Skip to content

Run discovery

Discovery inventories a connected AWS account through the read-only discovery role and writes a snapshot the Assets section shows. It runs on demand, with no schedule: you decide when to take a fresh look. StackTakt also refreshes the inventory automatically after a successful apply or destroy, so deployed resources appear without a manual run.

One snapshot covers, in order: IAM roles and users, VPCs, subnets, security groups, S3 buckets, Transfer Family servers, RDS instances, and DynamoDB tables. StackTakt stores a lean summary per asset (name, region, identifier, a few key facts), not policy documents, object contents, or secrets.

  1. Open Assets and select Run discovery (the connect flow also offers it once a connection is healthy).
  2. The run is synchronous: the button carries the running state and the result appears when it finishes.
  3. Completion writes a discovery.completed audit event with per-type counts.

Discovery needs a Healthy connection. If the tenant has none, the page says so and links to the connect flow.

A run that fails any service call writes no asset rows at all. The run records Failed with the exact call that failed and its error, and the prior completed snapshot remains what the inventory shows. You never see a half-updated inventory.

Asset Inventory lists the latest snapshot with type filters and a per-asset detail panel (region, AWS ID, summary facts, and the run it came from). The Map view (Knowledge Map) draws the same data as a graph: tenants, AWS accounts, assets, deployments, controls, and evidence, with edges like demonstrates and evidenced by. Select a node to see its facts and jump to the matching Inventory, Deployment, Compliance, or Evidence page.

Assets that carry controls (buckets, servers, databases, security groups, IAM users) are promoted to durable tracked resources for compliance evaluation. An asset missing from a later completed run is marked removed and keeps its history.