Overview
iControl: Enabling the Enterprise Control Center
iControl delivers real-time business flow observability, offering insights to leaders from CXOs down to on-ground operations teams into business-relevant controls by creating meaningful views from both business and technology perspectives. It brings your entire organization onto a single page and enables proactive action in areas that ultimately impact overall business outcomes.
Value for AWS Customers: End-to-End Visibility: Gain a clear understanding of when and where critical business controls are being breached.
Break Elimination & Flow Optimization: Identify and eliminate process breaks, optimizing the end-to-end business flow.
Critical SLA Chain Management: Understand and manage crunch points to proactively improve performance.
Regulatory Trust: Demonstrate full control over operations, building trust with regulators.
Value-Based Outcomes: Enhance the quality and reliability of deliverables to customers.
Proactive Alerts: Receive real-time alerts to prevent business impacts before they occur.
Operational Stability: Increase the stability of business operations, ensuring product cut-offs and deadlines are consistently met.
Additional Benefits: a. Initiatives: Identify where failures occur most frequently and implement AI-driven strategies for a transformational approach to risk and compliance.
b. Operational Connections: Enable visibility into control performance from the operational level up to the CXO suite.
Highlights
- End-to-End Business Observability: Achieve full business observability with real-time visibility into control points, helping teams identify and resolve bottlenecks efficiently.
- Real-Time Control Monitoring & SLA Compliance: Enable real-time control monitoring and ensure SLA compliance with proactive alerts across your business-critical workflows.
- Process Visibility for Regulatory & Operational Confidence: Gain comprehensive process visibility to support regulatory requirements and maintain operational stability across enterprise functions.
Details
Unlock automation with AI agent solutions

Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
As per the terms and conditions in EULA.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
HCL iControl Helm Chart v4.1.1
- Amazon EKS
- Amazon EKS Anywhere
Helm chart
Helm charts are Kubernetes YAML manifests combined into a single package that can be installed on Kubernetes clusters. The containerized application is deployed on a cluster by running a single Helm install command to install the seller-provided Helm chart.
Version release notes
iContorl Release 4.1.1
Additional details
Usage instructions
HCL iControl Helm Deployment Guide
Prerequisites
- Kubernetes cluster running on AWS EKS or self-managed Kubernetes cluster
- Helm v3.8 or higher installed
- kubectl configured to communicate with your cluster
- Before installing HCL iControl, you must create an IAM role and Pod Identity associations for proper AWS service access.
- Create a namespace for iControl
Installation Steps
- Step 1: Create an IAM Role for Pod Identity assocaitions
Create IAM role with EKS Pod Identity trust policy. Attach CloudWatchReadOnlyAccess and custom policies for SQS, SNS, S3, Route53, Secrets Manager access.
-
Step 2: Create Service accounts for applications icontrol-api
icontrol-metric-processor
icontrol-metrics-producer -
Step 3: Create Pod Identity Associations
Create 3 associations linking your IAM role to service accounts icontrol-api, icontrol-metric-processor, icontrol-metrics-producer in icontrol namespace.
- Step 4: AWS SQS and SNS Queue Setup Create required messaging infrastructure for HCL iControl metrics processing.
SNS/SQS: Create 3 SNS topics (metrics, observations, target-performance) and corresponding SQS queues. Subscribe queues to appropriate topics for message processing.
- Step 5: Update Helm Values When installing, you'll need to configure these ARNs in your values file or override parameters:
Note: Replace all placeholder names (your-icontrol-*) with your preferred naming convention. Ensure your IAM role has permissions for all SNS topics and SQS queues created above.
**** Custom values.yaml file****
global: image: pullPolicy: IfNotPresent persistence: enabled: true storageClassName: "gp2" # Change to your preferred storage class cloud: provider: "aws" aws: region: "us-east-1" profiles: - marketplace # Replace ARNs with your actual values metricsProducer: topic: "arn:aws:sns:YOUR-REGION:YOUR-ACCOUNT-ID:your-icontrol-metrics-topic" api: environment: values: OBSERVATION_PUBLISHER: "arn:aws:sns:YOUR-REGION:YOUR-ACCOUNT-ID:your-icontrol-observations-topic" ALLOW_HTTP_BASIC_AUTH: "true" rateLimits: enabled: false tpm: environment: values: OBSERVATION_PUBLISHER: "arn:aws:sns:YOUR-REGION:YOUR-ACCOUNT-ID:your-icontrol-observations-topic" TARGET_PERFORMANCE_PUBLISHER: "arn:aws:sns:YOUR-REGION:YOUR-ACCOUNT-ID:your-icontrol-target-performance-topic" metricProcessor: serviceAccount: create: false name: icontrol-metric-processor environment: values: METRIC_SUBSCRIBER: "<https://sqs.YOUR-REGION.amazonaws.com/YOUR-ACCOUNT-ID/your-icontrol-metrics-processor-queue>" OBSERVATION_PUBLISHER: "arn:aws:sns:YOUR-REGION:YOUR-ACCOUNT-ID:your-icontrol-observations-topic" keycloak: addLocalUsers: enabled: true defaultRealms: realms: icontrolKeycloak: internalLdap: enabled: false localUsers: password: "your-secure-password" admin: password: "your-admin-password" ingress: enabled: true className: nginx annotations: # Add your ingress-specific annotations here hosts: web: forceHttpsConnectionUrl: true name: "your-icontrol-web-domain.example.com" api: name: "your-icontrol-api-domain.example.com" keycloak: name: "your-icontrol-keycloak-domain.example.com"- Step 5: Configure AWS CLI authentication
aws ecr get-login-password --region us-east-1 | helm registry login --username AWS --password-stdin 709825985650.dkr.ecr.us-east-1.amazonaws.com
helm pull oci://709825985650.dkr.ecr.us-east-1.amazonaws.com/icontrol --version 4.1.1 tar -xzf icontrol-4.1.1.tgz
helm install icontrol ./icontrol
-f ./icontrol/custom-values.yaml
-n icontrol
--set cloud.aws.region=us-east-1
Detailed explanation of all Helm chart values is available on chart/icontrol/README.md. If you contact with our marketing team you should also receive extended instructions.
Resources
Vendor resources
Support
Vendor support
For support, please contact HCL Software Support https://support.hcltechsw.com/Â
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

