# Cloud Plans Reference

## Introduction

Cloud Plans is a SaaS (Software as a Service) focused on Governance, Cost Savings and Operativity. The main functionality of Cloud Plans (hereinafter CP) consist on a ON/OFF scheduling for groups of Virtual Servers among the three main Public Cloud providers in the workd (AWS, Azure and GCP). CS not only provides your Company Governance over resources, but also operativity, control, security and effective Cost Saving.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FmDnc7C9Jlu92mLQXbVvv%2FSin%20ti%CC%81tulo-7.png?alt=media&amp;token=763bb69e-2127-4c5b-b02c-a5459b3856c0" alt=""><figcaption></figcaption></figure>

The following documentation will show you the power of scheduling, the power of Governance and the gains CP will give to you and your company letting you work on the most important thing: your product and not your expensive and wasteful infrastructure.


# What is Cloud Plans

Cloud Plans is a SaaS wich you can use to schedule your Virtual Servers on Cloud, no matter if you have workloads distributed between Google Cloud, Azure or AWS, CP can go with your combination if you need.&#x20;

In this first release we can switch on/off virtual servers based in a schedule, but we go far away from the basics offered by the Providers. We able you to decide a combination of Timezone and Schedule (when you decide to start and for how long), but CP also provides you to set this schedule for a certain days of a week!, just by a few clicks (an absolute Game Changer).

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FjDtwB7FRHhd2BgL8BY3u%2FglobalFlow.gif?alt=media&amp;token=7992acc2-f207-494e-9571-3154d6c885a2" alt=""><figcaption></figcaption></figure>

Above we explained the main capabilities, but what about the SECURITY (yes, uppercase as it is critical for us and for you): It is simple, we use the most secure services in every Cloud to provide you the less Data Leak and minimize threats  , etc.&#x20;

* Information in transit: We use very secure 2048 RSA SSL Certificate, making it near to impossible to decrypt.
* Information in rest: We have Encrypted storage and databases, but also we encrypt every sensitive data we consider.
* We do not expose databases to public. And our services are perfectly secured to avoid any leak.
* Almost all our Service works with no passwords, just roles, so you can secure the actions based on what is expected and no more.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fu6dAbHpfLaA5GCB5erMS%2Fundraw_Security_re_a2rk.png?alt=media&amp;token=c259c2e2-2e25-46ce-abe4-20a29ee3ac86" alt=""><figcaption></figcaption></figure>

Last but not least, Cloud Plans was born for saving money in Cloud, as Compute resources are always free if the Virtual Servers are stop (<mark style="background-color:orange;">**Disclaimer: not the storage**</mark>). Every company, every project has unused resources all the time. No matter if it is because you have a Development Team working 10h away from your PO/PMO/Customers or if you work on Development OOO time, that means you always have certain time in the day and in the week when you don't use your resources and that's almost regular in the time, so why don't you plan it in a schedule? - Yes we know there are exceptions all the time (a project need for an urgent development, a PoC we have to show to our customers tomorrow\... and so). Thats why standard Cloud Schedules are not for you, as it is complex not only to program, but also to exception and far more if the Company asks for evidences of every exception.... It is complex when you programmatically generates a schedule on a Cloud and it is needed an exception, or even more, a bunch os exceptions... The govern of that mess is an enormous effort. But Cloud Plans helps you normalize the highly governed schedule and its interruptions, just with a few clicks.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Ft7d1ISwavCf0YeUp6slG%2Fundraw_Savings_re_eq4w.png?alt=media&amp;token=e8378cd9-a75a-40fe-a905-973b2de69aad" alt=""><figcaption></figcaption></figure>

This is a tool for Engineering teams, but also for Financial, Development and Project Management, because no deep Cloud/Infrastructure knowledge is needed to schedule resources or for forcelly start/stop resources when needed, this will save you teams time and resources for simple tasks.


# Starting with out tutorials

In the next videos, you’ll discover just how effortlessly you can create a Plan with a Resource. Fresh content will drop regularly, tailored to the needs and vibes of our growing community.

### Start and Login into Cloud Plans

{% embed url="<https://youtu.be/IBrSmyefd9g>" %}

Create your first Plan with all it needs

{% embed url="<https://youtu.be/ifypCQPgApM>" %}

Your experience starts here...


# User Management

To start using Cloud Plans there are not complex registration: just provide us your email, username, name, family name and password.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F9LwPH7m4gAc23yR0OOdH%2Fundraw_Secure_server_re_8wsq.png?alt=media&amp;token=caf660a6-2cc5-451b-97a1-4ae7694eafed" alt=""><figcaption><p>Clouds Scheduler if secure at Transit and Rest using the most recent methods</p></figcaption></figure>

{% hint style="success" %}

Your data is completely safe as is stored under the \<AWS global network security> , using the TLS 1.2-3 for the transport and DHE (Ephemeral Diffie-Hellman) / ECDHE (ECDHE (Elliptic Curve Ephemeral Diffie-Hellman). But also the data is encrypted at rest.
{% endhint %}

To Start using Clouds Scheduler just:

* Go to the Home page
* Click on \<console> in the upper right corner&#x20;
* You will be prompted to enter your user data. If you don't have a user, click on \<Sign Up>

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FJGaFlcugqxMLRTnm2Opt%2FGreenshot%202024-10-22%2006.30.44.png?alt=media&amp;token=2330a9a0-0167-466d-8957-d9154ffabb08" alt="" width="183"><figcaption><p>Sign up</p></figcaption></figure>

* Enter all the form required data and click on the \<Sign up> blue button:

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FPGFOXVsDuDCEmoOONOHt%2FGreenshot%202024-10-22%2006.32.21.png?alt=media&amp;token=73ec0323-f047-4232-b51d-d3a1acc98959" alt="" width="187"><figcaption></figcaption></figure>

* An email will be sent to your provided account, when you click on the confirmation link you can start using Cloud Plans.


# MFA

Cloud Plans can work with normal \<password authenticated> users, but we strongly recommend you to enable MFA in your Account as we recommend to require MFA in most of the Organization operations.&#x20;

MFA is used to authenticate if the identity of a user is genuine. It requires a user to present two or more pieces of evidence, or factors, for authentication. A key goal for MFA is to add additional authentication factors to increase security. The well-designed multi-factor authentication strategy strives to maintain a balance between added security and user convenience.

The primary objective of multi-factor authentication is to reduce the risk of account takeovers and provide additional security for users and their accounts. Since [over 80% of cyber breaches](https://enterprise.verizon.com/en-gb/resources/reports/2020-data-breach-investigations-report.pdf) happen due to weak or stolen passwords, MFA can provide added layers of security necessary to protect users and their data. If one of the factors such as a user’s password is stolen or breached, the other factors provide an additional layer of security and assurance of the user identity.&#x20;

Organizations use MFA for a variety of reasons. Three primary purposes of MFA implementation include:

Security: Enhancing the security and safety of business information and operation is the chief purpose of multi-factor authentication. The strength of a technological safety system depends on the number of layers or factors incorporated in the software. Systems using two or more authentication factors are considered safer than others.

Usability: Working with MFA provides an opportunity to eliminate the use of passwords. The average user has in excess of 40 mobile apps and managing to remember complex passwords for each account is a challenge for most users. Password managers do help however for most users, resetting their password is a common event that adds unnecessary and unwelcome friction to accessing online accounts.&#x20;

Compliance: MFA can be a chief requirement for complying with specific industry regulations. Many states or local rules already state that organizations should utilize multi-factor authentication under some circumstances. Organizations are required to comply with these regulations to avoid potential fines and minimize audit findings.

To start using MFA:

* Login into the console
* Click on \<User>

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FSHyuu3hKXzxX8DlNnpVA%2FGreenshot%202024-10-22%2006.49.31.png?alt=media&amp;token=b581a50c-dbe8-43e7-b3f4-a96bc0d5e93d" alt=""><figcaption></figcaption></figure>

* Just toggle the enable/disable MFA button

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FwAzbzHWslBvSP0sNwNcT%2FGreenshot%202024-10-22%2006.50.40.png?alt=media&amp;token=79728ccf-8d3f-48b5-a822-12f9582d96ce" alt=""><figcaption></figcaption></figure>

* If it waas dissabled, you will be prompted to:

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FxDrt69jLmjt5Rhzw3noh%2FGreenshot%202024-10-22%2006.53.41.png?alt=media&amp;token=5eea6ec8-757b-4933-8bc7-23a5607cea68" alt=""><figcaption></figcaption></figure>

* 3 simple steps:
  1. Scan a QR with your MFA favorite application (MS Authenticator, Google Authenticator, Authy...)
  2. As Soon As Possible introduce the current code your Application shows you into the text field for the current code
  3. Click on \<Set>&#x20;
* Next time you Access the Console you will be prompted to enter the MFA after the password challenge.


# Support

We are concerned about the quality of your experience and are committed to providing you with the best possible support. Our dedicated team is here to assist you with any questions, issues, or guidance you may need. Whether you’re seeking technical help, product information, or troubleshooting advice, we’re here to make sure your experience is as smooth and positive as possible.

Please explore our support resources or reach out directly for personalized assistance. Your satisfaction and success are our priorities.

