5 min read

Automated AWS Network Topology Diagram with AI

Connect AWS and Obelinf to an AI assistant, inventory cloud network resources, and turn verified records into an AWS network topology diagram.

ByAndré Ribeiro· Founder, Obelinf
Automated AWS Network Topology Diagram with AI
Automated AWS Network Topology Diagram with AI · September 23, 2026
On this page

An AWS network topology diagram is useful only when it reflects the infrastructure that is actually deployed. Drawing VPCs, subnets, instances, and connections by hand can take hours, and a static diagram begins to drift as soon as the account changes. You can reduce that manual work by asking an AI assistant to inspect AWS and create structured infrastructure records from what it can verify.

This tutorial connects an AI assistant to AWS and Obelinf through MCP. AWS remains the read only source for discovery, while Obelinf stores the documented resources and renders their relationships as a topology. It is an agent assisted documentation workflow, not a live network scanner, so review the records and connections before relying on the diagram.

What the AWS to Obelinf workflow does

The assistant acts as the bridge between two systems. An AWS MCP connection lets it query the services allowed by your AWS identity. An Obelinf MCP connection lets it create infrastructure documentation in the organization you choose. The assistant translates verified AWS details into sites, devices, subnets, interfaces, and relationships that Obelinf can represent.

The important distinction is that AWS does not directly generate the Obelinf diagram. The assistant reads AWS, writes the relevant records, and Obelinf visualizes those records. If a relationship cannot be confirmed from available AWS data, leave it undocumented rather than asking the model to guess.

Obelinf AWS topology showing a managed Kubernetes cluster and application, database, worker, and load balancer instances across us-east-1 availability zones
An AWS infrastructure topology documented in Obelinf, with resources across multiple us-east-1 availability zones.

Prepare access before connecting

Use an AWS identity dedicated to documentation. Grant it only the read permissions needed for the services in scope. For a first pass focused on VPC and EC2 inventory, a policy can allow the relevant ec2:Describe* actions. If you also need Direct Connect details, add the relevant directconnect:Describe* actions. Expand the list only when the inventory requires another AWS service.

For example, this starter policy allows description calls for EC2 and Direct Connect resources. It is read only, but still broad within those services, so narrow it further if your environment allows it:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["ec2:Describe*", "directconnect:Describe*"],
      "Resource": "*"
    }
  ]
}

The AWS MCP Server forwards requests under your AWS identity, and AWS evaluates that identity’s existing permissions. OAuth allows a quick browser based connection, while the SigV4 proxy is the better choice when you want read only mode to hide write capable tools or need multiple AWS profiles. OAuth also requires the IAM identity to have the AWSMCPSignInOAuthAccessPolicy. That policy authorizes the connection, while separate service permissions control which resources the assistant can read. In either case, use IAM to prevent writes. A sentence in an AI prompt is not an access control.

For Obelinf, create a separate API and MCP key for this workflow. The assistant must be able to write documentation, so choose Full Access only for the organization you intend to populate. Full Access also permits updates and deletions, so require your approval before write calls and do not rely on the prompt as the only safeguard. Keep the key private, store it in your MCP client’s secret storage where possible, and revoke it when the workflow is no longer needed. Obelinf records changes in the changelog, which gives you a way to review what the agent created.

Connect Claude to AWS

AWS currently offers a managed AWS MCP Server. For Claude Code, the quick OAuth connection uses the AWS endpoint and a browser authorization step:

claude mcp add aws-mcp https://aws-mcp.us-east-1.api.aws/mcp --transport http

For Claude Desktop, add the remote server URL https://aws-mcp.us-east-1.api.aws/mcp?oauth=initialize in the MCP settings. The first tool call opens AWS Sign in so you can authorize the identity. If your organization prefers local AWS credentials, use the SigV4 setup in the AWS MCP Server guide instead. The AWS guide lists the current supported regions, client instructions, and permission model, so check it before configuring a different client.

After connecting, ask the assistant to confirm the AWS account identity and which regions it can query. Limit the first inventory to a specific account, region set, and service list. A focused scope makes the output easier to validate and reduces the chance that relevant resources are missed in an unbounded request.

Connect Obelinf and verify both servers

In Obelinf, open API & MCP, create a key for this task, and copy the client configuration shown after creation. That generated configuration includes the current server details for the selected organization. Add it to the same Claude client where AWS MCP is already configured, then restart or reload the client if required.

