1-Click CloudFormation Deploy

Deploy the Cloud Spectra Gateway

Pick a tier, configure every stack parameter on this one clean page -- with a live architecture diagram that updates as you go -- then launch straight into the AWS CloudFormation console in the region you choose, settings pre-filled.

1

Subscribe to the AMI

Subscribe to your Cloud Spectra tier on the AWS Marketplace (one-time, per account).

2

Configure below

Click a quick-start profile for instant sensible defaults, or pick a tier and tune the grouped form. A live architecture diagram tracks your choices.

3

Launch to AWS

Click Launch in CloudFormation. You land on the AWS quick-create page, pre-filled.

4

Create stack

Review on AWS, check the IAM box, click Create stack. Live in ~10 minutes -- dashboard on HTTPS :9443.

Fastest path: pick a quick-start profile below, then click Launch. Everything else is optional -- safe defaults are pre-filled, and you can change any feature later from the dashboard.

Configure your deployment

Parameters are grouped by function. Green groups are the essentials; purple are optional features (off by default). Hover any ?Help tooltips like this explain each parameter, including its underlying CloudFormation parameter name. for details. You always finish and submit on the AWS console.

Quick-start profilesone click sets the tier, sizing and features -- tweak anything after
No profile applied -- configure manually below, or pick a starting point above.
Essentialstier, target, network, placement, compute
Selects the release CloudFormation template and its Marketplace AMI. "latest" pins the newest published template and floats the AMI to the newest image at launch.
per vCPU / month$8
On-demand~$16/mo
Annual (-25%)~$12/mo
Cloud Spectra software fee per single running instance (est., c6in.large) -- billed hourly per vCPU through AWS Marketplace, on top of your EC2/EBS cost, and excludes data transfer. No minimum and no per-GB data-processing fee; vCPU counts above 128 are not billed. A multi-AZ fleet bills per instance across zones. See full pricing ->
The matching AMI for your tier and version is selected automatically per region.
Becomes part of every resource name. Use a different name per stack in the same account/region.
VPC mode ?Create a brand-new VPC, or wire Cloud Spectra into an existing one. With "Existing", Cloud Spectra adds its own subnets, route tables and ENIs to the VPC you select. newOrExistingVpc
A /16 gives plenty of room for per-AZ subnets. Must not overlap VPCs you intend to peer with.
For production, restrict this to your admin network rather than 0.0.0.0/0.
Restrict to specific spoke VPC CIDRs to tighten the transit security group.
1-65535. Keep the default unless you front the gateway with a load balancer on 443.
💡

The first AZ letter is the master AZ created by the template; any additional letters are non-primary AZs the gateway reconciles at runtime. Each enabled AZ gets its own subnet, ENI, route table and Auto Scaling Group -- an independent gateway -- so the fleet scales out across AZs for HA. This is a first-boot seed only; the dashboard / API / Terraform are the source of truth thereafter.

Full AZ names for your region. First = master AZ. e.g. us-east-1a,us-east-1b
Auto-resolved from the selected Tier + Version (an SSM parameter CloudFormation resolves per Region). No AMI ID to enter.
Start small; resize later from the dashboard.
Min / Desired / Max per AZ ?Auto Scaling Group sizing per AZ. The stack supports 0 or 1 instance per AZ at deploy time; multi-instance-per-AZ is configured afterward from the Cloud Spectra dashboard or API. asg0000minSize / asg0000desiredCapacity / asg0000maxSize
Min / Desired / Max (each 0-1). For multiple instances per AZ, scale from the dashboard after deploy.
Warm pool ?Pre-initialized standby instances per ASG for fast scale-out (~25s vs ~90s cold launch). Disabled by default. When enabled, choose how many standby instances and whether they are Stopped (cheapest) or Running (fastest). Warm pools make horizontal scale-out fast -- the only way past a single box's throughput ceiling -- and pairing elastic right-sizing with spot is what makes running the data plane yourself cheaper than both an always-on fixed appliance and the managed cloud meter. asg0000warmPoolDisabled / asg0000warmPoolMinSize / asg0000warmPoolState
Disabled / Enabled · min standby (0-10) · Stopped or Running.
Features (optional)off by default -- expand to enable
💡

When a port-forwarding rule is submitted with externalPort=0, the gateway auto-allocates a free port from this range and opens it in the security group -- ideal for WireGuard tunnels dialed in from on-prem sites behind NAT.