### Create a Support Case

First it is important to consider who/what is the requester:&#x20;

* User focused:
  * Accessing problems
  * Lost Organizations
  * MFA enabling / disabling
* Organization focused
  * Billing
  * Resources
    * Not working well
    * Removed
  * Credentials
    * Guidance
    * Troubleshooting
  * Plans
    * Schedule not working properly&#x20;
    * Unable to add/remove/update resources
  * Users
    * Adding/removing/updating users
    * MFA enforceability

When the "who" and what are defined:

* Go to the Cloud Plans  console portal
  * If the request is for a Organization:
    * Connect to the Organization  first
* Click on the "Support" menu in the left vertical NavBar

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fl53dQD3G4rl9fRlzVYJJ%2FGreenshot%202024-11-03%2023.08.05.png?alt=media&amp;token=a58afcef-abd1-4eae-b364-d634af0d947f" alt=""><figcaption></figcaption></figure>

* Select your options in the form

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fz3ZRJmCmgcTS8M51OTDr%2FGreenshot%202024-11-03%2023.09.10.png?alt=media&amp;token=a2b3539a-ee8e-4238-bb4c-874871e65529" alt=""><figcaption></figcaption></figure>

* Once the case is open you will get it down the same page (if you want to get any Organization Support cases and if you have the correct role, first ensure you have the Organization selected in the "Organization" section)

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F8WZBegm6Os5sOl6tSpbs%2FGreenshot%202024-11-03%2023.14.42.png?alt=media&amp;token=5d1df027-70c3-465e-813e-75afc8f515a4" alt=""><figcaption></figcaption></figure>

* Just click on "View" to get the full conversation and manage it (answer, ask, close or re-open)

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fz3LPC5cwTnlf2mVt48Le%2FGreenshot%202024-11-03%2023.16.26.png?alt=media&amp;token=1605ce44-d102-4ef5-86d3-709cd6e8f179" alt=""><figcaption></figcaption></figure>


# Create

This is the first thing to do when working with Cloud Plans: Create an Organization.

It is a straight forward process consisting on the following steps:

* Go to the main page
* In the left vertical menu, click on "Organizations"
* Look for the plus <+> button placed in the up-left corner of the main table

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FTr7Q7ygEKvNzDow5u9ef%2FGreenshot%202024-10-21%2017.46.56.png?alt=media&amp;token=fdf36884-c78c-4ac1-8eb3-757290913c52" alt=""><figcaption></figcaption></figure>

* Once in the New Organization form, just enter the Organization Name in the test area and click on "Create". Then you should start having the new created Organization as follows:

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FT50TQpmaCkpn7UXiwhPC%2FGreenshot%202024-10-21%2017.50.55.png?alt=media&amp;token=778144b8-43b7-4b05-ace1-c320a7762e69" alt=""><figcaption></figcaption></figure>


# Select

{% hint style="info" %}
It is neccesary to be part of a Organization before. Go to [Add User](/organization/users/add) to learn how.
{% endhint %}

To connect to a Organization is simple:

* Go to the Organizations page using the vertical left menu
* Select the Organization clicking on the bolt icon placed on the left side of the name

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FbrH79pEdn4RYyDU9lhRw%2FGreenshot%202024-10-21%2017.56.20.png?alt=media&amp;token=94a652a0-10ae-4922-ac82-48fbd6079c0c" alt=""><figcaption></figcaption></figure>

* After connection you should see the Organization Name in the vertical menu and in the Top horizontal menu.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F1cWhpja1ZPVH8eJzFI2c%2FGreenshot%202024-10-21%2017.56.48.png?alt=media&amp;token=0a61b922-f41c-411a-a406-49ccb617061a" alt=""><figcaption></figcaption></figure>

In the same horizontal menu, but in the right side you have your role in the Organization and the last actions notifications (if succeeded or not and why if not)

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FjsAtcPUf5SgfJovSO2bi%2FGreenshot%202024-10-21%2017.59.07.png?alt=media&amp;token=04a4b20c-b998-4834-8fb0-6faf4893d998" alt=""><figcaption></figcaption></figure>


# Configure

There are not many posibilities of configuration for the Organization object: *<mark style="color:red;">**Name**</mark>*. Exactly, the name is the only attribute you can update from the Console/API. To change the Organization Name:

* Billing --> Configuration

After going to the above menú, the first squared section will show you the Name changing text area. You just need to update the value here and "Save".

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FNC0a430802iiu8Ieazds%2F2024-10-22%2012_16_57-Window.png?alt=media&amp;token=fd24aafd-dd4c-4167-8880-73f8de5c18ee" alt=""><figcaption></figcaption></figure>


# Subscription

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FDq0mFUu8JgDFzjNirVgR%2Fcsnow-Subscription.drawio.png?alt=media&amp;token=94a591b8-b18d-41ef-ab64-712ec1b4ebf4" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}

The Subscription is Quantity-based, also known as resource-based. Subscriptions allow consumers to subscribe to a plan and specify the number of units at the time of subscription.
{% endhint %}

Subscriptions are monthly billed and can be updated at any time. BUT when a Organization updates its subscription, it will be billed for the proration of the current used % of the month and then the billing will continue with the percentage of the rest of the month with the new resources. Lets see some examples:

Case 1:

* Org example1 starts the subscription on 1th April 2024 with 10 resources
* after 15 days they realized Cloud Plans is suitable for more servers and decided to upgrade the Subscription to 100

In this Case 1, Org example1  starts with a estimated billing of ($5,99 x 10) $59,9, and  in the 15th April it will be billed with $29,99. In the 30th April it will be billed with ((($4.19 x 100) / 30) x 15) $209,50. Now imagine your average instance is a t3.large / t3.medium ...

t3.medium ->&#x20;

* Normal monthly costs: $30,96
* With Cloud Plans:&#x20;
  * Cloud Plans costs in the Case 1:  $2,99 + $2,09 = 5,08 $
  * 86h instance costs: $3,59
  * Total Costs: $8,67
  * Savings: $30,96 - $8,67 = 22,29 $ -> Saves 71,99% over the NO Cloud Plans option &#x20;
* Now in the above example we have 10 instances first 15 days and then 100:
  * First 15 days:
    * NO Cloud Plans: (30,96/2) \* 10 = 154,8 &#x20;
    * With Cloud Plans:  (8,67/2) \* 10 = 43,35 --> You saves  $111,45 in 15 days&#x20;
  * Last 15 days:
    * NO Cloud Plans: (30,96/2) \* 100 = 1548
    * &#x20;With Cloud Plans:  (8,67/2) \* 100 = 433,5  -> You save $1114,5 in 15 days
  * Full Month: you save $111,45 + $1114,5 = **$1225,95** (including CP costs)

t3.large ->

* Normal monthly costs: $60,12
* With Cloud Plans:&#x20;
  * Cloud Plans costs in the Case 1:  $2,99 + $2,09 = 5,08 $
  * 86h instance costs: $7,18
  * Total Costs: $12,26
  * Savings: $60,12 - $12,26 = 47,86 $  $ -> Saves 79,6% over the NO Cloud Plans option &#x20;
  * Total savings in Case 1:&#x20;
    * No Cloud Plans Costs: (($60,12 \* 10) / 30) \* 15 = 300,60 $ +   (($60,12 \* 100) / 30) \* 15 = 3006; 300,60 + 3006 = 3306,6&#x20;
    * With Cloud Plans Costs:  ((12,26 \* 10) /30) \* 15 = 61,3;   ((12,26 \* 100) /30) \* 15  =613  -> 61,3 = $674,3
      * Full Month Savings:   3306,6 - 674,3 = **$2632,3** (including CP costs)


# Add / Update

Subscribing is a simple and required step to start using Cloud Plans properly. When a Organization starts has 3 free resources and one plan to try our features (it means up to 3 resources and 3 credentials). But if you already tested CS and want to integrate more resources, you will need to subscribe to a plan. The subscriptions are fully fixed to your needs as you can set as many resources as you need (CP don't work with fixed packs). The unit/price depends on the quantity you subscribe and it is billed in steps using the following Pricing table: <https://www.cloudsscheduler.com/index.html#pricing>

### Steps

* Select an Organization
* Go to Billing -> Configuration on the vertical menu on the left side

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FlInQBWNP5m48wf4elnPM%2FGreenshot%202024-10-22%2013.54.48.png?alt=media&amp;token=67b1839c-dc0d-4e29-ab5b-829301a618a4" alt=""><figcaption></figcaption></figure>

* Scroll down the page up to the end. Then it is the full Subscription zone.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FMlpIhdWR4IBPqEC3Pn9Q%2FGreenshot%202024-10-22%2013.56.58.png?alt=media&amp;token=a451f195-e997-47df-8e92-e0e48f4ec86d" alt=""><figcaption></figcaption></figure>

* When \<ENABLE SUBSCRIPTION> button is clicked, new popup region will be shown as follows:

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FCju9HWeMipqNagX1HAjb%2FGreenshot%202024-10-22%2013.58.10.png?alt=media&amp;token=75fcaf8a-e6a2-40af-a1f9-fd34d9cb6447" alt=""><figcaption></figcaption></figure>

* Here the first thing to configure is the \<Subscription Units> AKA "Quantity". This attribute is the main configuration of your Subscription. When a number higher than 0 is set, the box following that will show the estimated monthly costs for your resources.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FkmXWUsM5iV9fTnVwnfUd%2FGreenshot%202024-10-22%2014.25.38.png?alt=media&amp;token=66b2c99a-e864-4369-98cf-f80fe9eb4b23" alt=""><figcaption></figcaption></figure>

* Then click on \<SET>. You will need to allow POP UP tabs on your browser as we will open a Stripe form for you.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FqaCcDmzdk5XTTB4TlD4G%2Fbuy.stripe.com%20as%20viewed%20from%20United%20Kingdom%20-%20powered%20by%20Geo%20Targetly.png?alt=media&amp;token=49fa2194-fd41-45e6-a093-eeb6ed4ffefb" alt=""><figcaption></figcaption></figure>

* Select Card or SEPA Direct Debit and provide any data needed
* Click on \<Subscribe> and wait until the Stripe confirmation
* In a few minutes you will have enabled your subscription in your Organization and it will be possible to use as many resources as you subscribed for.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fso3abjMyWrPPRIUwe74a%2FGreenshot%202024-10-22%2014.38.30.png?alt=media&amp;token=8c0c58f3-0e38-48bc-926f-5b2d95c38e86" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F1cnDlheIhECZAbYTrSwr%2FGreenshot%202024-10-22%2014.38.55.png?alt=media&amp;token=1eca3775-02dc-489e-a42c-5808366b8d0b" alt=""><figcaption></figcaption></figure>

As shown above, you will see in the Billing->Configuration page your current Subscription

### Updates

{% hint style="warning" %}
“When downgrading a subscription, the current usage of your subscription resources will be verified beforehand. If your organization exceeds the resource limits of the new subscription plan, the update operation will be declined. To proceed, you must reduce the number of resources to align with the limits of the new subscription plan. Additionally, if you update a plan, the proration will be applied immediately, and you will be charged accordingly.”
{% endhint %}

#### Payment Method

When you have a Subscription, and wanted to change the payment method (maybe you have a near to expiration Card, or your Organization Financial changed the Bank Account for projects..., you can always change the payment method.

