# Connect an AWS provider link

Connect an AWS account to Northflank through a provider link. Choose the features for your task before granting AWS permissions. Available features depend on the provider and your account.

Use the authentication instructions on this page for registry access, OpenTofu, workload identity, or cluster deployment. Connecting the account does not create a cluster. Cluster quotas apply only when you deploy clusters.

For an application that uses AWS resources, read [Connect an app to AWS](https://northflank.com/docs/v1/application/use-cases/connect-an-app-to-aws). For cluster deployment, use [Amazon Web Services on Northflank](https://northflank.com/docs/v1/application/bring-your-own-cloud/aws-on-northflank).

Review [provider-link features](provider-links) before selecting an authentication method.

## Generate and view required permissions

Select the features that your AWS integration needs. Northflank shows the corresponding permissions as a table and an inline policy that you can copy.

For ECR access, select Docker Registries. To push project builds, also select Docker Registry Push. The generated push policy includes permission to create ECR repositories.

For cluster deployment, select BYOC and any required features, such as BYOC - Custom VPC or BYOC - Static Egress. Registry-only integrations do not require these cluster features.

Open an existing provider link under Cloud → Provider links. On its Edit tab, select Verify all permissions under Credentials. If you add features, update the AWS policy to grant their required access.

The following policy is a cluster example with custom VPC and static egress permissions. Use the policy shown in Northflank for your current feature selection.

AWS inline policy

```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "Northflank",
      "Effect": "Allow",
      "Action": [
        "ec2:AllocateAddress",
        "ec2:AssociateRouteTable",
        "ec2:CreateNatGateway",
        "ec2:CreateRoute",
        "ec2:CreateRouteTable",
        "ec2:CreateSubnet",
        "ec2:CreateTags",
        "ec2:DeleteNatGateway",
        "ec2:DeleteRoute",
        "ec2:DeleteRouteTable",
        "ec2:DeleteSubnet",
        "ec2:DescribeAddresses",
        "ec2:DescribeNatGateways",
        "ec2:DescribeRouteTables",
        "ec2:DescribeSubnets",
        "ec2:DescribeVpcs",
        "ec2:DisassociateRouteTable",
        "ec2:ReleaseAddress",
        "eks:AssociateAccessPolicy",
        "eks:CreateAccessEntry",
        "eks:CreateAddon",
        "eks:CreateCluster",
        "eks:CreateNodegroup",
        "eks:DeleteAccessEntry",
        "eks:DeleteAddon",
        "eks:DeleteCluster",
        "eks:DeleteNodegroup",
        "eks:DescribeAccessEntry",
        "eks:DescribeAddon",
        "eks:DescribeCluster",
        "eks:DescribeNodegroup",
        "eks:DescribeUpdate",
        "eks:DisassociateAccessPolicy",
        "eks:ListAccessEntries",
        "eks:ListAccessPolicies",
        "eks:ListAddons",
        "eks:ListAssociatedAccessPolicies",
        "eks:ListClusters",
        "eks:ListIdentityProviderConfigs",
        "eks:ListInsights",
        "eks:ListNodegroups",
        "eks:ListTagsForResource",
        "eks:ListUpdates",
        "eks:TagResource",
        "eks:UntagResource",
        "eks:UpdateAccessEntry",
        "eks:UpdateAddon",
        "eks:UpdateClusterConfig",
        "eks:UpdateClusterVersion",
        "eks:UpdateNodegroupConfig",
        "eks:UpdateNodegroupVersion",
        "iam:AttachRolePolicy",
        "iam:CreateOpenIDConnectProvider",
        "iam:CreateRole",
        "iam:CreateServiceLinkedRole",
        "iam:DeleteOpenIDConnectProvider",
        "iam:DeleteRole",
        "iam:DeleteRolePolicy",
        "iam:DetachRolePolicy",
        "iam:GetOpenIDConnectProvider",
        "iam:GetRole",
        "iam:ListAttachedRolePolicies",
        "iam:PassRole",
        "iam:PutRolePolicy",
        "iam:SimulatePrincipalPolicy",
        "iam:TagOpenIDConnectProvider",
        "iam:TagRole"
      ],
      "Resource": [
        "*"
      ]
    }
  ]
}
```

## Add your account with a cross-account role

A cross-account role grants Northflank access to your AWS account through temporary credentials. Use this method when it is available for your selected features.

