# Common Tasks in Confluent Cloud for Government

To use Confluent Cloud for Government, you must first accept an invitation to a Confluent Cloud for Government organization and log in. Once you are logged in, you can complete common
tasks in your environment.

<a id="gov-cloud-accept-invitation"></a>

## Accept your invitation to Confluent Cloud for Government

You will receive an email invitation to Confluent Cloud for Government that contains a link. Click the link to accept the
invitation and set up your account. The SSO login screen that appears after you click the link
is your new permanent Confluent Cloud for Government SSO login page. Bookmark this URL.

Considerations for invitations:

- The link in the notification is for one-time use. Do not share the link with other users in your
  organization. This link only works for the recipient of the email notification.
- To receive an invitation, a member of the Confluent Cloud for Government organization that you want to join must invite you.

<a id="gov-cloud-sign-on"></a>

## Log in to Confluent Cloud for Government

Confluent Cloud for Government uses single sign-on (SSO) for authentication. For more information,
see [Single sign-on (SSO) user accounts](/cloud/current/access-management/identity/user-accounts.html#single-sign-on-accounts).

Sign in using the Confluent CLI or the Confluent Cloud for Government Console.

### Confluent CLI

Sign in using the `confluent login` command with the `--us-gov` flag.

```none
confluent login --us-gov
```

If the Confluent CLI is running on a server without a web browser (also known as
a “jump host”), add the `--no-browser` flag.

<details id="target-details">
<summary id="target-summary" style="display: list-item; cursor:pointer; color:#337ab7;">
   Example and workflow for servers without web browsers
</summary>
```none
confluent login --us-gov --no-browser
```

After running this command, you receive a printout of a URL, which you must
copy and paste into a local browser. After you provide your credentials and
successfully log in, the browser displays a code that you must copy and paste
back into in the Confluent CLI. Your workflow should look like the following:

```none
confluent login --us-gov --no-browser

Enter your Confluent credentials:
Email: example@example.com

Navigate to the following link in your browser to authenticate:

https://login.confluentgov.com/authorize?response_type=code&code_challenge=NovO_c6FO44G-6cfRbqTrBcEOrDnvm7GNZLCHCmbPM8&code_challenge_method=S252&client_id=hPbGLM8G55HSaUsaaieiiAprnJaEc3rH&redirect_uri=https://confluentgov.com/cli_callback&scope=openid+profile+email+offline_access&state=EoOGX1aQhvwdH2dFSvKV-gh09INnYcXFaYbUnWq3Ekw&connection=big-company

After authenticating in your browser, paste the code here:
<EXAMPLE-CODE-PASTED-HERE>

Logged in as example@example.com using environment t21388 ("default")
```

</details>

### Confluent Cloud for Government Console

- Use the bookmark to your SSO login page.

For more information, see [Accept your invitation to Confluent Cloud for Government](#gov-cloud-accept-invitation).

## Working with Confluent Cloud for Government

Use the links in this section to set up and manage your environment.

Install the Confluent CLI:

- [Install the CLI](https://docs.confluent.io/confluent-cli/current/install.html)

Invite users and assign role-based access:

- [Single Sign-on (SSO) Overview](/cloud/current/access-management/authenticate/sso/overview.html)
- [Add an SSO user](/cloud/current/access-management/identity/user-accounts.html#add-an-sso-user)
- [Restrict user access](/cloud/current/access-management/access-control/cloud-rbac.html)

Kafka cluster management:

- [CRUD operations for Kafka clusters](/cloud/current/clusters/create-cluster.html#how-to-work-with-clusters)
- [Resize clusters](/cloud/current/clusters/resize.html)
- [Self-Managed Encryption Keys and AWS](/cloud/current/clusters/byok/byok-aws.html)

Setup network security:

Setting up a private network on Confluent Cloud for Government is a two-step process. First you create the Confluent Cloud for Government network,
then you add the private networking option. AWS includes multiple private networking options, including
AWS PrivateLink, VPC Peering on AWS, and AWS Transit Gateway.

- [Confluent Cloud Network on AWS](/cloud/current/networking/ccloud-network/aws.html#create-ccloud-network-aws)
- [AWS PrivateLink](/cloud/current/networking/private-links/aws-privatelink.html)

Monitoring and logging:

- [Confluent Cloud Audit Log Overview](/cloud/current/monitoring/audit-logging/cloud-audit-log-concepts.html)
- [Audit Log Reference](/cloud/current/monitoring/audit-logging/audit-log-records.html)
- [Audit Log Event Schema](/cloud/current/monitoring/audit-logging/audit-log-schema.html)
- [Access and Consume Audit Logs](/cloud/current/monitoring/audit-logging/configure.html)

Backups and contingency plans:

- [Confluent Replicator to Confluent Cloud Configurations](/cloud/current/get-started/examples/ccloud/docs/replicator-to-cloud-configuration-types.html#ccloud-to-ccloud-with-connect-backed-to-origin)
- [Confluent for Kubernetes and Replicator GitHub Example](https://github.com/confluentinc/confluent-kubernetes-examples/tree/master/hybrid/replicator-cloud2cloud)
- [Confluent for Kubernetes](https://docs.confluent.io/operator/current/overview.html)

## Related content

- [Install the CLI](https://docs.confluent.io/confluent-cli/current/install.html)
- [Add an SSO user](/cloud/current/access-management/identity/user-accounts.html#add-an-sso-user)
- [Single sign-on (SSO) user accounts](/cloud/current/access-management/identity/user-accounts.html#single-sign-on-accounts)
- [Restrict user access](/cloud/current/access-management/access-control/cloud-rbac.html)
- [CRUD operations for Kafka clusters](/cloud/current/clusters/create-cluster.html#how-to-work-with-clusters)
- [Resize clusters](/cloud/current/clusters/resize.html)
- [Self-Managed Encryption Keys and AWS](/cloud/current/clusters/byok/byok-aws.html)
- [Confluent Cloud Network on AWS](/cloud/current/networking/ccloud-network/aws.html#create-ccloud-network-aws)
- [AWS PrivateLink](/cloud/current/networking/private-links/aws-privatelink.html)
- [AWS VPC Peering](/cloud/current/networking/peering/aws-peering.html)
- [AWS Transit Gateway](/cloud/current/networking/aws-transit-gateway.html)
- [Confluent Cloud Audit Log Overview](/cloud/current/monitoring/audit-logging/cloud-audit-log-concepts.html)
- [Audit Log Reference](/cloud/current/monitoring/audit-logging/audit-log-records.html)
- [Audit Log Event Schema](/cloud/current/monitoring/audit-logging/audit-log-schema.html)
- [Access and Consume Audit Logs](/cloud/current/monitoring/audit-logging/configure.html)
- [Confluent Replicator to Confluent Cloud Configurations](/cloud/current/get-started/examples/ccloud/docs/replicator-to-cloud-configuration-types.html#ccloud-to-ccloud-with-connect-backed-to-origin)
- [Confluent for Kubernetes and Replicator GitHub Example](https://github.com/confluentinc/confluent-kubernetes-examples/tree/master/hybrid/replicator-cloud2cloud)
- [Confluent for Kubernetes](https://docs.confluent.io/operator/current/overview.html)