* Just go to Billing -> Configuration
* Click on \<Change Card> and you will be redirected to the Stripe web console. There you will be able to change the Credit/Debit Card or set SEPA Direct Debit
* The rest of the steps are exactly the same and you will be billed just in your normal period

#### Update Subscription (Resources Subscribed)

When your business changes Cloud Plans can change with you. It is possible at any time to update the number of resources subscribed for. You will be billed (detailed in the parent topic) for the proration inmediately and the rest in your normal billing period. To change your subscription:

* Billing -> Configuration
* Scroll Down
* Click on \<UPDATE SUBSCRIPTION>
* In the dialog, change the Subscription value and you will get ann estimation of the cost deviation estimation

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F3OaFwbv0WRluHf2xvfKS%2FGreenshot%202024-10-22%2014.51.25.png?alt=media&amp;token=cefd9513-e38c-4e53-8f2b-a23a3794e547" alt=""><figcaption></figcaption></figure>

* Confirm the operation clicking on \<UPDATE>. As explained before, the current consumed resources will be billed and the rest of the current period will be billed as normal.


# Cancel

Every Subscription can be cancelled at any time. You can have a disabled subscription in a Organization for up to 1 month. After that period we will remove all your resources data (credentials, plans, resources, messages, etc). When you Cancel a Subscription, the proration of the consumed month resources will be billed.

{% hint style="danger" %}
ALERT: When a Subscription is canceled, the current billing period will be charged to your payment method. And your resources will remain for One month, but will be skipped (so you can get your configuration back if you restablish the Subscription again)
{% endhint %}

To cancel a Subscription you have to complete the following steps:

* Select the Organization in the Web Console
* Go to Billing -> Configuration
* Scroll Down the page
* Click on \<Cancel Subscription> Button

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FTRyDNE8vXPeGDygCaYTl%2FGreenshot%202024-10-22%2015.06.50.png?alt=media&amp;token=d3e0328e-0144-4472-9de2-07ff89a91868" alt=""><figcaption></figcaption></figure>

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FLZGbDOcBCHZsJNdrtRMc%2FGreenshot%202024-10-22%2015.08.03.png?alt=media&amp;token=e3f43f76-eb1b-4da7-a929-8dbfe0a5d806" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: in the next release Cloud Plans will be able to "pause" a subscription for a low fee. Keep updated.
{% endhint %}


# Delete

{% hint style="info" %}
Only a OWNER can delete it's Organizations
{% endhint %}

You can DELETE your Organization. It is important to know that after a Organization is deleted, no data will be able to be downloaded and there are no way to recover your previous configuration easy.

{% hint style="warning" %}
You can not DELETE a Organization with pending invoices but the resources associated will be deleted.
{% endhint %}

Simple step is needed:

* Go to Organizations -> Billing -> Configuration
* In the bottom of the page you can find a small link >Delete Organization<

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FcrKTc7hqbeRuCkjMyzC2%2FGreenshot%202024-10-22%2017.26.33.png?alt=media&amp;token=164b23d8-1ab2-47e7-bd37-1ab8f1522692" alt=""><figcaption></figcaption></figure>

* You will be prompted to confirm the Organization deletion. When click on "YES"/"CONFIRM", the Organization will be deleted.


# Users

{% hint style="info" %}
We are excited to announce the release of our first version and would like to offer you the opportunity to explore it in depth. For a limited time, there will be no restrictions on the number of users (but the logical  with no abuse). After this period, you will be notified to adjust the user count as needed. If the adjustment is not made within the given timeframe, the system will automatically remove the most recently added users.
{% endhint %}

The Organization (highest level resource in Cloud Plans) has initially one single user: the Owner. But this can be enhanced using users with fixed roles (such as RBAC). Initially the Owner can invite a user to the Organization with certain Role: admin, billing viewer, planner. In this article all the roles will be detailed:

| Action                | Owner                | Admin                | Billing              | Planner              | Viewer               |
| --------------------- | -------------------- | -------------------- | -------------------- | -------------------- | -------------------- |
| List Plans            | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :white\_check\_mark: |
| Edit Plan             | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :x:                  |
| Add resources to Plan | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :x:                  |
| Modify Resources      | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :x:                  |
| Remove Resources      | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :x:                  |
| Modify Plan           | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :x:                  |
| Remove Plan           | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :x:                  |
| Add Credentials       | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :x:                  |
| List Credentials      | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :white\_check\_mark: |
| Edit Credentials      | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :x:                  |
| Remove Credentials    | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :x:                  |
| Add User              | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :x:                  |
| Modify User Role      | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :x:                  |
| Remove User           | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :x:                  |
| Get Billing           | :white\_check\_mark: | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: |
| Edit Billing          | :white\_check\_mark: | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  |
| Cancel Billing        | :white\_check\_mark: | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  |
| Get History           | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  | :white\_check\_mark: |
| Get Job History       | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :white\_check\_mark: |
| Get Messages          | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :white\_check\_mark: | :white\_check\_mark: |
| Modify Organization   | :white\_check\_mark: | :white\_check\_mark: | :white\_check\_mark: | :x:                  | :x:                  |
| Delete Organization   | :white\_check\_mark: | :x:                  | :x:                  | :x:                  | :x:                  |


# Add

Once with the Organization selected, it is possible to add users directly with the desired role:

{% hint style="info" %}
Role and Status are editable from the Users page. It is critical to set the best fit to the Organization needs, so review the [reference table](/organization/users).
{% endhint %}

* Go to the Users section on the nav bar
* Click on the <+> (Plus) icon

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F2pNHVBu43U55Airxv5dd%2FGreenshot%202024-10-22%2022.15.03.png?alt=media&amp;token=ce97ff8a-2ee1-417a-8206-b8a6559ca4c1" alt=""><figcaption></figcaption></figure>

* In the PopUp fill in the blanks with the asked data and select the Role and Status (By default "inactive" is selected, we recomend you to review the full permissions before enable the users)

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FI4LNOWtIh4AmEpKFpfuX%2FGreenshot%202024-10-22%2022.16.21.png?alt=media&amp;token=2b323177-a767-450a-80fe-5b7ccfbd0951" alt=""><figcaption></figcaption></figure>

* Click on "Add" and the user will be included in the Organization, but it will not able to connect while the \<State> is "inactive", so be wary.


# Manage

There are some operations you can do in a user:

* Enable / Disable / Update
* Remove from athe Organization

### Enable / Disable / Update

We can have Inactive Users in the Organization for many reasons: it is on a leave, not working on the project yet, just sporadic collaborations... So we can enable/disable the users at every moment:

* Go to the Users console under the Organization menu
* Click on the "edit" icon on the left side of the user you want to edit

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FQqL0MT5P3iMsnGt7FCS2%2FGreenshot%202024-10-23%2014.35.06.png?alt=media&amp;token=38b92192-59e0-4818-b039-8f35ed132867" alt=""><figcaption></figcaption></figure>

* In the Pop Up dialog, change your preferences

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FA1yE0sHQD1H5vAft51E1%2FGreenshot%202024-10-23%2014.36.36.png?alt=media&amp;token=da603831-5922-4021-a413-04d6815bb2e0" alt=""><figcaption></figcaption></figure>

* Click on \<Save>

### Remove from the Organization

In the Users Console, every User in the Table has its action buttons: edit and remove. To remove a user from a Organization just click on the red bin icon and confirm in the Pop Up.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fru531So0K1K86aRA8FIB%2FGreenshot%202024-10-22%2022.27.27.png?alt=media&amp;token=0474e8df-64e8-4304-99e8-634c748061cb" alt=""><figcaption></figcaption></figure>

When the prompt appears, just verify and click on \<Delete>

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F8kcmFkBAUPhG2xb39alx%2FGreenshot%202024-10-23%2014.09.44.png?alt=media&amp;token=3a716c04-695e-463f-97b3-dd7ec7c6257d" alt=""><figcaption></figcaption></figure>


# MFA

MFA is the most recommended configuration for create/update/delete operation because it is how you can protect your organization in the case of Phising and MitM.&#x20;

Now at day, Cloud Plans has the following options: View, Create, Update, Delete and User Management (MGMT)

MFA restrictions are easy to configure:

* Select the Organization
* Go to \<Users> in the Navigation Bar
* You shoul see the MFA Settings table in the upper side of the page

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F0bGB4nb9bb5UvzQPB2Kc%2FGreenshot%202024-10-23%2014.27.55.png?alt=media&amp;token=5a9684f2-acd0-4ca3-8912-89d0fabd8e64" alt=""><figcaption></figcaption></figure>

* Select your preferred options
* Click on \<Save>


# Credentials

The credential resource is the way Cloud Plans connect to your Clouds:

* To AWS accounts CS connects using a remote role you shuld create in your AWS Account IAM
* To Azure Subscriptions CS connects using Service Principal
* To Google Cloud projects CS connects using a your project ID

&#x20;

### AWS

We use remote roles to connect to Accounts and manage the desired resources ([best Security Practice](https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#bp-workloads-use-roles)). All you have to do is:

* Create a role trusting the external account 605134468875 with the following permissions:

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "ec2:RebootInstances",
                "sts:GetSessionToken",
                "ec2:DescribeInstances",
                "ec2:StartInstances",
                "ec2:DescribeInstanceAttribute",
                "ec2:DescribeRegions",
                "ec2:DescribeInstanceTypes",
                "sts:GetCallerIdentity",
                "ec2:StopInstances",
                "ec2:DescribeInstanceStatus"
            ],
            "Resource": "*"
        }
    ]
}
```

This can be enhaced in Security with the following recommendation:

* Tag your desired instances with something like "cloudsscheduler"
* Edit the policy with the following:

