CloudMapper is a FIPS 140-2 compliant AWS network topology visualizer for air-gapped environments. Generate interactive network diagrams of VPC infrastructure with multi-region support, 2FA authentication, and read-only IAM permissions for secure network documentation and compliance reporting.
CloudMapper is a professional-grade AWS network topology visualization tool designed specifically for security-conscious enterprises operating in air-gapped, FIPS 140-2 compliant environments. Built by Buckshot Technologies, CloudMapper transforms complex VPC infrastructure into clear, interactive network diagrams that document network architecture across single or multiple AWS regions. The solution provides comprehensive visibility into VPC components including subnets, route tables, internet gateways, NAT gateways, transit gateways, VPC peering connections, and VPC endpoints, making it ideal for security audits, compliance documentation, disaster recovery planning, and network troubleshooting.
Security is at the core of CloudMapper's design. The application is distributed as a hardened Amazon Linux 2023 AMI with SSM-only access (SSH disabled by default), enforces FIPS 140-2 cryptographic standards, and operates with read-only IAM permissions to ensure zero impact on your AWS infrastructure. Multi-factor authentication (2FA) using TOTP is mandatory for all users, with optional OIDC integration for enterprise single sign-on. Password policies enforce 12-character minimum complexity requirements, and automatic expiration handling to maintain security compliance.
CloudMapper operates entirely within your AWS account with no external dependencies or data transmission, making it perfect for government, healthcare, financial services, and other regulated industries requiring air-gapped deployments. The intuitive web interface requires no training, supports both light and dark modes for comfortable viewing, and generates diagrams that can be exported for documentation or shared with stakeholders. Whether you're documenting network architecture for compliance audits, troubleshooting connectivity issues, or planning infrastructure changes, CloudMapper provides the visibility and security your organization demands.
Highlights
FIPS 140-2 Compliant & Air-Gapped Security - Hardened Amazon Linux 2023 AMI with 2FA authentication, OIDC integration, SSM-only access, and read-only IAM permissions. Operates entirely within your AWS account with zero external dependencies, perfect for government, healthcare, and financial services compliance requirements.
Comprehensive Multi-Region VPC Visualization - Generate interactive network diagrams of your AWS network topology including VPCs, subnets, route tables, internet gateways, NAT gateways, transit gateways, VPC peering connections, and VPC endpoints. Document infrastructure across single or multiple AWS regions for security audits and compliance reporting.
Enterprise-Ready, deploy in minutes using our CloudFormation template.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on a fixed subscription cost and actual usage of the product. You pay the same amount each billing period for access, plus an additional amount according to how much you consume. The fixed subscription cost is prorated, so you're only charged for the number of days you've been subscribed. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour for the EC2 instance size you run CloudMapper on. The nine dimensions map to different instance types, so pricing scales with the compute you choose. The t3 family (small, medium, large, xlarge, 2xlarge) covers general-purpose needs at graduated sizes. The m5 and m6i families (large and xlarge) suit larger workloads. You select one instance type per deployment. Larger instances carry higher hourly rates. There is no upfront commitment; billing runs on usage. The software license bills alongside your chosen instance's hourly rate.
Top-of-mind questions for buyers
What do I actually get for each hourly instance dimension?
Each dimension runs CloudMapper on one EC2 instance of that size. The t3 sizes cover general-purpose workloads. The m5 and m6i sizes suit larger workloads. All are x86_64. One instance visualizes a single AWS account across selected regions. The instance uses a read-only IAM role for automatic network discovery.
Am I charged when the CloudMapper instance is stopped?
The software license meters running instance-hours. A stopped instance stops accruing hourly software charges. You may still pay underlying AWS storage fees for the attached EBS volume, which the CloudFormation template encrypts and keeps by default. Restarting the instance resumes hourly software billing.
Can one instance cover multiple AWS accounts, or do I need several?
Each instance operates within a single AWS account only. It does support multiple regions in that account, configured through the web interface. To visualize separate accounts, you run separate instances, each billed at its own hourly rate. Multi-account support is planned for future releases.
buckshottech.com+2
Helpful?
Vendor refund policy
All sales are final and non-refundable. Cancel anytime via AWS Marketplace; access continues through current billing period.
Contact support@buckshottech.com for technical issues.
Refunds considered only for billing errors or unresolvable technical problems within 7 days of purchase. Submit requests with AWS account ID and details within 30 days to support@buckshottech.com.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial launch of CloudMapper supports:
FIPS Compliance
TLS1.2/SSL ONLY Access
SSM and SSH Access (ec2-user only)
Self Signed Certificate generation for SSL ONLY access (ssh port 22 is optional)
Multi Region Network Diagramming
VPC, Public and Private Subnets, Transit Gateways (with peers), VPC Peering, NAT Gateways, Internet Gateways, VPCEs - all supported in diagrams and auto discovered
OIDC SSO Support
2FA Authentication
Strong Password Requirments (12 character, alpha numeric, no repeat of password)
If you provide a key then the ec2-user will have ssh access otherwise the SSM agent is enabled and you can connect through the console.
The app runs on port 443 and will redirect port 80 to 443. Your security group inbound rule should allow tcp port 443 (https) and optionally tcp port 22(ssh) if a key is associated to the instance. Your security group outbound rule should allow tcp 443 (https) to connect to aws apis including systems manager.
You will need to add an EC2 Instance Role that has the following policies:
- arn:aws:iam::aws:policy/ReadOnlyAccess
- arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore
What's Included (Free Community Support):
GitHub Issues for bug reports and technical questions
GitHub Discussions for community Q&A and feature ideas
Comprehensive online documentation and installation guides
Troubleshooting articles and best practices
Public issue tracking and resolution history
Community-driven support (24-48 hour response time)
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.