Before asking the assistant to write anything, verify both connections separately. Ask it to identify the AWS account and list a few permitted resources. Then ask it to report the Obelinf organization name and available MCP tools. If either answer points to the wrong account or organization, stop and correct the connection before continuing.

Obelinf API and MCP new key form with the AWS Claude Connector name and Full Access permission selected
Create a dedicated Obelinf API and MCP key for the AWS documentation workflow. The key value is not shown.

Inventory AWS and create the topology records

Start with a plan that names the account, regions, and resource types to inspect. For a basic network view, include VPCs, subnets, route tables, gateways, network interfaces, and EC2 instances. Add Direct Connect, transit gateways, VPNs, load balancers, or other services when they are relevant and the AWS identity can read them. Ask the assistant to report permission errors rather than silently omitting resources.

Use a prompt with explicit guardrails, such as:

Use the AWS MCP server as a read only source. Never create, modify, stop, or delete AWS resources.
Inventory the VPC and network resources in account ACCOUNT_ID across REGIONS.
Before writing, show me the proposed Obelinf sites, devices, subnets, interfaces, and relationships.
Use only attributes and connections supported by the AWS results. Do not guess missing values.
Check Obelinf for matching records before creating anything. Do not delete or overwrite existing records.
Wait for my approval before writing the proposed batch to Obelinf.
After approval, create the records in manageable batches and summarize successes, omissions, and errors.
Compare the saved records with the AWS inventory and list anything that could not be represented.

Review the proposed mapping before approving writes. AWS services do not always correspond one to one with physical network entities, and the fields available through an API vary by resource type. Keep cloud objects in the appropriate inventory records and only draw an edge when AWS provides evidence for that relationship. Obelinf’s network topology view is generated from the device and connection records you maintain.

Validate and maintain the diagram

When the assistant finishes, compare its summary with the AWS resource list. Check region coverage, duplicate names, subnet CIDRs, device types, and each proposed relationship. Open the topology view and confirm that the structure matches the documented records. Correct errors in the records, then regenerate or refresh the view as needed.

Obelinf topology view with AWS availability zones, a Kubernetes cluster, cloud instances, backbone networks, and transit circuits across multiple regions
Example of AWS infrastructure records visualized in Obelinf's topology view.

Treat the result as a documentation snapshot, not continuous discovery. AWS changes do not automatically update Obelinf unless you run the inventory workflow again or build a scheduled integration. Keep each run scoped, review changes before they are written, and inspect the changelog afterward. For more on the platform’s agent workflow, see AI infrastructure documentation and device inventory.

When this approach fits

An AI assisted import is useful when you want to turn existing cloud inventory into a browsable network reference without manually entering every record. It can also give your team a consistent first draft to review. It is not a substitute for AWS configuration monitoring, flow analysis, or a live discovery product. Choose the workflow based on whether you need a maintained inventory, operational telemetry, or both.

Obelinf’s free Personal plan includes core infrastructure records and topology for small environments. See Obelinf pricing for current plan limits. If you are comparing dedicated mapping products as well, our best network topology tools guide explains how documentation based topology differs from discovery and monitoring tools.

Frequently Asked Questions

Can AI create an AWS network topology diagram automatically?
An AI assistant can inspect AWS resources through an MCP connection, then create structured records in a topology tool. Obelinf generates its diagram from those records, so you should review resource relationships instead of treating the result as live network discovery.
What AWS permissions should an AI assistant have?
Start with a dedicated IAM identity that can only describe the AWS services you intend to inventory. The AWS MCP Server uses the identity's permissions for downstream calls, so do not rely on a prompt alone to prevent changes.
Can this workflow change my AWS infrastructure?
The workflow should use read only AWS permissions and a prompt that forbids AWS changes. Those IAM permissions enforce the boundary. The assistant needs write access only on the Obelinf side to create documentation records.
Does Obelinf scan AWS to discover network connections?
No. An AI assistant uses the AWS MCP tools to inspect resources and then writes supported, verified records to Obelinf. Obelinf creates a topology view from documented devices and relationships, not from a live scan of AWS.

Stop reaching for a spreadsheet

Obelinf keeps every subnet, device, circuit, and rack in one live source of truth, with audit logs and a topology view. Free for personal use.

Related Articles