# Connecting clouds

Artifacts creates buckets in your AWS account, GCP project or Azure subscription
and signs URLs for them, without any long-lived cloud key from you.

## Federation

The app is an OpenID Connect identity provider. It publishes
`/.well-known/openid-configuration` and its keys at `/.well-known/jwks.json`,
and signs short JWTs whose subject is one connection, `org_…:c…`. Your cloud
trusts that issuer for that one subject and swaps the JWT for its own
short-lived credentials.

Nothing you give us can be lifted and used elsewhere. Revoking is deleting the
role, the workload identity pool or the federated credential on your side.

## Connect

1. **Connections → Connect AWS**, **GCP** or **Azure**, and name the connection.
2. The app shows a setup script with your connection's subject, the issuer and
   the audience filled in. Run it in your account with the cloud's CLI, as an
   administrator.
3. The script's last line prints the identifiers it created, `key=value` pairs.
   Paste that line back into the app, or fill in the fields.
4. The app exchanges a token to check the connection works, and marks it
   **active**. A connection whose trust was removed shows as **broken**, with
   the error.

Then create locations in that cloud: pick the connection and a region, and the
app creates the bucket.

| Cloud | The script creates                                                                                  | It grants                                                                                  | The app signs with                                                                                             |
| ----- | --------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------- |
| AWS   | An IAM OIDC provider for the issuer and a role trusting the subject, max session 12 h               | Create `o41art-*` buckets and set their lifecycle; object and multipart operations in them | Temporary keys from `AssumeRoleWithWebIdentity`, cached until shortly before they expire                       |
| GCP   | A workload identity pool and provider for the issuer, a service account the subject may impersonate | Create buckets; storage admin on `o41art-*` buckets only; sign as the service account      | The service account through IAM `signBlob`, with the federated token: V4 URLs on the XML API, no key ever made |
| Azure | An app registration with a federated credential for the issuer and subject                          | Storage Account Contributor and Storage Blob Data Contributor on a resource group you name | A user delegation key per storage account, refreshed daily; user delegation SAS                                |

## The identifiers

| Cloud | Pasted back                                                                 |
| ----- | --------------------------------------------------------------------------- |
| AWS   | `roleArn`                                                                   |
| GCP   | `projectId`, `projectNumber`, `poolId`, `providerId`, `serviceAccountEmail` |
| Azure | `tenantId`, `clientId`, `subscriptionId`, `resourceGroup`                   |

## Created buckets

- Named `o41art-<random>`; on Azure a storage account `o41art<random>` with a
  container `artifacts`.
- Private, with a lifecycle rule that aborts unfinished multipart uploads after
  2 days. Azure drops uncommitted blocks after 7 days by itself.
- The app never deletes a bucket. A location is retired instead: no new writes
  go to it and its versions stay readable.
- A created location whose bucket or first test write fails stays
  **unfinished**: it takes no writes and can be removed (`locations rm`); the
  bucket, if one was made, stays in your account.

A tenant who cannot set up federation on AWS or GCP adds the bucket as an
[S3 endpoint](https://artifacts.041.io/docs/s3-endpoints.md) with a key instead. Azure Blob has no S3 API, so
Azure is federation only.

---

Artifacts by 041 documentation. Every page: https://artifacts.041.io/llms.txt
