Choose one deployment path.
Start with a repository whose AWS deployment you understand. Identify the target account, regions, service, and dependencies that matter to that deployment.
You need permission to install the GitHub App for the repository. You also need an AWS administrator who can create the role shown during setup.
For an Amazon Elastic Container Service (ECS) deployment, identify the service and its task definition. Include the database or load balancer it depends on when those resources fall within the supported integration scope.
Connect the repository to its environment.
- Sign in with GitHub and install the Proofline App for the repository you choose.
- Set up the target environment and link the repository to it.
- Configure the AWS connection for the account and regions that contain the deployment.
The environment link defines where the code runs and which evidence a review can use. A repository can link to more than one environment. Without an environment link, an environment review cannot run.
Install the generated read-only role.
Proofline provides the role configuration during setup. Use that configuration because its trusted principal and external ID belong to your connection.
The trust policy names the Proofline principal allowed to assume the role. It requires the connection's external ID. Proofline then obtains temporary role credentials when it reads AWS evidence.
Inspect both the trust policy and the permission policy before installation. Complete the access verification in setup. Read the security and data access page for how the hosted service processes the resulting evidence.
Check the evidence your deployment needs.
The integration reads supported AWS records. These examples describe the scope of a typical ECS deployment; the integration catalog lists the other supported services.
| Service | Records Proofline reads |
|---|---|
| Amazon ECS | Services, tasks, and task definitions. |
| Amazon RDS | Database clusters and instances from the AWS control plane. The connector does not query database tables. |
| Amazon ECR | Container image inventory and immutable image digests. |
| Elastic Load Balancing | Target groups, reported target health, listeners, and routing rules. |
| VPC Reachability Analyzer | Existing network path analyses and their reported outcomes. This read-only integration does not start an analysis. |
A database instance record does not supply every database setting or the application's connection behavior. A finding needs evidence for each part of its failure mechanism.
Inspect the first review.
Open a pull request for a change that affects the connected deployment. Proofline reviews the exact commit against recorded evidence from its target environment.
For each supported finding, inspect the trigger, failure mechanism, source evidence, and suggested fix. Check that the environment and resources match the deployment you intend to change.
If the assessment is incomplete, inspect the reported gap. Check the environment link, account, regions, and granted permissions before rerunning. A result with no supported findings does not establish that the deployment will succeed.
How it works explains what each review result means. The documentation covers the API and review contracts.
Connect your first repository.
Keep setup focused on one environment. Add other deployment paths when you need reviews for them.
Get Started with GitHub