Log Provider Connector Permissions
For setup, see Debugging.
Gloria stores only read-only credentials and never stores log content. Enter each credential once on the dashboard’s Logs settings tab; do not send it through chat or MCP tool arguments.
cloudwatch
| Credential | Action | Scope | Notes |
|---|---|---|---|
| Read-only IAM user/keypair | logs:DescribeLogGroups | * | Gloria uses this action to list available log groups. |
| Read-only IAM user/keypair | logs:FilterLogEvents, logs:StartQuery, logs:GetQueryResults, logs:StopQuery | Configured log-group ARNs | Gloria uses these actions to read and query the mapped log groups. |
cloudflare-workers
| Credential | Minimum scope | Notes |
|---|---|---|
| Scoped Cloudflare API token | Workers Observability read access | Gloria uses this token for Workers logs. |