AWS prerequisites AWS account permissionsObtaining IDs for environment provisioningCreating a cross-account access IAM roleTo allow Cloudera to create resources in your AWS account, you create a cross-account access IAM role in your AWS account and grant Cloudera access to the role as a trusted principal by specifying a specific AWS account and an external ID.Creating a provisioning credential for AWSCreate a role-based credential referencing the IAM role created earlier. This can be done from the Cloudera web interface or CDP CLI.VPC and subnetsWhen registering an AWS environment in Cloudera, you will be asked to select a VPC and two or more subnets. You can use your existing VPC and subnets for provisioning Cloudera resources.Security groupsSecurity groups determine the inbound and outbound traffic to and from your Cloudera environment. That is, you should use security group settings to allow users from your organization access to Cloudera resources.Customer-managed encryption keysSSH key pairWhen registering an environment, you will be asked to provide a BC FIPS SSH public key for which you have a matching private key. The minimum SSH key size is 4096 bits.S3 bucket, and IAM roles and policies for logs and backupsCloudera requires that you create and provide at least one S3 bucket for storing workload data and logs. You also need to create and provide multiple IAM roles and policies that allow access to the S3 bucket.AWS outbound network access destinationsParent topic: Cloud Provider Requirements