# Connect AWS, Azure and GCP securely | ZopNight

> Connect AWS, Azure, Google Cloud, Databricks, Snowflake and Red Hat OpenShift the way each one recommends. Start read-only and rotate credentials in place.

Source: https://zop.dev/zopnight/cloud-accounts

---

_Read-only to start_

## Connect a cloud in minutes.

Connect AWS, Azure, Google Cloud, Databricks, Snowflake and Red Hat OpenShift using the method each one recommends. Start read-only, and grant write access only when you want ZopNight to start and stop things.

- 6 — platforms to connect
- Keyless — on AWS and Azure
- Read-only — to start, write when you choose
- AES-256 — encryption on every credential

Free to start. No card. The playground just needs your work email.

## Least access, by default.

Grant more only when you want ZopNight to act.

- 01. Pick the recommended method — A keyless cross-account role on AWS, One-Click Connect with Google sign-in for Google Cloud, a service principal or federated identity on Azure.
- 02. Start read-only — ZopNight discovers resources and reads metadata and billing, and changes nothing. Every credential is checked live against the provider before it is saved.
- 03. Upgrade when ready — Grant Read + Write when you want schedules, bulk start and stop, and fixes to act on your behalf. Cloud IAM Import can bring your users and roles across too.
- 04. Rotate in place — Change credentials or switch authentication method without disconnecting the account. On an Azure tenant connection, the change carries down to every child subscription.

## The recommended option, first.

Every platform connects the way it recommends.

- AWS: WIF-Assume Role, a keyless cross-account IAM role, is recommended. Static keys and temporary credentials are supported where a role is not possible.
- Google Cloud: One-Click Connect through Google sign-in is recommended: ZopNight creates and manages a dedicated service account in a guided three-step flow. A customer-managed service account key is also supported.
- Azure: A service principal is recommended, with workload identity federation as the keyless alternative. A tenant connection finds every subscription you can reach.
- Databricks, Snowflake, OpenShift: Databricks on AWS and Google Cloud connects with an OAuth service principal; on Azure it rides your existing subscription. Snowflake connects with a key pair or an access token. OpenShift connects through OpenShift Cluster Manager.

## Your first account is a few minutes away.

Pick a cloud, follow the guided setup, and discovery starts the moment it connects.

[object Object]
