EyrieHQ combines cloud monitoring, full-stack observability, and secure JIT access control in one open-source platform. Start with AWS — expand anywhere.
A unified dashboard with drag-and-drop metric panels for every AWS service you run. Databases, clusters, caches, load balancers, queues — all with live CloudWatch metrics, auto-refresh, and customizable layouts per user.
Collect logs, metrics, and traces from any server — cloud or bare metal. Deploy the lightweight EyrieHQ Agent powered by OpenTelemetry, and stream telemetry data into a unified view. No vendor lock-in, no per-host pricing.
A modular connector architecture that organizes plugins by domain. The AWS Connector ships with 12 plugins covering compute, databases, networking, security, and cost. The Observability Connector provides log search, metrics exploration, and distributed tracing. Each connector auto-discovers plugins at startup — activate what you need from the admin panel.
Sensitive AWS services — Secrets Manager, Cost Explorer, IAM, SES — are locked by default. Engineers see that a resource exists, but the live data requires an explicit access request. A manager approves, AWS STS issues scoped temporary credentials, and access auto-expires. No standing privileges. No manual cleanup.
Three built-in roles — Employee, Manager, and Admin — each with granular permissions scoped to specific AWS services. Admins manage user roles and plugin activation. Managers can approve access requests.
Built-in multi-factor authentication using time-based one-time passwords (TOTP). Users can enable MFA from their profile, scan a QR code with any authenticator app, and verify codes. Admins can enforce MFA across the org.
Built-in Cost Explorer plugin gives you monthly cost summaries with service-level breakdown and trend analysis. See exactly what you are spending, by service, by account — without leaving EyrieHQ.
EyrieHQ is open-source and free. Deploy it in minutes with Docker Compose.