```
{
	"Version": "2012-10-17",
	"Statement": [
		{
			"Sid": "exampleCSPolicyWithCondition",
			"Effect": "Allow",
			"Action": [
				"ec2:DescribeHosts",
				"ec2:RebootInstances",
				"ec2:DescribeInstances",
				"ec2:StartInstances",
				"ec2:DescribeInstanceAttribute",
				"ec2:DescribeInstanceTypes",
				"ec2:DescribeFleetInstances",
				"ec2:RunInstances",
				"ec2:DescribeClassicLinkInstances",
				"ec2:StopInstances",
				"ec2:DescribeInstanceStatus"
			],
			"Resource": "*",
			"Condition": {
				"StringLikeIfExists": {
					"aws:ResourceTag/cloudsscheduler": "True"
				}
			}
		}
	]
}
```

### Azure

Cloud Plans needs Service Principals with the access key. It is recommended to have one SP per Subscription. The recommended policy can be as follows:

```
{
    "properties": {
        "roleName": "cloudsscheduler",
        "description": "",
        "assignableScopes": [
            "/subscriptions/1a2e3b4e4d-0a0a-1b1b-aaaa-aaa000111aaa" (an example)
        ],
        "permissions": [
            {
                "actions": [
                    "Microsoft.Compute/locations/runCommands/read",
                    "Microsoft.Compute/availabilitySets/vmSizes/read",
                    "Microsoft.Compute/hostGroups/hosts/read",
                    "Microsoft.Compute/hostGroups/read",
                    "Microsoft.Compute/proximityPlacementGroups/read",
                    "Microsoft.Compute/hostGroups/hosts/hostSizes/read",
                    "Microsoft.Compute/virtualMachines/read",
                    "Microsoft.Compute/virtualMachines/start/action",
                    "Microsoft.Compute/virtualMachines/powerOff/action",
                    "Microsoft.Compute/virtualMachines/restart/action",
                    "Microsoft.Compute/virtualMachines/vmSizes/read",
                    "Microsoft.Compute/virtualMachines/runCommands/read",
                    "Microsoft.Compute/virtualMachines/runCommands/write",
                    "Microsoft.Compute/sharedVMExtensions/read",
                    "Microsoft.Compute/virtualMachineScaleSets/read",
                    "Microsoft.Compute/virtualMachineScaleSets/manualUpgrade/action"
                ],
                "notActions": [],
                "dataActions": [],
                "notDataActions": []
            }
        ]
    }
}
```

### GCP

In Google Cloud is similar to AWS. We will connect from other GCP Projectand you have to bind our Service Account to the desired role in your Projects IAM. An example Policy may contain:

* compute.autoscalers.get&#x20;
* compute.autoscalers.list&#x20;
* compute.autoscalers.update&#x20;
* compute.healthChecks.get&#x20;
* compute.healthChecks.list&#x20;
* compute.instanceGroups.get&#x20;
* compute.instanceGroups.list&#x20;
* compute.instanceGroups.update&#x20;
* compute.instances.get&#x20;
* compute.instances.list&#x20;
* compute.instances.reset&#x20;
* compute.instances.start&#x20;
* compute.instances.stop&#x20;
* compute.instances.suspend&#x20;
* compute.nodeGroups.get&#x20;
* compute.nodeGroups.list&#x20;
* compute.nodeGroups.update


# Automations


# AWS

Terraform Code

{% code overflow="wrap" fullWidth="true" %}

```hcl
data "aws_iam_policy_document" "policy" {
  statement {
    effect    = "Allow"
    actions   = ["ec2:Describe*", ""ec2:StartInstances", "ec2:RebootInstances", "ec2:RunInstances", "ec2:StopInstances"]
    resources = ["*"]
  }
}

resource "aws_iam_policy" "cloudplans_policy" {
  name        = "test-policy"
  description = "A test policy"
  policy      = data.aws_iam_policy_document.policy.json
}


data "aws_iam_policy_document" "assume_role" {
  statement {
    effect = "Allow"

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::851725229460:root"]
    }

    actions = ["sts:AssumeRole"]
  }
}

resource "aws_iam_role" "cloudplans_role" {
  name = "test_role"

  assume_role_policy = data.aws_iam_policy_document.assume_role.json
}

resource "aws_iam_role_policy_attachment" "test-attach" {
  role       = aws_iam_role.cloudplans_role.name
  policy_arn = aws_iam_policy.cloudplans_policy.arn
}
```

{% endcode %}


# Azure

{% code overflow="wrap" fullWidth="true" %}

```hcl
data "azuread_client_config" "current" {}
data "azurerm_subscription" "current" {}

resource "azuread_application" "cloudplans_application" {
  display_name = "cloudplans_application"
  owners       = [data.azuread_client_config.current.object_id]
}

resource "azuread_service_principal" "cloudplans_sp" {
  client_id                    = azuread_application.cloudplans_application.client_id
  app_role_assignment_required = false
  owners                       = [data.azuread_client_config.current.object_id]
}

resource "azurerm_role_definition" "example" {
  name        = "cloudplans_role"
  scope       = data.azurerm_subscription.primary.id
  description = "This is a custom role created via Terraform for CloudPlans"

  permissions {
    actions     =  [
                    "Microsoft.Compute/locations/runCommands/read",
                    "Microsoft.Compute/availabilitySets/vmSizes/read",
                    "Microsoft.Compute/hostGroups/hosts/read",
                    "Microsoft.Compute/hostGroups/read",
                    "Microsoft.Compute/proximityPlacementGroups/read",
                    "Microsoft.Compute/hostGroups/hosts/hostSizes/read",
                    "Microsoft.Compute/virtualMachines/read",
                    "Microsoft.Compute/virtualMachines/start/action",
                    "Microsoft.Compute/virtualMachines/powerOff/action",
                    "Microsoft.Compute/virtualMachines/restart/action",
                    "Microsoft.Compute/virtualMachines/vmSizes/read",
                    "Microsoft.Compute/virtualMachines/runCommands/read",
                    "Microsoft.Compute/virtualMachines/runCommands/write",
                    "Microsoft.Compute/sharedVMExtensions/read",
                    "Microsoft.Compute/virtualMachineScaleSets/read",
                    "Microsoft.Compute/virtualMachineScaleSets/manualUpgrade/action"
                ]
    not_actions = []
  }

  assignable_scopes = [
    data.azurerm_subscription.primary.id, # /subscriptions/00000000-0000-0000-0000-000000000000
  ]
}

resource "azurerm_role_assignment" "assignment" {
  principal_id = azuread_service_principal.cloudplans_sp.id
  scope        = data.azurerm_subscription.current.id
  role_definition_name = var.rolename
  skip_service_principal_aad_check = true
}

```

{% endcode %}


# GCP

{% code overflow="wrap" fullWidth="true" %}

```hcl
resource "google_project_iam_custom_role" "cloudplans_role" {
  role_id     = "cloudplans_role"
  title       = "Cloud Plans Role"
  description = "This is a custom role created via Terraform for CloudPlans"
  permissions = ["compute.autoscalers.get","compute.autoscalers.list","compute.autoscalers.update","compute.healthChecks.get","compute.healthChecks.list","compute.instanceGroups.get","compute.instanceGroups.list","compute.instanceGroups.update","compute.instances.get","compute.instances.list","compute.instances.reset","compute.instances.start","compute.instances.stop","compute.instances.suspend","compute.nodeGroups.get","compute.nodeGroups.list","compute.nodeGroups.update"]
}

data "google_iam_policy" "cloudplans_role_policy_binding" {
  binding {
    role = google_project_iam_custom_role.cloudplans_role.name

