stacks— setup includes a permissions policy for creating, updating, and deleting Nuon CloudFormation install stacks.custom— setup includes only the OIDC trust configuration. Attach your own permissions policy to the IAM role before using it for stack operations.
OIDC trust model
Nuon mints a short-lived OIDC token when it needs to perform an operation. The role trust policy must restrict these values:- Issuer — your Nuon control plane’s public API URL.
- Subject —
org:<org_id>:connection:<connection_id>, unique to one connection. - Audience —
sts.amazonaws.com.
Create and configure a connection
Create the connection first. This saves the connection in Nuon; it does not create the IAM role or OIDC provider in AWS.stacks preset also includes an explicit action allowlist covering the resources in Nuon’s install stack templates. It does not include image registry access. With --preset custom, no permissions policy is generated: attach your own policy.
After applying the setup, verify the connection from the dashboard’s Verify step or run:
verified, the connection is available in the install creation wizard. For scripts, create --output json and get <connection-id> --output json include the generated setup material in setup without the human-readable next-step instructions.
Verification exchanges a Nuon OIDC token for temporary AWS credentials, checks the returned identity, and confirms that a foreign connection subject cannot assume the role. For stacks, it also makes a read-only CloudFormation DescribeStacks probe. This probe does not prove that every stack operation is permitted. For custom, verification checks identity and trust only; you are responsible for the permissions required by your stacks.
Use connections for install stacks
When creating an AWS install, select a verified AWS connection with either preset. The connection binding is immutable after creation: a connection cannot be added, replaced, or removed from an existing install. Nuon uses the pinned connection for CloudFormation stack creation, updates, and deletion. If no connection is selected at creation, the install remains customer-managed. A connection referenced by an install cannot be deleted; the API returns HTTP 409. Delete the referencing installs before deleting the connection.CLI
Usenuon cloud-connections list|get|create|verify|delete. Responses report the preset, status, status message, and last verification time.
Nuon verifies connections on demand, not on a recurring schedule. The last verification time records the most recent verification attempt; a verified status does not guarantee that AWS trust or permissions have not changed since then. Use verify after changing the role or its policies. A failed verification updates the connection’s status and emits cloud-connection-verification-failed for notification subscriptions.
Stack operations still obtain temporary AWS credentials through the connection when needed. This does not repeat the full verification checks, including the foreign-subject trust check.