> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superblocks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud-Prem deployment guide

Superblocks deploys and operates Cloud-Prem for you. Your team prepares an AWS account, runs a Superblocks-provided Terraform configuration, and hands off to Superblocks, who builds the platform in your account and keeps it running.

## Who does what

| Your team | Superblocks |
| - | - |
| Prepares the AWS account that hosts Cloud-Prem | Provides the Terraform configuration for your setup |
| Runs the Terraform and shares the results | Deploys the full platform into your account |
| Chooses and provides any [optional configurations](/enterprise/cloud-prem/configure/index) | Applies your configurations as part of a deployment |
| Creates an SSO application in your identity provider | Configures SSO on your instance |
| Invites builders after go-live | Operates, upgrades, and supports the platform |

## Deployment stages

<Steps>
  <Step title="Plan your deployment">
    Work with your Superblocks deployment team to choose an AWS region and identify who on your team will prepare the account, review security, and administer Superblocks.

    Review the [optional configurations](/enterprise/cloud-prem/configure/index) and decide which ones to include from day one.
  </Step>

  <Step title="Prepare for deployment">
    **Set up single sign-on.** Cloud-Prem instances are SSO only, so no one can sign in until SSO is configured. Create an application in your identity provider by following the guide for your provider in [Single sign-on](/admin/org-administration/auth/single-sign-on/index).

    Prepare settings for any optional configurations you chose. For example, if you're sending telemetry to your own tools, create the [observability destinations](/enterprise/cloud-prem/configure/observability-destinations) secret now.
  </Step>

  <Step title="Run the Superblocks Terraform and hand off">
    Run the Terraform configuration that Superblocks provides in your Cloud-Prem account. It sets up two things:

    * **An in-account deployment mechanism** that deploys and upgrades Cloud-Prem from inside your account.
    * **Cross-account IAM roles** that Superblocks uses to trigger deployments and manage your instance.

    When the Terraform finishes, tell your deployment team, including which optional configurations you've prepared so they're part of the initial deployment.
  </Step>

  <Step title="Superblocks deploys Cloud-Prem">
    Superblocks deploys the platform into your account and configures SSO and any optional configurations you prepared. Your deployment team lets you know when your instance is ready.
  </Step>

  <Step title="Go live">
    Sign in to your Cloud-Prem instance through your identity provider, then invite your builders. Optionally, set up [SCIM](/admin/org-administration/auth/scim/index) to provision users and groups from your identity provider.
  </Step>
</Steps>

## Add configurations after go-live

You don't have to decide everything up front. Optional configurations can be added or changed after go-live: prepare any settings described on the configuration's page, then tell your Superblocks deployment team. Superblocks applies the change at the next deployment.

## Next steps

<CardGroup cols={2}>
  <Card title="Optional configurations" icon="sliders" href="/enterprise/cloud-prem/configure/index">
    See every opt-in configuration and how it's applied.
  </Card>

  <Card title="Cloud-Prem on AWS" icon="aws" href="/enterprise/cloud-prem/aws">
    How Cloud-Prem works and why teams choose it.
  </Card>
</CardGroup>