Leave empty to keep the dial-in range closed until you add sources later.
Leave empty to skip firewall sync at deploy time.
Operations & Advancedupgrades, admin, developer
Leave empty to pin to the AMI's built-in version.
Keep the default unless you self-host the release bucket.
🔑

For your security, the admin password is never placed in a launch URL. Leave it blank to auto-generate a strong initial password (retrievable via SSH), or type it in the masked access0000passwordBcrypt field on the AWS console page -- either a plaintext password (min 8 chars: upper/lower/digit/special) or a pre-computed bcrypt hash. A plaintext value is bcrypt-hashed at deploy time, so only the hash is ever written to SSM.

Blank = AWS-managed aws/ebs key.
Leave blank to auto-generate a strong password.
Blank = no OS password (the secure default). Format user:password.
Feature configurationoptional -- every shipping feature, filtered by tier
🔧

Everything below is optional and set to safe defaults. Whatever you change is bundled into a single first-boot configuration overlay (nothing here needs a dedicated CloudFormation field), so this page configures every feature your tier ships -- no dashboard round-trip needed. You can still change any of it later from the dashboard, API or Terraform.

💡

One AMI serves ALL bundled apps. Choose a single App, OR a Bundle (metrics = Prometheus+Grafana, logs = OpenSearch+Dashboards+Fluent Bit), OR list an explicit Desired Apps set. Precedence: Desired Apps > Bundle > App. The tier runs one multi-AZ single-instance ASG that scales vertically and rides Spot.

Schema default: grafana. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: 0.75. Blank keeps it.
Schema default: 0.3. Blank keeps it.
Schema default: strict. Blank keeps it.
Schema default: 60. Blank keeps it.
Schema default: cloudspectra/elastic. Blank keeps it.
Schema default: 8090. Blank keeps it.
Schema default: openai. Blank keeps it.
Schema default: https://api.openai.com. Blank keeps it.
Schema default: https://api.anthropic.com. Blank keeps it.
Schema default: us-east-1. Blank keeps it.
Schema default: 3600. Blank keeps it.
Schema default: 0.9. Blank keeps it.
Schema default: 5000. Blank keeps it.
Schema default: 60. Blank keeps it.
Schema default: 24. Blank keeps it.
Schema default: 24. Blank keeps it.
Schema default: none. Blank keeps it.
Schema default: self-managed. Blank keeps it.
Schema default: 3129. Blank keeps it.
Schema default: cef. Blank keeps it.
Schema default: stdout. Blank keeps it.
Schema default: tcp. Blank keeps it.
Schema default: ids,audit. Blank keeps it.
Schema default: 1080. Blank keeps it.
Schema default: 1024. Blank keeps it.
Schema default: 256. Blank keeps it.
Schema default: 65536. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: 0. Blank keeps it.
Schema default: on. Blank keeps it.
Schema default: on. Blank keeps it.
Schema default: ut1. Blank keeps it.
Schema default: 64. Blank keeps it.
Schema default: 100. Blank keeps it.
Schema default: none. Blank keeps it.
Schema default: 0.0.0.0/0. Blank keeps it.
Schema default: 0.0.0.0/0. Blank keeps it.
Schema default: 1. Blank keeps it.
Schema default: instanceTypeWeighted. Blank keeps it.
Schema default: 28. Blank keeps it.
Schema default: 1000. Blank keeps it.
Schema default: 500. Blank keeps it.
Schema default: 3. Blank keeps it.
Schema default: 30. Blank keeps it.
Schema default: 10. Blank keeps it.
Schema default: 300. Blank keeps it.
Schema default: /data. Blank keeps it.
Schema default: gp3. Blank keeps it.
Schema default: 100. Blank keeps it.
Schema default: 3000. Blank keeps it.
Schema default: 125. Blank keeps it.
Schema default: ext4. Blank keeps it.
Schema default: 12347. Blank keeps it.
Schema default: 9100. Blank keeps it.
Schema default: 30. Blank keeps it.
Schema default: 15. Blank keeps it.
Schema default: 20. Blank keeps it.
Schema default: 30. Blank keeps it.
Schema default: 2001. Blank keeps it.
Schema default: 22. Blank keeps it.
Schema default: 22. Blank keeps it.
Schema default: admin. Blank keeps it.
Schema default: light. Blank keeps it.
Schema default: english. Blank keeps it.
Schema default: 86400. Blank keeps it.
Ready to launch
Opens the AWS CloudFormation quick-create page with your settings pre-filled. You review and click Create stack on AWS.
Show the generated launch URL

Template: <version>/cloudspectra_gateway_cf_deploy.yaml -- one merged template whose "VPC mode" selector chooses Create-new vs Use-existing (the deploy-page variant, identical to the Marketplace template but resolving the AMI itself) -- served from the per-region releases bucket for the region you pick. You must be signed in to the AWS console for the chosen region. The final Create-stack step (including the IAM capabilities acknowledgement) always happens on AWS -- this page never touches your account.