Add a connection
Create credentials
Follow the guide to create least-privilege credentials — read-only wherever possible.
Connect
In CloudThinker, navigate to Connections, select the service, and enter the credentials. The connection shows a Connected status.
Cloud platforms
| Connection | What agents do | |
|---|---|---|
| AWS | Cost analysis, security auditing, and infrastructure management via IAM role or access keys | |
| Google Cloud | Resource management, cost optimization, and security monitoring via service account | |
| Azure | Multi-cloud operations, cost analysis, and compliance monitoring | |
| Firebase | Project and app inventory, SDK config lookup, and security-rule audits | |
| Cloudflare | DNS management, CDN optimization, and security configuration | |
| Vercel | Project inventory, deployment inspection, runtime log triage, and domain auditing |
Infrastructure & access
| Connection | What agents do | |
|---|---|---|
| Kubernetes | Workload analysis, resource optimization, and cluster operations on EKS, GKE, AKS, or self-managed clusters | |
| SSH | Shell commands on your own servers with key-based authentication and trusted host keys | |
| HashiCorp Vault | KV secret reads, dynamic credentials, and policy, token, and health audits | |
| Keycloak | Realm inspection, client audits, and user and role reviews |
Databases
| Connection | What agents do | |
|---|---|---|
| PostgreSQL | Query optimization, performance tuning, and analytics | |
| MySQL | Query analysis, performance monitoring, and slow-query triage | |
| MongoDB | Document query analysis, performance tuning, and operational insights | |
| Redis | Cache performance monitoring across self-hosted, Upstash, or Redis Cloud deployments | |
| Neon | Serverless Postgres project discovery, schema inspection, and query tuning via OAuth MCP | |
| Elasticsearch | Log analysis, index management, and search performance optimization |
Messaging & streaming
Observability & monitoring
| Connection | What agents do | |
|---|---|---|
| Grafana | Dashboard integration, metric analysis, and alerting | |
| Prometheus | Read-only PromQL queries, metric discovery, scrape-target health, and active-alert inspection | |
| Datadog | Log search, metric queries, infrastructure monitoring, and incident investigation | |
| New Relic | APM, NRQL queries, alerting, and incident investigation | |
| Dynatrace | DQL queries, problem investigation, and vulnerability review | |
| AppDynamics | Application health monitoring, health-rule violation triage, and error-event analysis | |
| Coralogix | Log search, metrics, traces, and incident triage | |
| SigNoz | Service latency investigation, log search, alert-rule audits, and trace drill-downs | |
| Zabbix | Infrastructure monitoring, alerting, and performance analysis | |
| Better Stack | Uptime monitoring, incident triage, on-call schedules, and log search via OAuth | |
| Rollbar | Error triage, top-error tracking, and deployment-correlated investigation | |
| Langfuse | LLM trace investigation, conversation debugging, and prompt auditing |
CI/CD & code quality
| Connection | What agents do | |
|---|---|---|
| Jenkins | Build pipeline monitoring, job analysis, and deployment tracking | |
| CircleCI | Pipeline status, build log triage, and approval-gated pipeline controls | |
| ArgoCD | GitOps operations and application management | |
| Ansible AWX | Job template launches, job monitoring, and inventory management | |
| SonarQube | Code quality analysis, security scanning, and technical debt tracking | |
| GitGuardian | Secrets detection, incident investigation, and honeytoken monitoring |
Incident & ticketing
| Connection | What agents do | |
|---|---|---|
| PagerDuty | On-call management, incident alerting, and escalation policy integration | |
| ServiceNow | Incident, change request, problem, and CMDB management | |
| Atlassian | Jira issue tracking and Confluence knowledge base | |
| Backlog | Issue tracking, milestone planning, wiki, and pull-request context |
Custom MCP
| Connection | What agents do | |
|---|---|---|
| Custom MCP | Any tool or API that exposes an MCP server, immediately available to all agents |
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
Related
Connect AWS
Set up the most common starting connection with an IAM role or access keys.
Custom MCP connections
Extend agents with any tool that speaks the Model Context Protocol.
Meet the agents
See what Alex, Oliver, Tony, Kai, and Anna do with your connections.
Automation & autonomy
Let agents act on connected services in Manual or Auto mode.