    members = [
      "cloudplanssa@cloudplans.iam.gserviceaccount.com",
    ]
  }
}

resource "google_service_account_iam_policy" "cloudplans_role_binding" {
  service_account_id = "cloudplanssa@cloudplans.iam.gserviceaccount.com"
  policy_data        = data.google_iam_policy.cloudplans_role_policy_binding.policy_data
}
```

{% endcode %}


# Create

The Credential object is diferent depending on the Cloud Provider (AWS, Azure or GCP).  Each one has it's own parameters:

* AWS
  * Credential Name
  * Role
  * Comments
* Azure
  * Credential Name
  * Tenant
  * Subscription
  * Client ID
  * Secret
  * Comments
* GCP
  * Credential Name
  * Project
  * Comments

Every Credential needs an action from you (in AWS you have to create a policy + role with binding, in Azure it is neccesary to create a Service Principal in a Subscription and assign a Key and Role, and in GCP it is needed to have a IAM Policy + Role + Binding).

* Selet an Organization
* Go to \<Credentials> in the nav menu
* Click on the "+" icon
  * &#x20;![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FUkdKYMYShH3p3FaKg77o%2FGreenshot%202024-10-23%2022.00.03.png?alt=media\&token=bc58bb03-2959-4e0b-ac87-bbcc1d37fab0)
* Fill in the blanks with the required Data (Comments are optional, but desired, as we can have same roles in different accounts and this could be a real mess.
  * ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FZTwZ9J6UXrwqpQCvHroE%2FGreenshot%202024-10-23%2022.03.43.png?alt=media\&token=e88ebdd0-a9c8-4fe6-ad84-70210fb6df9e)


# Create Azure Service Principal

Creating a Service Principal in Azure and retrieving its Client ID and Secret involves several steps. Below is a detailed, step-by-step guide:

<br>

### Step 1: Log in to Azure

1\. Open the Azure Portal (<https://portal.azure.com>).

2\. Log in with your Azure credentials.

<br>

### Step 2: Navigate to Azure Active Directory

1\. In the left-hand navigation pane, select Azure Active Directory.

2\. Under the Manage section, click App registrations.

<br>

### Step 3: Register a New Application

1\. Click New registration at the top of the page.

2\. Fill in the required fields:

• Name: Enter a descriptive name for the Service Principal (e.g., “MyServicePrincipal”).

• Supported account types: Choose who can access this application. Typically, select Accounts in this organizational directory only.

• Redirect URI: Leave this blank for Service Principal creation unless required by your application.

3\. Click Register.

<br>

### Step 4: Retrieve the Application (Client) ID

1\. Once the registration is complete, you will be redirected to the application’s overview page.

2\. Note down the Application (client) ID and Directory (tenant) ID. You will need them later.

<br>

### Step 5: Create a Client Secret

1\. In the application’s Manage section, select Certificates & secrets.

2\. Under the Client secrets tab, click New client secret.

3\. Provide a description (e.g., “DefaultSecret”) and choose an expiration duration (e.g., 1 year, 2 years, or custom).

4\. Click Add.

5\. Copy the generated value of the secret. This is the Client Secret.

Note: You will not be able to view this secret again once you leave the page, so save it securely.

### Step 6: Create a Custom Role

### 1. Navigate to Azure Active Directory in the portal.

2\. In the left-hand menu, click Roles and administrators > + New custom role.

<br>

### Step 7: Define Role Details

#### 1. Basics Tab:

• Name: Enter a name like “Virtual Machine Manager Role.”

• Description: Provide a brief description, e.g., “Allows listing, getting, starting, and stopping Virtual Machines.”

#### 2. Permissions Tab:

• Click + Add permissions.

• Search for Microsoft.Compute/virtualMachines.

• Select the following actions:

* Microsoft.Compute/virtualMachines/read
* Microsoft.Compute/virtualMachines/start/action
* Microsoft.Compute/virtualMachines/deallocate/action

• Click Add.

#### 3. Assignable Scopes Tab:

Navigate to the Resource Group:

• Specify the scope where this role can be assigned:

• Subscription: Assign it at the subscription level if you want it to apply to all resource groups and VMs.

• Resource Group: Assign it at the resource group level for more granular control. (Here is the most important part, as we have to specify the Resource Groups for this Credential. It is a Best Practice to create Service Principals and roles for 1 to 2-3 Resource Groups, to limit the overgevernance.

• Click + Add Assignable Scope and select the relevant scope.

#### 4. Review and finalize the role:

• Click Review + create.

• Click Create.

### Step 8: Assign the Role to the Service Principal

1\. Navigate to the resource you want the Service Principal to access (e.g., a subscription, resource group, or specific resource).

2\. Go to the Access control (IAM) section of the resource.

3\. Click Add role assignment.

4\. In the Role field, select the Custom Role created in the Step 7

5\. In the Assign access to field, select User, group, or Service Principal.

6\. Search for the name of the Service Principal (the application name you created).

7\. Select it, and click Save.


# Create AWS Role

### Step 1: Log in to the AWS Management Console

1\. Open the AWS Management Console: <https://aws.amazon.com/console/>.

2\. Navigate to the IAM (Identity and Access Management) service.

<br>

### Step 2: Create the Role

1\. In the IAM dashboard, click Roles in the left navigation pane.

2\. Click Create Role.

3\. Under Select trusted entity, choose AWS Account.

4\. Enter the AWS Account ID:

• Select Another AWS account.

• Enter 851725229460 (the account ID).

5\. Click Next to proceed.

<br>

### Step 3: Attach the Policy

1\. On the Permissions page, select Create policy (if you don’t already have a policy for EC2 permissions).

2\. Define the policy:

• Choose the JSON tab.

• Paste the following policy to allow listing, describing, starting, and stopping EC2 instances:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "VisualEditor0",
            "Effect": "Allow",
            "Action": [
                "ec2:RebootInstances",
                "sts:GetSessionToken",
                "ec2:DescribeInstances",
                "ec2:StartInstances",
                "ec2:DescribeInstanceAttribute",
                "ec2:DescribeRegions",
                "ec2:DescribeInstanceTypes",
                "sts:GetCallerIdentity",
                "ec2:StopInstances",
                "ec2:DescribeInstanceStatus"
            ],
            "Resource": "*"
        }
    ]
}
```

###

### Step 5: Verify the Role Trust Policy

1\. Go to the Roles section and select the role you just created.

