> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Discover resources

> Turn cloud-discovered destinations into reviewed, protected Resources.

Forge can suggest Resources from connected cloud inventory. Endpoint network
traffic is not used for Resource discovery. A suggestion is evidence to review,
not an automatically active proxy definition. Protecting it never invents a
credential, policy, Gateway assignment, or user access.

## Discovery sources

### AWS RDS and Aurora

The existing AWS inventory sync can suggest PostgreSQL and MySQL endpoints from
RDS and Aurora. Add these read-only permissions to the inventory role:

```json theme={"system"}
{
  "Effect": "Allow",
  "Action": ["rds:DescribeDBInstances", "rds:DescribeDBClusters"],
  "Resource": "*"
}
```

Forge records the AWS account, Resource ARN, endpoint role, engine, Region,
hostname, port, TLS requirement, and safe labels. It imports instance endpoints
and Aurora writer and reader endpoints. It does not import a database
credential or retain the raw AWS response.

A missing permission is reported as partial Resource discovery without failing
the rest of AWS AI inventory. A partial run does not mark earlier endpoints as
missing.

## Review a suggestion

Open a row marked **Discovered** and verify:

* the human-readable name;
* protocol, destination host, and port;
* discovery source and last observation;
* destination encryption and private authority;
* the Resource Gateway that can reach it; and
* whether managed devices should use automatic routing.

Choose **Protect resource** to create a normal Resource, or **Ignore** to dismiss
the suggestion. Ignored suggestions remain available through the State filter.

The State filter also includes **Update available** when a discovered endpoint
has changed since protection and **Source missing** when the integration no
longer reports it. Neither state silently rewrites or deletes the protected
Resource. Review the current destination and source before accepting an update
or deciding that the Resource should be disabled.

For bulk review, select suggestions on the current page and choose **Protect**
or **Ignore** once. Bulk-protected Resources retain the reviewed destination
and name, start without automatic routing, and receive no credentials,
policies, or access assignments. Open an individual suggestion when you need to
select those settings during protection.

## After protection

Assign a Resource Gateway, add a credential, test connectivity, and create a
Resource Policy. Enable automatic routing only after the Resource is ready to
serve traffic. The Resource page links directly to its policies and filtered
activity.

See [Configure Resources and routing](/resources/configure-resources-and-routing) for the
remaining setup.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.