Skip to main content
To connect accounts for edge platforms, see Setting up Accounts for Edge Platforms. To add a cloud account in CoPilot:
  1. Go to Cloud Resources > Cloud Accounts.
  2. Click Onboard Cloud Account.
  3. Enter the parameter values:
ParameterDescription
Account NameEnter the name of the cloud account.
Cloud AccountSelect the Cloud Service Provider (CSP) for this account.
  1. Select the parameters specific to the Cloud Account you are using. See the tables below for the parameters you can select when connecting cloud accounts.
  2. Click Save. The new cloud account appears in the table.
The tables below provide descriptions of the onboarding parameters for each cloud service provider (CSP). They also identify which fields can be modified for each CSP. After onboarding a cloud account, you can do the following on the Cloud Account page:
  • Modify the settings by clicking the Edit icon in the row of the cloud account.
  • Audit the account from either the Actions menu or the vertical ellipses menu.
  • Update the IAM Policy for any AWS cloud account from the Actions menu.

Kubernetes Clusters

If you have any Kubernetes clusters in your AWS or Azure cloud accounts, they are discovered automatically during the AWS/Azure cloud account onboarding process and displayed on the Cloud Assets > Kubernetes Clusters tab. After they are displayed on this tab they can be onboarded. All necessary EKS and AKS permissions are added as part of the AWS/Azure cloud account onboarding process.
Any clusters you created outside of AWS/EKS can be onboarded manually.

AWS Cloud Account Parameters

When you select AWS as the CSP, you can click the dropdown menu on the AWS icon to select Standard, China, or GovCloud. You can onboard using CloudFormation or using access keys. CloudFormation is the recommended option. Access keys should only be used in nonproduction environments.
ParameterDescriptionCan Be ModifiedComments
Account NameThe name assigned to the account.NoAssign a descriptive and unique name.
Cloud TypeThe cloud service provider for the account.NoSelect the AWS logo.
IAM Role-BasedToggles IAM role-based access On or Off.YesIf the IAM Role-Based toggle is set to Off, you are prompted to provide a key and secret for access.
Launch the CloudFormation templateThe template runs in AWS to establish trust with your access account. (Skip if you have already run the template.) Only displays if IAM Role-Based option is On.NoThe template cannot be rerun to change settings. For AWS Standard and GovCloud, the template opens. For AWS China, the template downloads.
AWS Account NumberThe 12-digit number for the AWS account.YesIf the account number is changed, the launch CloudFormation option displays and you are prompted at the bottom of the page to create a secondary account.
AWS Access Key IDPart of an access key that provides long-term credentials to sign programmatic requests to the AWS CLI or API.YesOnly displays if IAM Role-Based is set to Off. Not recommended for production environments.
AWS Secret KeyPart of an access key that provides long-term credentials to sign programmatic requests to the AWS CLI or API.YesOnly displays if IAM Role-Based is set to Off. Not recommended for production environments.
AWS App Role ARN (Optional)Enter the AWS App Role ARN. ARN values are only required if you are creating an access account that is separate from the one from which you deployed the Controller.YesAvailable if IAM Role-Based is On.
AWS EC2 Role ARN (Optional)Enter the EC2 Role ARN. This IAM role gives Aviatrix temporary security credentials to make API requests.YesAvailable if IAM Role-Based option is On.
Add to RBAC Groups (Optional)Select the RBAC (Role Based Access Control) groups that should be able to access this account.NoAvailable if IAM Role-Based option is On.
I have run the CloudFormation script to set up this secondary access account.Select this checkbox to create a secondary AWS account.---This option displays if you change the AWS Account Number.

Azure Cloud Account Parameters

Note that when you select Azure as the cloud for this account, you can click on the dropdown menu on the icon to select Global, China, or GovCloud.
ParameterDescriptionCan Be ModifiedComments
Account NameThe name assigned to the account.NoAssign a descriptive and unique name.
Cloud TypeThe cloud service provider for the account.NoSelect the Azure logo.
ARM Subscription IDThe unique ARM Subscription ID from your Azure account.YesIdentifies a specific subscription within the Azure account.
Directory IDThe unique Entra ID from your Azure account, assigned to a tenant.YesAllows users to access Microsoft services.
Application IDThe unique identifier assigned to an application in your Azure account.YesAllows the application to authenticate and access Azure services. Also called Client ID.
Application KeyThe Secret Key Value saved from your Azure account.YesUsed to authenticate an application and provide programmatic access to Azure services.
Add to RBAC Groups (Optional)Lists the RBAC (Role Based Access Control) groups to choose from for access to this account.No

GCP Cloud Account Parameters

ParameterDescriptionCan Be ModifiedComments
Account NameThe name assigned to the account.NoAssign a descriptive and unique name.
Cloud TypeThe cloud service provider for the account.NoSelect the Google Cloud Platform (GCP) logo.
GCP Project IDThe unique ID that identifies a specific project in your GCP account.Yes
GCP Project CredentialsThe service account credentials file downloaded from GCP.YesYou must upload a project credentials file.
Add to RBAC Groups (Optional)Lists the RBAC (Role Based Access Control) groups to choose from for access to this account.No

OCI Cloud Account Parameters

ParameterDescriptionCan Be ModifiedComments
Account NameThe name assigned to the account.NoAssign a descriptive and unique name.
Cloud TypeThe cloud service provider for the account.NoSelect the OCI logo.
OCI Tenancy IDThe unique ID for your OCI account (tenancy).Yes
OCI User IDThe ID for the user who should have access to this account through CoPilot.Yes
OCI Compartment IDThe unique label for a logical container (compartment) within your OCI tenancy.YesAllows you to control access to compartment resources using policies.
OCI API Private Key FileThe private key file you downloaded from your OCI account.YesThe secret part of a key pair used to authenticate programmatic requests.
Add to RBAC Groups (Optional)Lists the RBAC (Role Based Access Control) groups to choose from for access to this account.No

Alibaba Cloud Account Parameters

ParameterDescriptionCan Be ModifiedComments
Account NameThe name assigned to the account.NoAssign a descriptive and unique name.
Cloud TypeThe cloud service provider for the account.NoSelect the Alibaba logo.
Alibaba Account IDA unique ID for your Alibaba Cloud account.Yes
Access KeyThe access key ID from your Alibaba account.YesPart of the AccessKey pair that provides access to APIs and resources.
Secret Access KeyThe Secret Access Key from your Alibaba account.YesPart of the AccessKey pair that provides access to APIs and resources.
Add to RBAC Groups (Optional)Lists the RBAC (Role Based Access Control) groups to choose from for access to this account.No