Docs

Connect an app to AWS

Use AWS resources from an application on Northflank. Accessing external resources does not require a Northflank cluster in your AWS account.

Requirements

You will need the following to get started:

  • An AWS account and permission to configure access to the intended resources
  • A Northflank application and permission to configure its connections
  • The required provider-link features enabled for your account

1. Choose the task

TaskPath
Access a resource that already existsProvider link → Workload identity → Application request
Create a supported external addonProvider link → Managed external addon → Application connection
Define external resources in codeProvider link → OpenTofu template → Resource outputs

Review provider-link features for availability. Select the features for your task before granting AWS permissions. A feature selection does not grant permissions or provision a resource.

2. Connect the AWS account

Connect an AWS provider link. Use the authentication method and permissions required for the selected features.

Keep existing permissions that other resources still use. Cluster quotas apply when you also deploy a cluster.

3. Configure the resource path

For an existing resource, configure workload identity. This gives services and jobs cloud access without manually managing their cloud credentials. Use the intended resource permissions for the application.

For a supported S3 or RDS resource, create a managed external addon. These resources run in your AWS account. Wait for resource creation to complete before connecting the application.

For other infrastructure defined in code, configure an OpenTofu node. Select the provider link and define the outputs that the application needs. Review resource changes before running the template.

4. Connect and exercise the application

Provide the endpoint and other required values through runtime variables or secrets.

Access permissions and network connectivity are separate requirements. Workload identity does not create a network path. Review the resource's network access and Northflank networking guidance.

Make a representative request from the application. Make sure that it can access the intended resource with the intended permissions. For resources created by a template, define teardown behavior before adding cleanup actions.

To host the application itself in AWS, use Run workloads in your cloud.

© 2026 Northflank Ltd. All rights reserved.

northflank.com / Terms / Privacy / feedback@northflank.com