Skip to content

Latest commit

 

History

History
88 lines (63 loc) · 5.22 KB

rosa-sts-aws-prereqs.adoc

File metadata and controls

88 lines (63 loc) · 5.22 KB

_attributes/attributes-openshift-dedicated.adoc :context: rosa-sts-aws-prereqs

Detailed requirements for deploying ROSA using STS

{product-title} (ROSA) provides a model that allows Red Hat to deploy clusters into a customer’s existing Amazon Web Service (AWS) account.

Ensure that the following AWS prerequisites are met before installing ROSA with STS.

Important

When you create a ROSA cluster using AWS STS, an associated AWS OpenID Connect (OIDC) identity provider is created as well. This OIDC provider configuration relies on a public key that is located in the us-east-1 AWS region. Customers with AWS SCPs must allow the use of the us-east-1 AWS region, even if these clusters are deployed in a different region.

Customer requirements when using STS for deployment

The following prerequisites must be complete before you deploy a {product-title} (ROSA) cluster that uses the AWS Security Token Service (STS).

Additional resources

Additional resources

Red Hat managed IAM references for AWS

With the STS deployment model, Red Hat is no longer responsible for creating and managing Amazon Web Services (AWS) IAM policies, IAM users, or IAM roles. For information on creating these roles and policies, see the following sections on IAM roles.

Additional resources