Connect read-only
Add an AWS account through a cross-account IAM role (read-only). GCP and OCI use the same pattern. We never gain write access to your accounts.
read-only IAM · STS:AssumeRole
Every VM, disk, bucket, function, queue, cluster and managed service across AWS, GCP, Azure, Oracle Cloud and Kubernetes — normalised, taggable and joined to the cost line that paid for it.
By the numbers
AWS · GCP · Azure · OCI
0
clouds with live adapters
resources · metrics · cost
0
adapter roles per cloud
100% provider APIs
0
agents installed in your runtime
type · region · tags · metrics · cost
0
shared Resource model across clouds
How it works
Add an AWS account through a cross-account IAM role (read-only). GCP and OCI use the same pattern. We never gain write access to your accounts.
read-only IAM · STS:AssumeRole
For each connected account/project/subscription/tenancy, the matching adapter walks the configured regions and calls the cloud's resource API (AWS EC2, GCP Compute, Azure Resource Manager, OCI Resource Manager).
region-by-region crawl
Resources are enriched with usage metrics (CloudWatch · Cloud Monitoring · Azure Monitor · OCI Monitoring) and monthly cost (Cost Explorer · Cloud Billing/BigQuery · Azure Cost Management · OCI Usage API). Query via /api/v1/resources.
metrics + cost · per cloud
What's inside
An EC2 instance, a GCE VM and an Azure VM are all 'compute' — and we model them that way. Filter, group and report without learning each provider's billing taxonomy.
We join the line items in the cloud bill to the actual ARN / resourceId — so you can ask 'how much did THIS pod cost last week?' and get an answer in seconds.
Each resource carries observed status: idle, orphaned, drifted (vs. IaC), about-to-renew, missing required tags. The signals also drive the recommendation engine.
Capabilities
Before vs after Lumicost
Without Lumicost
With Lumicost
Where teams use it
Connect the acquired company's accounts and get a full inventory with owner attribution in under an hour.
Find every resource missing a 'team' tag, group by service, fix in bulk via a CSV round-trip.
Filter to all pods with utilisation < 30% across all clusters, sort by cost, ship a single PR.
From the field
“If we have to install a daemon in your runtime, we've already lost. The Resource model is built only on what the cloud provider already exposes.”
Plays nice with your stack
FAQ
Default refresh is hourly. Critical attributes (state, tags) can be set to 5-minute polling on Pro/Enterprise.
Yes — CSV, JSON Lines and a read-only API. Useful for CMDB sync.
Keep exploring
Connect read-only credentials. First insights in 24 hours. No credit card.
90 seconds · read-only credentials · no credit card