Prerequisites
- Review the . Make sure you understand and acknowledge the responsibilities you hold for management of your cloud infrastucture and the necessary permissions you must grant to Cockroach Labs.
- if you do not already have one.
- The BYOC deployment option is not available by default and must be requested. Reach out to your account team to express interest in BYOC.
- Once your cloud account is prepared for a CockroachDB BYOC deployment, cluster configuration and management is identical to a CockroachDB Cloud Advanced cluster. Review the documentation to plan your cluster sizing and resource allocation.
- Review cloud service regions supported by .
- Create an to use the with your CockroachDB Cloud organization.
- The AWS account must not contain a BYOC cluster created before 27 July 2026. More than one BYOC cluster can run in a single AWS account, but any BYOC clusters created before this date must be deleted or their data migrated before additional clusters can be created in the same account.
- The AWS account must not contain resources that can affect the control plane’s ability to operate on CockroachDB clusters.
Step 1. Create a new AWS account
Provision a new AWS account dedicated to CockroachDB infrastructure. The account configuration for BYOC requires you to grant Cockroach Labs permissions to access and modify resources in this account, so this step is necessary to isolate these permissions from non-CockroachDB Cloud resources and allow Cockroach Labs to meet cluster uptime SLAs. This account can be reused for multiple CockroachDB clusters.Step 2. Collect the Cockroach Labs IAM role ARN
Cockroach Labs uses cross-account resource management to provision and manage resources in your AWS account. This requires two IAM roles:- An IAM role owned by Cockroach Labs which must be granted permissions to access an IAM role in your AWS account.
- An intermediary IAM role in your AWS account which must be granted permissions to create and manage infrastructure. This IAM role is the target used by Cockroach Labs for cross-account management.
GET request to the /v1/organization endpoint of the similar to the following example:
cockroach_cloud_service_principals.aws.user_arn in the response:
Step 3. Create intermediary IAM role and apply permissions
In this step, create the intermediary IAM role in your AWS account, then apply a trust relationship policy and permissions that allow Cockroach Labs to assume the intermediary role as needed.This permission policy is the minimum required for Cockroach Labs to provision, operate, patch, back up, and heal your cluster over its full lifecycle. This is not a temporary permission set used only at time of creation.Do not remove, narrow, or add conditions to these permissions after setup, or use Resource Control Policies (RCPs) against this account that may affect control plane operations. Many of these are exercised only during a specific lifecycle event, such as replacing a failed node, applying a patch, rotating an encryption key, or running a managed backup. Removing a permission might not cause an immediate error. A later operation that requires it, such as replacing a failed node or running a backup, can fail. Reducing the permission set voids the availability commitment for the cluster.Guardrails that restrict the account to particular regions or services, without touching the permissions the deployment requires, are compatible. Conditional or time-bounded policies, and service control policies that restrict this permission set, are not supported.
- Open the AWS IAM console.
-
Create a new role. You can choose any name for this role. In these instructions the example role is named
CRLBYOCAdmin. -
Use the following trust relationship policy for the new role, using the ARN collected in the previous step:
-
Apply an IAM policy to the intermediate role granting the following list of permissions:
Step 4. (Optional) Enable additional regions
If you plan to use non-default AWS regions, you must manually enable them in the AWS Management Console. You must also activate global STS tokens for these regions to work with CockroachDB. You may also need to adjust quotas for vCPU and EBS disk storage for the regions in which you plan to create your cluster.Step 5. Create the CockroachDB Cloud cluster
In BYOC deployments, CockroachDB clusters can be deployed in the CockroachDB Cloud Console or with the .Create a cluster with the CockroachDB Cloud Console
Follow these steps to create a CockroachDB cluster in the CockroachDB Cloud console:- Open the CockroachDB Cloud Console and select the organization that has been enabled for BYOC.
- Click Create cluster.
- Under Select a plan, click Advanced.
- Under Cloud & Regions, click Bring Your Own Cloud and select AWS.
- Under Cloud account, click Select your cloud account > Add new cloud account. Enter the ARN associated with the intermediate IAM role that you created, not the ARN of the Cockroach Labs IAM role.
- Follow the rest of the Create Cluster steps to configure your cluster’s regions, capacity, and features as desired. Read the documentation for more details.
Create a cluster with the CockroachDB Cloud API
Send aPOST request to the the /v1/clusters endpoint to .
The following example request creates a 3-node Advanced cluster in the us-east-2 region, specifying the ARN associated with your intermediate IAM role:
Create additional BYOC clusters
An AWS account prepared for BYOC can support multiple CockroachDB Cloud clusters. To create an additional BYOC cluster in the same account, follow the Create the CockroachDB Cloud cluster steps again. If you need to deploy the new cluster in non-AWS default regions, follow the Enable additional regions step.Delete a BYOC cluster
To delete a BYOC cluster, delete the cluster from the or with the . Deleting the cluster is permanent and cannot be undone. When you delete a BYOC cluster, Cockroach Labs removes the managed resources that it provisioned in your AWS account for the cluster. The intermediary IAM role you created during setup is not removed automatically and remains under your control. You can remove it once deletion is complete.Do not remove the intermediary IAM role or its permissions before deletion has finished. Cockroach Labs needs them to remove the managed resources from your AWS account. Removing access early can leave resources behind that you will need to clean up manually, and that will continue to incur charges from your cloud provider.

