# Provider links

A provider link connects a cloud account to Northflank. Choose the features that you need, then grant the required permissions.

Provider links support tasks such as pulling images, creating external resources, and granting workloads access to cloud resources. These tasks do not require BYOC. To host workloads in your cloud, follow the [cluster guides](https://northflank.com/docs/v1/application/bring-your-own-cloud/use-other-cloud-providers-with-northflank).

## Connect your cloud account

Open Cloud → Provider links to connect an account. If you already have provider links, select Create provider link. Otherwise, select Add provider link beside your provider.

Under Basic information, enter a Name. Select your Provider and Desired features before you grant cloud permissions. Selecting a feature does not grant permissions or create cloud resources.

### Select integration features

Available features depend on the provider and your account. If a required feature is missing, contact Northflank support about availability.

| Purpose | Feature and next step |
| --- | --- |
| Deploy clusters | Select BYOC, then follow [your provider's cluster guide](https://northflank.com/docs/v1/application/bring-your-own-cloud/use-other-cloud-providers-with-northflank). |
| Pull private images | Select Docker Registries, then [save registry credentials](https://northflank.com/docs/v1/application/run/save-registry-credentials#cloud-provider-registries). |
| Store project builds in your registry | Also select Docker Registry Push, then [configure a new project](https://northflank.com/docs/v1/application/build/use-custom-build-registry). |
| Provision external resources | Select OpenTofu, then [configure external infrastructure](https://northflank.com/docs/v1/application/infrastructure-as-code/external-infrastructure). This also supports [managed external resources](https://northflank.com/docs/v1/application/databases-and-persistence/create-a-managed-external-addon) on AWS. |
| Grant workloads access to cloud resources | Select the relevant Workload Identity features, then [configure workload identity](https://northflank.com/docs/v1/application/bring-your-own-cloud/configure-workload-identity) for AWS or GCP. |

For provider authentication, follow the [AWS](https://northflank.com/docs/v1/application/cloud-integrations/connect-aws#add-your-account-with-a-cross-account-role), [GCP](https://northflank.com/docs/v1/application/cloud-integrations/connect-google-cloud#add-your-account-with-a-cross-project-service-account), or [Azure](https://northflank.com/docs/v1/application/cloud-integrations/connect-azure#add-your-azure-account) authentication instructions. Select the features required for your task. You can leave BYOC unselected when you do not deploy clusters. Cluster quotas and Kubernetes permissions apply only when you also deploy clusters.

### Update an integration

To add features, open the provider link under Cloud → Provider links. Under Basic information, change Desired features. Grant the additional permissions in your cloud account. Select Update in Northflank. Keep the permissions that existing resources still need.

An organization can share integrations with teams and restrict which teams can use them. If a shared integration is missing, ask your organization administrator to review your team's access.