2\. Under the Trust relationships tab, ensure the trust policy looks like this:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": [
                    "arn:aws:sts::605134468875:assumed-role/cloudplansbatch/CloudPlansAssumeRoleSession"
                ]
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
```


# Create Google Cloud Bindings

### Step 1: Create a Custom Role

1\. Log in to the Google Cloud Console

• Go to [Google Cloud Console](https://console.cloud.google.com/).

2\. Navigate to IAM & Admin

• In the left-hand menu, select IAM & Admin > Roles.

3\. Create a New Role

• Click + CREATE ROLE at the top of the page.

• Fill in the following details:

• Title: Enter a name like CustomComputeRole.

• ID: A unique identifier for the role (e.g., custom\_compute\_role).

• Description: Add a description, such as “Role to list, describe, start, and stop VM instances.”

4\. Add Permissions

• Click + Add Permissions and add the following permissions:

• compute.instances.get (to describe instances).

• compute.instances.list (to list instances).

• compute.instances.start (to start instances).

• compute.instances.stop (to stop instances).

• Click ADD PERMISSIONS to save.

5\. Save the Role

• Click CREATE to finalize the custom role.

<br>

### Step 2: Assign the Custom Role

1\. Navigate to IAM

• Go to IAM & Admin > IAM.

2\. Grant the Custom Role

• Click + GRANT ACCESS.

• Enter the email address or service account of the entity you want to assign the role to.

• Select the custom role (CustomComputeRole) from the dropdown.

• Click SAVE.

<br>

### Step 3: Create Binding for External Access

To allow the project cloudplans to connect from outside its project, you need to create an IAM binding for external access.

1\. Determine the Service Account or Identity

• Ensure you have the service account email or identity from the cloudsscheduler project that needs access.

2\. Navigate to IAM Policy Binding

• In the IAM & Admin > IAM section, select the project where the VMs reside.

3\. Add a Binding

• Click Edit Principal or Add Principal.

• In the New Principals field, enter the service account or external identity of the cloudplans project (**<1000620131311-compute@developer.gserviceaccount.com>**).

• Select the custom role (CustomComputeRole) you created earlier.

4\. Save the Binding

• Click SAVE to apply the changes.


# Manage

### Update

Usually IAM changes in organizations, and Cloud Plans ease you the maintenance of your plans. If a AWS Role changes in an Account, you can update the Credential associated to that role, that way you won't need to change anything else.

* When Connected to a Organization. Go to \<Credentials>
* Select the Credential you need to update and click on the "edit" icon at the left side of the credential
  * ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FBOevvDV9DEKovDdw0Hic%2FGreenshot%202024-10-23%2022.26.02.png?alt=media\&token=53833dad-a572-4ca2-96b7-9c6b2dca1457)
* Every parameter can be updated
  * ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F1UJBGDhjqbHPMVlnZnGA%2FGreenshot%202024-10-23%2022.30.56.png?alt=media\&token=374f8914-8838-47aa-a1f0-822c308acb3f)

### Delete

Maybe you created some credentials for project not in use or without resources currently. It is a best practice to keep your resources as clean as possible so CP provide you the ability to delete every Credential.

* Click on the bin icon in the left side of the Credential
* Confirm the action in the Pop Up -> Provide a comment to document properly every action made in the Organization.
  * ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FWvu7MW75Ryu1hyCY9JDW%2FGreenshot%202024-10-23%2022.36.42.png?alt=media\&token=cce92a06-41e1-4fcc-b679-e412edc57328)


# Plans

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FPllriC1x73LrtSfE4Tnv%2FconfigFlow.gif?alt=media&amp;token=705f3aa4-7e46-4d31-a1e7-b576c1792a2e" alt=""><figcaption></figcaption></figure>

As shown above, the Plan depends on the credentials as any resource referenced in the plan (Virtual Servers) needs a Credential associated. The plan is a object with some specific attributes :

* **Name**: It is not neccesary to be uniqe but recommended, for a better Operation and Control
* **Timezone**: The schedule depends on the location you need. Depending on the idiosyncrasies of your Teams you may need to have a plan for a Group of resources in Argentina, other for your Beijin Team and other for your european Team as each of them are working with different resources in different projects&#x20;

{% hint style="success" %}
A common approach consists on naming the plans according to the project or a mix of team-project: devs-ar-surveillancecamconcentrator001
{% endhint %}

* **Start Time**: When your schedule starts in the desired Timezone; this means when to start assuming  the resources referenced in the plan should be stopped. This attribute only admits hours and not minutes.
* **Duration**: How long (in hours) since the Start Time the resources referenced shoud be stoppd
* **Days of the Week**: What days of the week we need this Plan working.&#x20;

{% hint style="info" %}
Please be vigilant: avoid adding the same resource to multiple plans simultaneously with different schedules, as this can lead to instability. Cloud Scheduler processes each plan individually, making the behavior unpredictable when two plans with overlapping schedules are involved. For instance, the resource may remain active until the next hour in some cases, while in others, it may shut down prematurely.
{% endhint %}

* **Notification:** It is possible (and recommended) the configuration of a Notifications Channel as this way every time an error occurs, the desired Channel will be informed.&#x20;
* **State**: Active / Disabled. It is possible to define a Plan just for showing the range of possible alternatives and then it can be easy to enable or destroy the definition.

{% hint style="warning" %}
It is crucial to carefully plan how to group resources based on projects, teams, or objectives to ensure efficient management and alignment with your goals. However, keep in mind that plans are flexible and can be easily modified at any time. Any changes made will take effect at the start of the next hour, providing adaptability without disrupting operations.
{% endhint %}


# Create

Creating a Plan is simple, but delicate as when a plan with resources is created, if it is in the "Active" state it will start working on the next hour so it is recommended to be concerned with that.

* Once authenticated and with the Organization selected. Go to the Plans -> Plans into the menu ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FFQu3NOqqei4fskSGFSHY%2FGreenshot%202024-10-24%2006.44.22.png?alt=media\&token=29ffb0fb-373b-46e8-a1d0-6f665b468ec3)
* There it is a of the current plans
  * &#x20;![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FiinEGKKHiwBUFbnKbo7m%2FGreenshot%202024-10-24%2006.49.58.png?alt=media\&token=158f099c-0f57-4075-aa95-243f7dcb1260)
* To create a NEW Plan you need to click on the "+" icon on the top left of the table.
* The fields must be filled with your desired configuration
  * ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FnqFMtOejGBzx3qaRE3tK%2FGreenshot%202024-10-24%2006.51.37.png?alt=media\&token=e7271445-f3a3-4e39-b786-412c0867291e)


# Update

* When it is a Plan created. Edit it to add resources or changes in timezone, start time, duration and status.&#x20;
* First go to Plans Menu
* Click on the "edit" icon (left side of every Plan)
  * ![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FerI7k2dMEsVvYiaiNdVi%2FGreenshot%202024-10-24%2006.58.06.png?alt=media\&token=8bb95829-1ae6-4678-b0ec-ac8e7cd337ed)
* When redirected you will see on top a configuration Box with the same attributes like when creating the Plan but also a checkbox for \<Resources dependancy>. It means that if you check, the order will be important and:
  * Every instance will be sopeed only after the previous was stopped
  * If a Stop instance fails before finishing the plan, the remaining instances will be sopeed (at least) up to the nex cycle.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FhL7y40UO3whIrT71RWo1%2FGreenshot%202024-10-24%2008.46.26.png?alt=media&amp;token=fd683408-5848-4101-8c64-69a515b67bcb" alt=""><figcaption></figcaption></figure>

* Once you update any configuration, click on \<Save> to apply the changes


# Add Reources

The Plan is the container for resources. You can add reources to a plan and the same resource can be present in more then one plan at the same time.

{% hint style="info" %}
More than one plan can have the same resources with different schedules
{% endhint %}

* Open the plan edition from the Menu ([steps are here](/organization/plans/update))
* Click on the "+" icon to ad resources

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fn5af61aLvzKPCnJgaTNs%2FGreenshot%202024-10-24%2009.16.50.png?alt=media&amp;token=e44465f9-f874-4ec3-b783-5807968439dd" alt=""><figcaption></figcaption></figure>

* In the Pop Up box, select the Cloud Provider and fill in the blanks with the desired data

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FZNBlYUAfhMSR3XoPMYnU%2FGreenshot%202024-10-24%2009.18.28.png?alt=media&amp;token=55aafff4-4b5f-4987-bdad-6d7c8d6eeef6" alt=""><figcaption></figcaption></figure>

* Some data is needed:
  * AWS:
    * Instance ID
    * Instance Name: Not mandatory
    * Region
    * Credential: Not mandatory
    * Status
  * Azure:
    * VM ID
    * VM Name: Not mandatory
    * Resource Group
    * Credential: Not mandatory
    * Status
  * GCP:
    * Instance Name: Not mandatory
    * Self Link
    * Credential: Not mandatory
    * Status
  * Common:
    * Comments: Not mandatory

{% hint style="info" %}
It is possible to create Instances with no Credential associated. The status will be "Inactive" and it is not possible to enable it until you specify a Credential.
{% endhint %}

Once the resource is created, you can change the order of the resources (useful if you need to set the Dependancy setting enabled)

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FMalj0juuVZCz417zza2J%2FGreenshot%202024-10-24%2009.58.59.png?alt=media&amp;token=d7067e5d-e1e6-4a38-a6f4-353769221ff1" alt=""><figcaption></figcaption></figure>

When a resource list is altered, you have to "push" the new sorted list. All you have to do is:

* Push on the green check button on the top of the resources list

![](https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FSuiBG98Jy5qUH3c16hpP%2FGreenshot%202024-10-24%2010.20.34.png?alt=media\&token=23c8ffc9-612e-4e81-932b-f3fbd2102220)&#x20;


# Update Resources

Every resource can be updated to your environment changes. There are immutable attributes such us the res-id, but every other attribute you specified when creating is variable at any time. This way we can:

* Enable / Disable an instance
* Change the vm/instance ID if you redeployed the resource and the reference changed
* Change the name according to your current preferences
* Change the comment

{% hint style="info" %}
For any Resource Update it is recommended to leave at least a "Edition comment". This way it is traceable. A Service Now REQ/TASK, Jira Issue, etc.
{% endhint %}

Just follow this simple steps:

* Open your desired plan from the Plans menu
* Click on the "edition" icon on the left side of the resource

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F9c8XehO8WnBohaZX6BkZ%2FGreenshot%202024-10-24%2010.27.38.png?alt=media&amp;token=63337d21-7d11-43f2-9a7b-218fc2015198" alt=""><figcaption></figcaption></figure>

* In the Pop Up box, change whatever you need and then click on \<Edit>

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2F64AUzXuTWsBt2ynZsv1V%2FGreenshot%202024-10-24%2010.28.55.png?alt=media&amp;token=5042e35f-a683-4fdf-bc26-1d8aa0d0db0c" alt=""><figcaption></figcaption></figure>


# Reorder Resources

It is normal when working in the "Dependancy mode" to change the order of the resources; usually front are first to be stopped, then back and finally database, but this can be too dynamic, and that's why Cloud Plans implements a dependancy control option and a mechanism for change the resources order in a plan.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Foq84C7KunCvzgOk7XPYC%2FGreenshot%202024-10-24%2017.38.38.png?alt=media&amp;token=986b451d-78e0-4250-a7f1-54733db906a1" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Whe enabled, Resources Dependancy will act in the stablished order for poweroff and reverse for powering on.

Having the following example Resources list:

* exapleAWSinstance001
* exapleAWSinstance002
* exapleAWSinstance003

The STOP operation will be:

1. exapleAWSinstance001
2. exapleAWSinstance002
3. exapleAWSinstance003

The START will be:

1. exapleAWSinstance003
2. exapleAWSinstance002
3. exapleAWSinstance001
   {% endhint %}

Above it is the check control for enabling or disabling the resources dependancy. If you change it, it is neccesary to click on \<Save>. Afet that every job will run with the resources dependancy in the correct order.

{% hint style="danger" %}
If Resources Dependancy is enabled, if a resource fails stopping or starting, the rest of the resources will be ignored.
{% endhint %}

When enabled the Order Dependancy, it starts making senso to change the order an Save...

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FZN4DrVJ2qQBuTZagddA6%2FGreenshot%202024-10-24%2017.50.08.png?alt=media&amp;token=586649e4-fcdd-45c6-9f98-189ffa5a46d2" alt=""><figcaption></figcaption></figure>

As showing in the image above this text, first we have to use de UP/DOWN arrow on the resources to have it in our needs. Then click on the green "check" button to SAVE the new order.


# Notifications

Every plan can have its own notification channel, so it is possible to configure as many channels as needed (one for PROJXXXXX via email, another for PROJXXXXX via Slack).

We are in the process of developing new channel types, such as ServiceNow and Jira, which will soon be available. In the interim, it is possible to configure email/Slack and change the notification type directly, with only one modification needed if certain responsible teams change their support channel.

To reach Notifications configuration just expand the "Plans" menu on the left side navigation bar, and click on "Notifications":

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FXkCZYzNoZisaqxh6eqHc%2F2024-11-28%2012_17_45-Window.png?alt=media&amp;token=047eca10-40e6-4bde-98c2-e047344e6c81" alt=""><figcaption></figcaption></figure>

Clicking on the 'plus' icon in the Notifications panel is all it takes to add a new Notifications channel:

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FCldsieljw41LTQxbnzsr%2F2024-11-28%2012_18_40-Window.png?alt=media&amp;token=04899eba-7d31-4e7a-9bd5-961fd0d0ac3c" alt=""><figcaption></figcaption></figure>

The form is straightforward: just fill in all the necessary information. There are no optional fields.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FGjD8vFPdjB9A3QDVT9Kv%2F2024-11-28%2012_18_59-Window.png?alt=media&amp;token=d8294d2e-d0b5-4424-88de-c2fae68f0a0c" alt=""><figcaption></figcaption></figure>

After finishing, select 'CREATE' and wait for 1-2 seconds until the notification creation is verified. Then You will be able to use it in a Plan:

* Go to Plans
* Select the \<edit> icon of your desired plan
* In the edition panel look for the \<Notifications> input and select your's (you have to click on the area, then you can select, but if you have several channels, you can start typing by the name for filtering the results):

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2Fjetzuep21b7bQQervXLQ%2F2024-11-28%2012_24_57-Window.png?alt=media&amp;token=d31edd4d-ab8e-49e9-93c5-31f72db01194" alt=""><figcaption></figcaption></figure>

* Click on \<Save>&#x20;
* If your resources encounter an error, such as instances that are not accessible, invalid credentials, or problems with our engine, the selected will receive notification.


# Jobs

The Job is the result of a Plan execution. Every Plan execution has it's own Job, with the result. And if the Job results on a error, it will include the best detailed description.

{% hint style="info" %}
We save your jobs execution for up to 3 months, for that period you can download in CSV format the full list
{% endhint %}


# History

History contains the last 10k activities (create, update or delete resources or configuration) from your Organization.You can download it in CSV format at any time.

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FyesilwiLsvjayCq6SkOJ%2FGreenshot%202024-10-24%2018.10.09.png?alt=media&amp;token=20b9197e-a871-4d8e-bc59-f5341a9f687f" alt=""><figcaption></figcaption></figure>


# Messages

Messages contains information regarding errors occured with your resources:

* Invalid resources
  * Bad credentials
  * Inexistent resource
  * There is no Resource Group in the Credential focus
  * The Zone was incorrect
* Insufficient permissions
* START/STOP error other than permissions
* Cloud Plans outage
* Payment problem
  * Card near to expiration
  * Card expirated
  * Unpaid bill

The errors will be showed with a ERROR LEVEL label: critical, warning and info


# Authentication

For Security reasons we don't allow long term tokens so the only allowed method consists on the Cloud Plans Portal Login and then obtaining a \<up to> 30 minutes token (the session max time).

{% hint style="info" %}
It is not possible to have long term API Keys in the Public distribution. If you need it, use the contact Support zone to ask for a Private deployment (there are some personalizations such as long term tokens disassociated.
{% endhint %}

* Login in&#x20;
* Go to the up Nav Bar and look for the "user" icon

<figure><img src="https://4068101876-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fof9VPhQljrlGxPCWMrxF%2Fuploads%2FjpfkPqg8Z91yIFJgM1FF%2FGreenshot%202024-11-04%2006.22.17.png?alt=media&amp;token=613fa70e-bef3-4a6e-8057-5813583a9a37" alt=""><figcaption></figcaption></figure>

* Once clicked, you should get an \<API Key> option. Click on it.
* Copy the API Key provided in the alert message and proceed with your operations over the API.


# User

## Describe user

<mark style="color:green;">`GET`</mark> /v1/user/describe

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name                  | Type   | Description                          |
| --------------------- | ------ | ------------------------------------ |
| action=describe\_user | string | The action (will not be needed soon) |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": {
    "MFA": bool
  }
}
```

