|
| 1 | +:_mod-docs-content-type: ASSEMBLY |
| 2 | +[id="rosa-hcp-sts-creating-a-cluster-ext-auth"] |
| 3 | += Creating ROSA with HCP clusters with external authentication |
| 4 | +include::_attributes/attributes-openshift-dedicated.adoc[] |
| 5 | +:context: rosa-hcp-sts-creating-a-cluster-ext-auth |
| 6 | + |
| 7 | +toc::[] |
| 8 | + |
| 9 | +You can create {hcp-title-first} clusters that use an external authentication to issue your access tokens. |
| 10 | + |
| 11 | +[IMPORTANT] |
| 12 | +==== |
| 13 | +Since it is not possible to upgrade or convert existing ROSA clusters to a {hcp} architecture, you must create a new cluster to use {hcp-title} functionality. |
| 14 | +==== |
| 15 | + |
| 16 | +[NOTE] |
| 17 | +==== |
| 18 | +{hcp-title} clusters only support AWS Security Token Service (STS) authentication. |
| 19 | +==== |
| 20 | + |
| 21 | +.Further reading |
| 22 | +* For a comparison between {hcp-title} and ROSA Classic, see the xref:../rosa_architecture/rosa_architecture_sub/rosa-architecture-models.adoc#rosa-hcp-classic-comparison_rosa-architecture-models[Comparing architecture models] documentation. |
| 23 | +* See the AWS documentation for information about link:https://docs.aws.amazon.com/rosa/latest/userguide/getting-started-hcp.html[Getting started with ROSA with HCP using the ROSA CLI in auto mode]. |
| 24 | +
|
| 25 | +.Additional resources |
| 26 | + |
| 27 | +For a full list of the supported certificates, see the xref:../rosa_architecture/rosa_policy_service_definition/rosa-policy-process-security.adoc#rosa-policy-compliance_rosa-policy-process-security[Compliance] section of "Understanding process and security for Red Hat OpenShift Service on AWS". |
| 28 | + |
| 29 | +[id="next-steps-hcp-ext-auth_{context}"] |
| 30 | +.Next steps |
| 31 | + |
| 32 | +* Ensure that you have completed the xref:../rosa_planning/rosa-sts-aws-prereqs.adoc[AWS prerequisites]. |
| 33 | +
|
| 34 | +[id="rosa-hcp-external-auth-prereqs"] |
| 35 | +== {hcp-title} Prerequisites |
| 36 | + |
| 37 | +To create a {hcp-title} cluster, you must have the following items: |
| 38 | + |
| 39 | +* A xref:../rosa_hcp/rosa-hcp-sts-creating-a-cluster-quickly.adoc#rosa-hcp-creating-vpc[configured virtual private cloud (VPC)] |
| 40 | +* xref:../rosa_hcp/rosa-hcp-sts-creating-a-cluster-quickly.adoc#rosa-sts-creating-account-wide-sts-roles-and-policies_rosa-hcp-sts-creating-a-cluster-quickly[Account-wide roles] |
| 41 | +* An xref:../rosa_hcp/rosa-hcp-sts-creating-a-cluster-quickly.adoc#rosa-sts-byo-oidc_rosa-hcp-sts-creating-a-cluster-quickly[OIDC configuration] |
| 42 | +* xref:../rosa_hcp/rosa-hcp-sts-creating-a-cluster-quickly.adoc#rosa-operator-config_rosa-hcp-sts-creating-a-cluster-quickly[Operator roles] |
| 43 | + |
| 44 | +include::modules/rosa-hcp-sts-creating-a-cluster-ext-auth-cli.adoc[leveloffset=+1] |
| 45 | + |
| 46 | +[id="next-steps-2_{context}"] |
| 47 | +== Next steps |
| 48 | + |
| 49 | +* xref:../rosa_install_access_delete_clusters/rosa-sts-accessing-cluster.adoc#rosa-sts-accessing-cluster[Accessing a ROSA cluster] |
| 50 | + |
| 51 | +[role="_additional-resources"] |
| 52 | +[id="additional-resources_rosa-sts-creating-a-cluster-ext-auth"] |
| 53 | +== Additional resources |
| 54 | + |
| 55 | +* For steps to deploy a ROSA cluster using manual mode, see xref:../rosa_install_access_delete_clusters/rosa-sts-creating-a-cluster-with-customizations.adoc#rosa-sts-creating-cluster-using-customizations_rosa-sts-creating-a-cluster-with-customizations[Creating a cluster using customizations]. |
| 56 | +* For more information about the AWS Identity Access Management (IAM) resources required to deploy {product-title} with STS, see xref:../rosa_architecture/rosa-sts-about-iam-resources.adoc#rosa-sts-about-iam-resources[About IAM resources for clusters that use STS]. |
| 57 | +* For details about optionally setting an Operator role name prefix, see xref:../rosa_architecture/rosa-sts-about-iam-resources.adoc#rosa-sts-about-operator-role-prefixes_rosa-sts-about-iam-resources[About custom Operator IAM role prefixes]. |
| 58 | +* For information about the prerequisites to installing ROSA with STS, see xref:../rosa_planning/rosa-sts-aws-prereqs.adoc#rosa-sts-aws-prereqs[AWS prerequisites for ROSA with STS]. |
| 59 | +* For details about using the `auto` and `manual` modes to create the required STS resources, see xref:../rosa_install_access_delete_clusters/rosa-sts-creating-a-cluster-with-customizations.adoc#rosa-understanding-deployment-modes_rosa-sts-creating-a-cluster-with-customizations[Understanding the auto and manual deployment modes]. |
| 60 | +* For more information about using OpenID Connect (OIDC) identity providers in AWS IAM, see link:https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_oidc.html[Creating OpenID Connect (OIDC) identity providers] in the AWS documentation. |
| 61 | +* For more information about troubleshooting ROSA cluster installations, see xref:../support/troubleshooting/rosa-troubleshooting-installations.adoc#rosa-troubleshooting-installations[Troubleshooting installations]. |
| 62 | +* For steps to contact Red Hat Support for assistance, see xref:../support/getting-support.adoc#getting-support[Getting support for Red Hat OpenShift Service on AWS]. |
0 commit comments