# Connect an app to AWS

Use AWS resources from an application on Northflank. Accessing external resources does not require a Northflank cluster in your AWS account.

> [!note] Requirements
>
> You will need the following to get started:
>
> - An AWS account and permission to configure access to the intended resources
> - A Northflank application and permission to configure its connections
> - The required provider-link features enabled for your account

### 1. Choose the task

| Task | Path |
| --- | --- |
| Access a resource that already exists | Provider link → Workload identity → Application request |
| Create a supported external addon | Provider link → Managed external addon → Application connection |
| Define external resources in code | Provider link → OpenTofu template → Resource outputs |

Review [provider-link features](https://northflank.com/docs/v1/application/cloud-integrations/provider-links) for availability. Select the features for your task before granting AWS permissions. A feature selection does not grant permissions or provision a resource.

### 2. Connect the AWS account

[Connect an AWS provider link](https://northflank.com/docs/v1/application/cloud-integrations/connect-aws). Use the authentication method and permissions required for the selected features.

Keep existing permissions that other resources still use. Cluster quotas apply when you also deploy a cluster.

### 3. Configure the resource path

For an existing resource, [configure workload identity](https://northflank.com/docs/v1/application/bring-your-own-cloud/configure-workload-identity). This gives services and jobs cloud access without manually managing their cloud credentials. Use the intended resource permissions for the application.

For a supported S3 or RDS resource, [create a managed external addon](https://northflank.com/docs/v1/application/databases-and-persistence/create-a-managed-external-addon). These resources run in your AWS account. Wait for resource creation to complete before connecting the application.

For other infrastructure defined in code, [configure an OpenTofu node](https://northflank.com/docs/v1/application/infrastructure-as-code/external-infrastructure). Select the provider link and define the outputs that the application needs. Review resource changes before running the template.

### 4. Connect and exercise the application

Provide the endpoint and other required values through [runtime variables](https://northflank.com/docs/v1/application/run/inject-runtime-variables) or [secrets](https://northflank.com/docs/v1/application/secure/inject-secrets).

Access permissions and network connectivity are separate requirements. Workload identity does not create a network path. Review the resource's network access and Northflank [networking guidance](https://northflank.com/docs/v1/application/network/networking-on-northflank).

Make a representative request from the application. Make sure that it can access the intended resource with the intended permissions. For resources created by a template, define [teardown behavior](https://northflank.com/docs/v1/application/infrastructure-as-code/configure-teardown-workflows) before adding cleanup actions.

To host the application itself in AWS, use [Run workloads in your cloud](run-workloads-in-your-cloud).