{% endtab %}
{% endtabs %}


# Organization

## List Organizations

<mark style="color:green;">`GET`</mark> /v1/organizations/list

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name        | Type   | Description                          |
| ----------- | ------ | ------------------------------------ |
| action=list | string | The action (will not be needed soon) |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "data": {
    "organizations": [
       {
         "org_id": "string",
         "org_name": "string",
         "role": "string",
         "owner": "string",
         "resources": number
        } 
    ]
  }
}
```

{% endtab %}
{% endtabs %}

## Create Organization

<mark style="color:green;">`POST`</mark> /v1/organizations/create

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Query String**

| Name            | Type   | Description                          |
| --------------- | ------ | ------------------------------------ |
| `action=create` | string | The action (will not be needed soon) |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": {
    "id": "string"
  }
}
```

{% endtab %}
{% endtabs %}

## Update Organization

<mark style="color:green;">`POST`</mark> /v1/organizations/update?`action=update`

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Querystring**

| Name            | Type   | Description                          |
| --------------- | ------ | ------------------------------------ |
| `org_id`        | string | The Organization ID                  |
| `action=update` | number | The action (will not be needed soon) |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Remove Organization

<mark style="color:green;">`POST`</mark> /v1/organizations/remove?action=remove

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name     | Type   | Description         |
| -------- | ------ | ------------------- |
| `org_id` | string | The Organization ID |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}


# Billing

## Describe Billing

<mark style="color:green;">`GET`</mark> /v1/organizations/billing/describe?action=getorganization

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name    | Type   | Description         |
| ------- | ------ | ------------------- |
| org\_id | string | The Organization ID |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": {
    "organization": {
      "resources": number,
      "name"; "string",
      "id": "string",
      "owner": "string"
    }
    "subscription": {
      "payment_exp": "string";
      "plan": "string";
      "quantity": "string";
    }
  }
}
```

{% endtab %}
{% endtabs %}

## Billing History

<mark style="color:green;">`GET`</mark> /v1/organizations/billing/history

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name                 | Type   | Description         |
| -------------------- | ------ | ------------------- |
| action=list\_billing | string | Name of the user    |
| org\_id              | string | The Organization ID |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "billing_history": [
    {
      "status": "paid | unpaid",
      "id": "string",
      "organization": "string",
      "date": "string",
      "due_date": "string",
      "amount": "string"
      
    }
  ]
}
```

{% endtab %}
{% endtabs %}

## Create subscription

<mark style="color:green;">`POST`</mark> /v1/organizations/billing/update?action=getpaymentlink

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Query String**

| Name     | Type   | Description                         |
| -------- | ------ | ----------------------------------- |
| org\_id  | string | The ID of the Organization          |
| quantity | number | Number of Instances for subscribing |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": "string" (the payment Link)
}
```

{% endtab %}
{% endtabs %}

## Change payment method

<mark style="color:green;">`POST`</mark> /v1/organizations/billing/update?action=getupdatecardlink

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name    | Type   | Description         |
| ------- | ------ | ------------------- |
| org\_id | string | The Organization ID |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": "string" (the Link for the Update Payment operation)
}
```

{% endtab %}
{% endtabs %}

## Update Subscription

<mark style="color:green;">`POST`</mark> /v1/organizations/billing/update?action=updatesubscription

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name     | Type   | Description                                  |
| -------- | ------ | -------------------------------------------- |
| org\_id  | string | The ID of the Organization                   |
| quantity | number | The number of instances for the Subscription |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Cancel Subscription

<mark style="color:green;">`POST`</mark> /v1/organizations/billing/update?action=cancelsubscription

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name     | Type   | Description                |
| -------- | ------ | -------------------------- |
| `org_id` | string | The ID of the Organization |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
}
```

{% endtab %}
{% endtabs %}


# Organization Users

## List Users

<mark style="color:green;">`GET`</mark> /v1/organizations/users/list

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name         | Type   | Description         |
| ------------ | ------ | ------------------- |
| action=users | string | Name of the user    |
| `org_id`     | number | The Organization ID |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "users": [
    {
      "email": "string",
      "role": "string",
      "state": "string"
    }
  ],
  "mfa": {
    "view": bool,
    "create": bool,
    "update": bool,
    "delete": bool,
    "usersmgmt": bool
  }
}
```

{% endtab %}
{% endtabs %}

## Add a new user

<mark style="color:green;">`POST`</mark> /v1/organizations/users/add?action=add\_user

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name     | Type   | Description         |
| -------- | ------ | ------------------- |
| org\_id  | string | The Organization ID |
| user\_id | string | The user email      |
| role     | string | The role            |
| state    | string | active \| inactive  |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Edit organization user

<mark style="color:green;">`POST`</mark>  /v1/organizations/users/update?action=update\_user

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name     | Type   | Description         |
| -------- | ------ | ------------------- |
| `org_id` | string | The Organization ID |
| user\_id | string | The user email      |
| role     | string | The role            |
| state    | string | active \| inactive  |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Remove user from Organization

<mark style="color:green;">`POST`</mark> /v1/organizations/users/remove?action=remove\_user

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name      | Type   | Description         |
| --------- | ------ | ------------------- |
| `org_id`  | string | The Organization ID |
| `user_id` | string | The user email      |
| reason    | string | The reason          |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}


# Credentials

## List credentials

<mark style="color:green;">`GET`</mark> /v1/organizations/credentials/list

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name                     | Type   | Description                          |
| ------------------------ | ------ | ------------------------------------ |
| org\_id                  | string | The Organization ID                  |
| action=list\_credentials | string | The action (will not be needed soon) |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "credentials": [
    {
      "type": "azure|aws|gcp",
      "id": "string",
      "name": "string",
      "comments": "string",
      "resources": 0-1000,
      "last_time": "string"
    }
  ]
}
```

{% endtab %}
{% endtabs %}

## Create a new credential

<mark style="color:green;">`POST`</mark> /v1/organizations/credentials/create?action=add\_credential

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

<table><thead><tr><th width="140">Name</th><th>Type</th><th>Description</th></tr></thead><tbody><tr><td>org_id</td><td>string</td><td>The Organization ID</td></tr><tr><td>type</td><td>string</td><td>aws / azure / gap</td></tr><tr><td>name</td><td>string</td><td>Credential Name</td></tr><tr><td>specific</td><td>Dict(string)</td><td>AWS:<br>{"role": ""}<br>Azure:<br>{"tenant": "", "clientId": "", "key": ""}<br>GCP:<br>{"project": ""}</td></tr><tr><td>comments</td><td>string</td><td>Descriptive comments</td></tr></tbody></table>

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": "Credential created"
}
```

{% endtab %}
{% endtabs %}

## Remove credential

<mark style="color:green;">`POST`</mark> `/`/v1/organizations/credentials/delete?action=remove\_credential

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name           | Type   | Description         |
| -------------- | ------ | ------------------- |
| org\_id        | string | The Organization ID |
| credential\_id | string | Credential ID       |
| comments       | string | Remove comments     |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": "Credential removed"
}
```

{% endtab %}
{% endtabs %}

## Credential update

<mark style="color:green;">`POST`</mark> /v1/organizations/credentials/update?action=update\_credential

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name           | Type   | Description         |
| -------------- | ------ | ------------------- |
| org\_id        | string | The Organization ID |
| credential\_id | string |                     |
| data           | Dict   |                     |
| reason         | string |                     |

#### data:

| Name     | Type         | Description                                                                                             |
| -------- | ------------ | ------------------------------------------------------------------------------------------------------- |
| name     | string       |                                                                                                         |
| comments | string       |                                                                                                         |
| specific | Dict(string) | <p>AWS:<br>{"role": ""}<br><br>Azure:<br>{"clientId": "", "key": ""}<br><br>GCP:<br>{"project": ""}</p> |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "response": "Credential updated"
}
```

{% endtab %}
{% endtabs %}


# Plans

## List Plans

<mark style="color:green;">`GET`</mark> /v1/organizations/plans/list

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name               | Type   | Description                          |
| ------------------ | ------ | ------------------------------------ |
| action=list\_plans | string | The action (will not be needed soon) |
| org\_id            | string | The Organization ID                  |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "plans": [
    {
      "pauses": [
        {
          
        },
        "id": "string",
        "name": "string",
        "schedule": {
          "start": "string",
          "duration": "string",
          "timezone": "string",
          "days": ["string", "string"]
        }
      ],
      "resources": number
    }
  ]
}
```

{% endtab %}
{% endtabs %}

## Describe Plan

<mark style="color:green;">`GET`</mark> /v1/organizations/plans/describe

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name                  | Type   | Description                          |
| --------------------- | ------ | ------------------------------------ |
| action=describe\_plan | string | The action (will not be needed soon) |
| org\_id               | string | The Organization ID                  |
| plan\_id              | string | The Plan ID                          |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "plan": {
    "id": "string",
    "name": "string",
    "schedule": {
      "duration": "string",
      "start": "string",
      "timezone": "string",
      "days": ["M", "T", "X".....]
    }
    "resources": [
      "id": "string",
      "resource_name": "string",
      "type": "string",
      "status": "string",
      "credential": "string",
      "index": number
    ],
    "dependencies": true/false,
    "state": "string"
  }
}
```

