Log Provider Connector Permissions

Log Provider Connector Permissions

For setup, see Debugging.

Gloria stores only read-only credentials and never stores log content. Enter each credential once on the dashboard’s Logs settings tab; do not send it through chat or MCP tool arguments.

cloudwatch

CredentialActionScopeNotes
Read-only IAM user/keypairlogs:DescribeLogGroups*Gloria uses this action to list available log groups.
Read-only IAM user/keypairlogs:FilterLogEvents, logs:StartQuery, logs:GetQueryResults, logs:StopQueryConfigured log-group ARNsGloria uses these actions to read and query the mapped log groups.

cloudflare-workers

CredentialMinimum scopeNotes
Scoped Cloudflare API tokenWorkers Observability read accessGloria uses this token for Workers logs.

See also