# Cloud environments

Connect a cloud environment and Eraser draws architecture diagrams from the infrastructure you actually have deployed. There are three steps to it.

## 1. Connect

You create a read-only credential in your own console and paste one or two values back into Eraser. It takes a few minutes, and each provider has its own walkthrough:

* [Connecting AWS](/connecting-aws) – an account, or an organization
* [Connecting Azure](/connecting-azure) – a subscription, or a whole tenant
* [Connecting Google Cloud](/connecting-google-cloud) – a project, or an organization or folder

At the end you pick which environments to import.

## 2. Scan

Eraser reads the environment and builds an inventory of what is deployed and how it connects. The first scan runs when you connect; after that, scans run on demand from **Settings → Cloud connect**.

## 3. Diagram

Reference an active connection in AI chat and ask for what you want – a VPC, a service, the whole account. See [Diagrams from your cloud](/cloud-diagrams).
