Skip to content

Connect your cloud accounts

View Markdown

A cloud account gives Nodus read-only access to your AWS account or GCP projects. Nodus lists your instances, their GPUs and your monthly spend, and you can enroll an instance into a pool. Nodus never creates, changes or deletes anything in your cloud account. Connecting a cloud account is free.

AWS access is a role in your account that only Nodus can assume, and only with an external id unique to your cloud account.

  1. In the console, open BYOCompute › Spend › Manage cloud accounts and choose Connect AWS. Enter your 12-digit account ID and choose Continue to AWS. Nodus names the connection and prepares the role for you. Or create it from the CLI:

    Terminal window
    nodus create cloudaccount aws-main --provider aws --account-id 123456789012
  2. In the AWS tab, review the prefilled CloudFormation template, acknowledge the IAM permissions and choose Create stack. If the tab did not open, choose Open AWS approval in Nodus. You can also read the template with nodus get cloudaccount/aws-main --subresource onboarding. The stack creates a role whose policy allows only these calls:

    Call Used for
    ec2:DescribeRegions, ec2:DescribeInstances, ec2:DescribeInstanceTypes Instances and their GPUs
    ce:GetCostAndUsage Daily spend
  3. Return to Nodus after the stack finishes. Nodus saves the role ARN, checks access automatically and opens your account when it has read your instances. There is nothing to copy. A failed check shows the reason while AWS finishes applying the permissions. Checks pause after ten minutes; Check again resumes the saved connection. Retrying setup reuses the existing account and its trust identity.

GCP access is an OAuth grant limited to read-only scopes: compute.readonly, bigquery.readonly (for a billing export) and cloud-platform.read-only.

  1. Choose Connect GCP, then Continue with Google. No account name, project ID or service account key is required. If you already know the IDs, you can enter them under Advanced instead.
  2. Approve read-only access on Google’s page. Nodus lists the projects you can access. Choose the projects to connect, then choose Connect projects. Only those projects are imported. The person who signs in must complete this selection within 15 minutes. If it expires, sign in again to resume the saved connection. Nodus refuses grants with broader scopes and encrypts the stored authorization.
  3. Inventory is imported independently of billing. For spend reports, enable a Cloud Billing export in the first configured project’s nodus_billing BigQuery dataset. The consenting Google user needs BigQuery Job User on that project and BigQuery Data Viewer on the export. Nodus detects the export table; connecting does not create an export or backfill billing history that Google has not supplied.

Azure is coming soon.

Terminal window
nodus get cloudaccounts
nodus cloud inventory aws-main

Nodus syncs inventory hourly and spend daily. Open an account to see its observed month-to-date charges, service breakdown and daily amounts. The first spend sync reads the previous 35 days plus today’s partial day, so connecting in the middle of a month includes the earlier charges. Currencies stay separate; Nodus does not convert them. Missing days remain unknown. The date of the last successful observation stays visible when a refresh fails.

AWS amounts use Cost Explorer’s unblended cost. GCP amounts use cost plus credits from the billing export, filtered to the connected projects. Charges outside those projects, including unassigned charges, are excluded. Neither is a final invoice. You continue paying your cloud directly; these amounts are separate from your Nodus balance.

The next-30-day estimate extends the recent daily average across at least seven consecutive usable billing days. Missing days and negative billing adjustments prevent a projection. AWS non-estimated observations are preferred; provisional AWS and GCP projections exclude today and yesterday to allow for reporting lag. Each projection shows its source, history length and last included date. It assumes the recent spending pattern continues.

The compute-service subtotal includes CPU and related service charges. It is not a GPU-only bill or a measured cost for an individual workload. A separate compute projection appears only when the source supports it. These cloud-bill projections are distinct from a pool’s paid Predict capacity forecasts.

Choose Compare a workload with Nodus, select matching capacity, and enter your current cost for the same workload after discounts. Enter its expected runtime on Nodus and any additional transfer, storage or ongoing commitment costs. Nodus requests a Job estimate that includes startup and shutdown; it does not start compute. The difference can be a saving or an additional cost. Changing inputs or an expired quote requires a fresh estimate.

This comparison does not assume that your entire cloud bill can move to Nodus. Check that the hardware, runtime and work performed are comparable before making a migration decision.

The Inventory section lists each instance and whether it is enrolled. Choose Enroll instance, select a private pool in your current project, and create an install command. Run it as root on that instance. The command contains a single-use token valid for 24 hours and associates the resulting node with the observed cloud account and instance. See the host prerequisites before installing. The installer checks the container runtime and GPU requirements before using the token.

Connecting a cloud account grants observation only. Installing the agent grants execution on that host for your organization. Neither action offers capacity to other Nodus customers.

Disconnecting stops observation at once and deletes the credential Nodus stored:

Terminal window
nodus delete cloudaccount/aws-main

Then revoke it on your side too:

  • AWS: delete the CloudFormation stack, which deletes the role.
  • GCP: remove Nodus from your Google account’s third-party access.

If you revoke access on your side first, the next sync marks the account Synced=False with GrantRevoked, and the account’s members get one email about it.