{% endtab %}
{% endtabs %}

## Create Plan

<mark style="color:green;">`POST`</mark> /v1/organizations/plans/create?action=create\_plan

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name        | Type   | Description                                                                                                     |
| ----------- | ------ | --------------------------------------------------------------------------------------------------------------- |
| org\_id     | string | The Organization ID                                                                                             |
| name        | string | Plan name                                                                                                       |
| description | string | Description                                                                                                     |
| timezone    | string | UTC; UTC +1; etc                                                                                                |
| schedule    | map    | <p>{</p><p>  "days": \["M", "T", "X".....], </p><p>  "duration": number,</p><p>   "start": "string"</p><p>}</p> |
| state       | string | active / inactive                                                                                               |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Update Plan

<mark style="color:green;">`POST`</mark> /organizations/plans/update?action=update\_plan

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name       | Type   | Description                                                                                                                                                           |
| ---------- | ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| org\_id    | string | The Organization ID                                                                                                                                                   |
| `plan_id`  | string | The Plan ID                                                                                                                                                           |
| name       | string |                                                                                                                                                                       |
| updates    | map    | <p>{<br>    "timezone": ,</p><p>    "schedule": {</p><p>        "days": \[],</p><p>        "duration": 1-23,</p><p>        "start": 1-23,</p><p></p><p>    }<br>}</p> |
| dependancy | bool   | If the resources will respect a order and are dependant on the previous                                                                                               |
| state      | string | The Plan State                                                                                                                                                        |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "state": 200
}
```

{% endtab %}
{% endtabs %}

## Add Resource

<mark style="color:green;">`POST`</mark> /organizations/plans/resources/add?action=add\_resource\_to\_plan

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

<table><thead><tr><th width="175">Name</th><th width="125">Type</th><th>Description</th></tr></thead><tbody><tr><td>org_id</td><td>string</td><td>The Organization ID</td></tr><tr><td><code>plan_id</code></td><td>string</td><td>The Plan ID</td></tr><tr><td>resource</td><td>map</td><td>{<br>  "resource_id": "string",<br>  "resource_name": "string",<br>  "instanceName": "string",<br>  "type": "string",<br>  "credential": "string",<br>  "status": "string",<br>  "reason": "string",<br>  "region": for AWS only (string),<br>  "resource_group": for Azure only (string)<br>}</td></tr></tbody></table>

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "id": 1,
  "name": "John",
  "age": 30
}
```

{% endtab %}
{% endtabs %}

## Update Resources Order in Plan

<mark style="color:green;">`POST`</mark> /organizations/plans/resources/change-order?action=update\_order

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name              | Type   | Description                    |
| ----------------- | ------ | ------------------------------ |
| `org_id`          | string | The Organization ID            |
| `plan_id`         | string | The Plan ID                    |
| new\_sorted\_list | list   | A sorted list of resources IDs |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Delete Resource

<mark style="color:green;">`POST`</mark> /v1/organizations/plans/resources/remove?action=delete\_resource

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name         | Type   | Description         |
| ------------ | ------ | ------------------- |
| `org_id`     | string | The Organization ID |
| `plan_id`    | string | The Plan  ID        |
| resource\_id | string | The Resource ID     |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Update Resource

<mark style="color:green;">`POST`</mark> /v1/organizations/plans/resources/update?action=update\_resource\_in\_plan

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name            | Type   | Description                   |
| --------------- | ------ | ----------------------------- |
| `org_id`        | string | The Organization ID           |
| `plan_id`       | string | The Plan ID                   |
| resource\_id    | string | The Resource ID               |
| resource\_name  | string | The Resource  Name            |
| region          | string | Optional, in case it is AWS   |
| resource\_group | string | Optional, in case it is Azure |
| status          | string | Status                        |
| credential      | string | The Credential ID             |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Pause Plan

<mark style="color:green;">`POST`</mark> /v1/organizations/plans/update?action=pause\_plan

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Payload**

| Name         | Type   | Description         |
| ------------ | ------ | ------------------- |
| `org_id`     | string | The Organization ID |
| `plan_id`    | string | The Plan ID         |
| pause\_start | string | DD/MM/YYYY          |
| pause\_end   | string | DD/MM/YYYY          |
| reason       | string | The reason          |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}

## Remove Plan Pause

<mark style="color:green;">`POST`</mark> /v1/organizations/plans/update?action=remove\_pause

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name      | Type   | Description         |
| --------- | ------ | ------------------- |
| org\_id   | string | The Organization ID |
| plan\_id  | string | The Plan  ID        |
| pause\_id | string | The Pause ID        |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200
}
```

{% endtab %}
{% endtabs %}


# Jobs

## List Jobs

<mark style="color:green;">`GET`</mark> /v1/organizations/jobs

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name              | Type   | Description                          |
| ----------------- | ------ | ------------------------------------ |
| action=list\_jobs | string | The action (will not be needed soon) |
| org\_id           | string | The Organization ID                  |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "jobs": [
    {
      "plan_name": "string",
      "job_id": "string", 
      "run_date": "string",
      "job_status": number,
      "time_consumed": "string",
      "resources_started": "string",
      "resources_stopped": "string"
    }
  ]
}
```

{% endtab %}
{% endtabs %}


# History

## Organization History

<mark style="color:green;">`GET`</mark> /v1/organizations/history

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**QueryString**

| Name           | Type   | Description                          |
| -------------- | ------ | ------------------------------------ |
| action=history | string | The action (will not be needed soon) |
| org\_id        | string | The Organization ID                  |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "history": [
    {
      "id": "string",
      "date": "string",
      "user": "string", 
      "type": "string",
      "summary": "string"
    }
  ]
}
```

{% endtab %}
{% endtabs %}


# Messages

## Get messages

<mark style="color:green;">`GET`</mark> /v1/organizations/messages

\<Description of the endpoint>

**Headers**

| Name          | Value              |
| ------------- | ------------------ |
| Content-Type  | `application/json` |
| Authorization | `Bearer <token>`   |

**Body**

| Name            | Type   | Description                          |
| --------------- | ------ | ------------------------------------ |
| `org_id`        | string | The Organization ID                  |
| action=messages | string | The action (will not be needed soon) |

**Response**

{% tabs %}
{% tab title="200" %}

```json
{
  "status": 200,
  "messages": [
    {
      "type": "info" / "warning" / "critical",
      "id": "string",
      "date": "string",
      "subject": "string",
      "message": "string"
    }
  ]
}
```

{% endtab %}
{% endtabs %}


# Terms

### **Terms of Service: Limitation of Liability and Use of the Tool**

This document outlines the conditions under which *Cloud Plans* (hereinafter referred to as "the Service") provides virtual machine orchestration to optimize cloud operational costs. By using the Service, the user agrees to the following terms:

#### **1. Nature of the Service and Potential Failures**

The Service is designed to automate the start and stop operations of virtual machines to help reduce cloud infrastructure costs. However, the user acknowledges and accepts that, due to the technical nature of the Service, **occasional failures**may occur. These failures could prevent the correct execution of start or stop actions on virtual machines.

In such cases, the user can access the *Cloud Plans* control panel to:

* Check the status of scheduled jobs ("Jobs").
* Review the hourly execution logs.
* Verify the current state of the managed resources.
* Configure, test, and control a Notifications Channel within *Cloud Plans* to stay informed of errors or failures when they occur.

#### **2. User Responsibility**

The user is solely responsible for configuring appropriate access permissions for the Service, ensuring that it has access only to the resources intended for start and stop operations. Misconfigured permissions that impact unrelated resources are entirely the user's responsibility.

Additionally, the user is responsible for monitoring the Service, maintaining its configuration, and assessing the risks associated with its usage.

#### **3. Security of the Service**

*Cloud Plans* is built using **Cloud Native** technologies and employs **highly secure tools** to ensure the protection of stored information. Data at rest is encrypted using industry-standard encryption mechanisms.

Where possible, the Service prioritizes the use of passwordless and native SDK authentication methods. However, for *Azure* integrations, it is not yet possible to implement a fully passwordless solution. As a result, information related to the Service Principal data (Client ID and Private Key) is **double encrypted** to maximize security.

The Service does not maintain a traditional user database. All user-related information is securely managed through a specific AWS service, ensuring that privacy is not compromised.

Cloud Plans uses AWS Cognito as the Identity Service; Cognito operates under the AWS Shared Responsibility Model and complies with security standards like GDPR, HIPAA, SOC, ISO, and PCI DSS.

#### **4. Limitation of Liability**

*Cloud Plans* is not liable for damages, losses, or disruptions arising from the use of the Service, including but not limited to:

* Errors or misconfigurations by the user.
* Occasional failures in executing scheduled start or stop operations.
* Impacts on unintended resources due to user misconfiguration of permissions.
* Any misuse of the Service by the user.

By using the Service, the user agrees to this limitation of liability.

#### **5. User Supervision and Control**

The user has full access to the *Cloud Plans* control panel to:

* Verify the current state of the resources managed by the Service.
* Review hourly logs and execution records for scheduled jobs.
* Adjust configurations or correct errors if any inconsistencies are detected.

#### **6. Disclaimer of Warranties**

The Service is provided "as is" and "as available." *Cloud Plans* makes no guarantees regarding the continuity, availability, or error-free performance of the Service. The user acknowledges that interruptions or technical failures may occasionally occur due to the inherent limitations of cloud orchestration tools.

#### **7. Acceptance of Terms**

By using *Cloud Plans*, the user confirms that they have read, understood, and accepted these terms and agree to assume full responsibility for the use of the Service.