> [!note] Requirements
>
> You will need the following to get started:
>
> - Permission to create [IAM roles](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies-cross-account-resource-access.html) and assign their policies in your AWS account
> - For cluster deployment: sufficient [quotas](https://northflank.com/docs/v1/application/bring-your-own-cloud/aws-on-northflank#check-your-quotas) to deploy your cluster

For registry access, select Docker Registries and, for project builds, Docker Registry Push. You do not need to select BYOC unless this integration also manages clusters.

1. Open Cloud → Provider links in Northflank.

2. Open the [AWS provider link form](https://app.northflank.com/s/account/cloud/integrations/new/aws).

3. Under Basic information, enter a Name. Select the features you need under Desired features.

4. In Credentials, select Cross-account role.

5. Select Copy Custom trust policy.

6. Open Roles in the [AWS IAM console](https://console.aws.amazon.com/iam/home).

7. Select Create role → Custom trust policy.

8. Paste the copied policy.

9. Name and save the role.

10. In Northflank, select Copy AWS inline policy under Required permissions.

11. Open the new role's Permissions tab in AWS.

12. Select Add permissions → Create inline policy.

13. Paste the copied policy into the JSON editor. Save the policy with a name.

14. In Northflank, enter the IAM role ARN under Credentials.

15. Select Create provider link.

You can now use the integration for its selected features. To deploy a cluster, continue to [create a cluster](https://northflank.com/docs/v1/application/bring-your-own-cloud/aws-on-northflank#create-a-cluster).

You can update the integration's shared secret and role ARN.

> [!warning] Keep access to existing resources
>
> Keep access to existing resources when you change the role. Without that access, Northflank cannot manage those resources, and deleting clusters directly in AWS can leave unused resources.

## Add your account with an IAM user

You can integrate AWS with an IAM user's access key and secret key. Prefer a [cross-account role](#add-your-account-with-a-cross-account-role) when it supports your selected features, because it uses temporary credentials.

> [!note] Requirements
>
> You will need the following to get started:
>
> - Permission to create [IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html), manage their access keys, and assign policies in your AWS account
> - For cluster deployment: sufficient [quotas](https://northflank.com/docs/v1/application/bring-your-own-cloud/aws-on-northflank#check-your-quotas) to deploy your cluster

For registry access, select Docker Registries and, for project builds, Docker Registry Push. You do not need to select BYOC unless this integration also manages clusters.

1. Open Cloud → Provider links in Northflank.

2. Open the [AWS provider link form](https://app.northflank.com/s/account/cloud/integrations/new/aws).

3. Under Basic information, enter a Name. Select the features you need under Desired features.

4. In Credentials, select Access key.

5. Select Copy AWS inline policy under Required permissions.

6. Open Users in the [AWS IAM console](https://console.aws.amazon.com/iam/home).

7. Create and save a user without console access.

8. Open the user's Permissions tab.

9. Select Add permissions → Create inline policy.

10. Paste the copied policy into the JSON editor. Save the policy with a name.

11. Under Security credentials, select Create access key.

12. Select the Third-party service use case and continue.

13. Enter a description for the access key. Select Create access key.

14. In Northflank, enter the Access key and Secret key under Credentials.

15. Select Create provider link.

You can update the integration's credentials when required.

> [!warning] Keep access to existing resources
>
> Keep access to existing resources when you replace credentials. Without that access, Northflank cannot manage those resources, and deleting clusters directly in AWS can leave unused resources.

