# AWS: credentials

You create an IAM access key, store it under Cloud accounts, and let MainPath create Kubernetes clusters and databases in your AWS account.

> Source: https://www.mainpath.ai/en/docs/aws-cloud-credentials/

Under [Cloud accounts]({{< relref "cloud-accounts" >}}) you store access keys for Amazon Web Services. MainPath uses them to create [Kubernetes clusters]({{< relref "kubernetes-integration" >}}) (EKS) and optional databases (RDS) in your account. Use a dedicated IAM user, not the root account.

## Create an access key in AWS

1. Sign in to the [AWS console](https://console.aws.amazon.com/) and open **IAM**.
2. Under **Users**, create a user, for example `application-platform`.
3. Grant rights to create EKS clusters, networks (VPC), and RDS databases in the region you will later select in MainPath. In a dedicated AWS account for MainPath, the **AdministratorAccess** policy is often enough.
4. Open the user → **Security credentials** → **Create access key** and choose **Application running outside AWS**.
5. Copy the **Access Key ID** and **Secret Access Key**. AWS shows the secret only once.

The official guide is [Manage access keys for IAM users](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html).

## Add the account in MainPath

1. Open **Cloud accounts** and click **Add cloud account**.
2. Choose **AWS**.
3. Enter a name, slug, and these values:

| Platform field | Source |
|---|---|
| Access Key ID | Access Key ID from IAM, usually starts with `AKIA` |
| Secret Access Key | Secret Access Key from the same dialog |
| Region | AWS region, for example `eu-central-1` for Frankfurt |

4. Save. Secrets are stored encrypted; the list shows name, provider, and region.

Then create a cluster under **Kubernetes clusters** and select this account.

## See also

- [Cloud accounts]({{< relref "cloud-accounts" >}})
- [Kubernetes clusters]({{< relref "kubernetes-integration" >}})
- [Azure: credentials]({{< relref "azure-cloud-credentials" >}})
- [Google Cloud: credentials]({{< relref "gcp-cloud-credentials" >}})
- [Open Telekom Cloud: credentials]({{< relref "otc-cloud-credentials" >}})

