Cloud connectors — NuPaaS Docs
Connect

Cloud connectors

A cloud connector is one of your provider credentials, stored so that NuPaaS can act on your behalf: list the servers you already own, provision new ones, and — where the credential allows it — manage DNS records for your domains.

What a connector does

Connectors are org-scoped. Manage them at /orgs/<org>/cloud-connectors, with DNS on its own tab at /orgs/<org>/cloud-connectors/dns.

Each credential record stores a provider, a label you choose, a non-secret key prefix so you can tell two credentials apart at a glance, a status, the time it was last verified, the last error if verification failed, and the capabilities the platform detected on it.

Supported providers

Each provider takes a slightly different credential shape, because each provider's API does.

ParameterTypeDescription
hetznercomputeLabel plus an API key.
hetzner_robotcomputeLabel plus an API key and an access key.
digitaloceancomputeLabel plus an API key.
scalewaycomputeLabel, API key and project ID; an access key and organization ID may also be supplied.
upcloudcomputeLabel plus an API key and an access key.
cloudflarednsLabel plus an API key.
route_53dnsLabel plus an access key ID and secret access key; region is optional.

Adding a credential

Create the credential at your provider first, scoped as narrowly as that provider allows, then add it here.

Add a credential
platform cloud-connectors credentials add \
  --provider hetzner \
  --label "hetzner-production" \
  --api-key <your-provider-api-key>

Give the credential the least privilege that still works. A connector used only to enumerate servers does not need permission to delete them; a DNS credential does not need compute scope at all.

Verification

Verification calls the provider with the stored credential and reports back three things: whether the credential is valid at all, whether it carries DNS edit permission, and — when it does — the zones it can see.

platform cloud-connectors credentials verify --id <credentialId>

A failed verification records the provider's error on the credential rather than discarding it, so a credential that stops working tells you why. Verify after any rotation at the provider side.

DNS through a connector

A credential with DNS permission lets NuPaaS manage records for you instead of asking you to create them by hand. Zones can be listed, and within a zone records can be listed, created, updated and deleted.

ParameterTypeDescription
ArecordIPv4 address.
AAAArecordIPv6 address.
CNAMErecordAlias to another hostname.
TXTrecordText record, used for verification challenges.

Records carry a TTL, and providers that support proxying expose a proxied flag. This is the machinery behind automatic domain setup — see Domains and TLS for the customer-facing flow.

SSH keys

Connectors also hold the SSH keys NuPaaS uses to reach machines it provisions or adopts on your behalf. A key can be generated for you or imported, and a stored key can be pushed up to a provider so that new servers are created with it already installed.

Three views exist, and they answer different questions: the keys NuPaaS holds, the org-level keys with the providers each has been synced to, and the keys that already exist at each provider — useful for spotting a key that is installed on your servers but that NuPaaS does not know about.

CLI reference

platform cloud-connectors
platform cloud-connectors credentials list
platform cloud-connectors credentials add    --provider <p> --label <l> --api-key <k>
platform cloud-connectors credentials verify --id <credentialId>
platform cloud-connectors credentials delete --id <credentialId>
platform cloud-connectors ssh-keys list
platform cloud-connectors ssh-keys generate
platform cloud-connectors ssh-keys sync
platform cloud-connectors provider-ssh-keys

Removing a credential

Deleting a credential removes NuPaaS's ability to act at that provider. Anything already provisioned keeps running — the servers are yours and live in your provider account — but NuPaaS can no longer enumerate, resize or terminate them, and DNS automation for zones that credential covered stops.

Revoke the key at the provider as well. Deleting the record here stops NuPaaS using it; only the provider can make it stop working.

platform cloud-connectors credentials delete --id <credentialId>