If you’re signing in to CoreWeave for the first time, see Activate and sign in to your CoreWeave organization.
Platform identity and CKS permissions
CoreWeave platform identity and IAM determine which CKS resources a user can access. Use the Security documentation to configure identity and access:- Organizations and users
- Managed Auth (recommended for most organizations)
- SAML SSO
- Manage API access tokens and kubeconfig files
- IAM Access Policies and IAM roles
CKS uses Organization IDs to enforce tenant isolation. CKS filters all user interactions and cluster requests by Organization ID.
Within a cluster, Kubernetes role-based access control (RBAC) determines what authenticated users can do. Read permissions include the
watch, get, and list verbs. Write permissions include the create and patch verbs. For the full permissions model, including how legacy admin, write, and read groups map to IAM and Kubernetes roles, see IAM Access Policies and Legacy User Permissions.
Choose an authentication method
After a cluster exists, choose how users authenticate to its Kubernetes API:Secure your cluster
Not every organization needs private API access or workload credentials. Those optional paths live under Secure your cluster:- Access a CKS cluster through Tailscale VPN for private API access.
- Introduction to OIDC Workload Identity for CKS for short-lived workload credentials.
- Access Google Cloud Storage from CKS Pods for Google Cloud federation.
- CKS Workload Federation for AI Object Storage for Object Storage federation.