management](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#cost-management)
    - [Dashboards](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#dashboards)
    - [Security & Compliance](https://support.hyperglance.com/knowledge/using-hyperglance?hsLang=en#security-compliance)
- [Setup & Configuration](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#main-content)
  
  
  
  
  
    - [Updating & Migrating](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#updating-migrating)
    - [General](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#general)
    - [RBAC & Users](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#rbac-users)
    - [STIGS & FIPS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#stigs-fips)
    - [AWS](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#aws)
    - [Azure](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#azure)
    - [Kubernetes](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#kubernetes)
    - [GCP](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#gcp)
    - [API](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#api)
    - [Legacy Docker-based deployments](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#legacy-docker-based-deployments)
    - [AI](https://support.hyperglance.com/knowledge/setup-configuration?hsLang=en#ai)

[![Chill listening crop-3](https://support.hyperglance.com/hs-fs/hubfs/hyperglance.png?width=134&height=24&name=hyperglance.png "Chill listening crop-3")](https://www.hyperglance.com/)

2880 Zanker Road, Suite 203, San Jose, CA 95134

<https://www.linkedin.com/company/hyperglance/>

Copyright © 2025 Hyperglance. All rights reserved.