Skip to main content
Forge can suggest Resources from connected cloud inventory. Endpoint network traffic is not used for Resource discovery. A suggestion is evidence to review, not an automatically active proxy definition. Protecting it never invents a credential, policy, Gateway assignment, or user access.

Discovery sources

AWS RDS and Aurora

The existing AWS inventory sync can suggest PostgreSQL and MySQL endpoints from RDS and Aurora. Add these read-only permissions to the inventory role:
Forge records the AWS account, Resource ARN, endpoint role, engine, Region, hostname, port, TLS requirement, and safe labels. It imports instance endpoints and Aurora writer and reader endpoints. It does not import a database credential or retain the raw AWS response. A missing permission is reported as partial Resource discovery without failing the rest of AWS AI inventory. A partial run does not mark earlier endpoints as missing.

Review a suggestion

Open a row marked Discovered and verify:
  • the human-readable name;
  • protocol, destination host, and port;
  • discovery source and last observation;
  • destination encryption and private authority;
  • the Resource Gateway that can reach it; and
  • whether managed devices should use automatic routing.
Choose Protect resource to create a normal Resource, or Ignore to dismiss the suggestion. Ignored suggestions remain available through the State filter. The State filter also includes Update available when a discovered endpoint has changed since protection and Source missing when the integration no longer reports it. Neither state silently rewrites or deletes the protected Resource. Review the current destination and source before accepting an update or deciding that the Resource should be disabled. For bulk review, select suggestions on the current page and choose Protect or Ignore once. Bulk-protected Resources retain the reviewed destination and name, start without automatic routing, and receive no credentials, policies, or access assignments. Open an individual suggestion when you need to select those settings during protection.

After protection

Assign a Resource Gateway, add a credential, test connectivity, and create a Resource Policy. Enable automatic routing only after the Resource is ready to serve traffic. The Resource page links directly to its policies and filtered activity. See Configure Resources and routing for the remaining setup.