Skip to main content
Use this page to understand how CoreWeave identity and access controls apply to CoreWeave Kubernetes Service (CKS), then choose how users authenticate to a cluster. Private API access, workload identity, and Object Storage federation live under Secure your cluster.
If you’re signing in to CoreWeave for the first time, see Activate and sign in to your CoreWeave organization.

Platform identity and CKS permissions

CoreWeave platform identity and IAM determine which CKS resources a user can access. Use the Security documentation to configure identity and access: CKS uses two product IAM roles: CKS uses Organization IDs to enforce tenant isolation. CKS filters all user interactions and cluster requests by Organization ID. Within a cluster, Kubernetes role-based access control (RBAC) determines what authenticated users can do. Read permissions include the watch, get, and list verbs. Write permissions include the create and patch verbs. For the full permissions model, including how legacy admin, write, and read groups map to IAM and Kubernetes roles, see IAM Access Policies and Legacy User Permissions.

Choose an authentication method

After a cluster exists, choose how users authenticate to its Kubernetes API:
Managed Auth is the recommended path for user authentication to CKS. You must use Managed Auth to create new CKS clusters or VPCs. Unmanaged authentication applies only to existing clusters.

Secure your cluster

Not every organization needs private API access or workload credentials. Those optional paths live under Secure your cluster: Private clusters have no public API endpoint. Besides Tailscale, you can reach the API through Traefik ingress, often paired with Direct Connect. Self-service cluster creation supports public clusters only. To set up a private cluster, contact CoreWeave Support.
Last modified on September 30, 2026