Cloud connectors
A cloud connector is one of your provider credentials, stored so that NuPaaS can act on your behalf: list the servers you already own, provision new ones, and — where the credential allows it — manage DNS records for your domains.
What a connector does
Connectors are org-scoped. Manage them at /orgs/<org>/cloud-connectors, with DNS on its own tab at /orgs/<org>/cloud-connectors/dns.
Each credential record stores a provider, a label you choose, a non-secret key prefix so you can tell two credentials apart at a glance, a status, the time it was last verified, the last error if verification failed, and the capabilities the platform detected on it.
Supported providers
Each provider takes a slightly different credential shape, because each provider's API does.
| Parameter | Type | Description |
|---|---|---|
| hetzner | compute | Label plus an API key. |
| hetzner_robot | compute | Label plus an API key and an access key. |
| digitalocean | compute | Label plus an API key. |
| scaleway | compute | Label, API key and project ID; an access key and organization ID may also be supplied. |
| upcloud | compute | Label plus an API key and an access key. |
| cloudflare | dns | Label plus an API key. |
| route_53 | dns | Label plus an access key ID and secret access key; region is optional. |
Adding a credential
Create the credential at your provider first, scoped as narrowly as that provider allows, then add it here.
platform cloud-connectors credentials add \
--provider hetzner \
--label "hetzner-production" \
--api-key <your-provider-api-key>Give the credential the least privilege that still works. A connector used only to enumerate servers does not need permission to delete them; a DNS credential does not need compute scope at all.
Verification
Verification calls the provider with the stored credential and reports back three things: whether the credential is valid at all, whether it carries DNS edit permission, and — when it does — the zones it can see.
platform cloud-connectors credentials verify --id <credentialId>A failed verification records the provider's error on the credential rather than discarding it, so a credential that stops working tells you why. Verify after any rotation at the provider side.
DNS through a connector
A credential with DNS permission lets NuPaaS manage records for you instead of asking you to create them by hand. Zones can be listed, and within a zone records can be listed, created, updated and deleted.
| Parameter | Type | Description |
|---|---|---|
| A | record | IPv4 address. |
| AAAA | record | IPv6 address. |
| CNAME | record | Alias to another hostname. |
| TXT | record | Text record, used for verification challenges. |
Records carry a TTL, and providers that support proxying expose a proxied flag. This is the machinery behind automatic domain setup — see Domains and TLS for the customer-facing flow.
SSH keys
Connectors also hold the SSH keys NuPaaS uses to reach machines it provisions or adopts on your behalf. A key can be generated for you or imported, and a stored key can be pushed up to a provider so that new servers are created with it already installed.
Three views exist, and they answer different questions: the keys NuPaaS holds, the org-level keys with the providers each has been synced to, and the keys that already exist at each provider — useful for spotting a key that is installed on your servers but that NuPaaS does not know about.
CLI reference
platform cloud-connectors credentials list
platform cloud-connectors credentials add --provider <p> --label <l> --api-key <k>
platform cloud-connectors credentials verify --id <credentialId>
platform cloud-connectors credentials delete --id <credentialId>
platform cloud-connectors ssh-keys list
platform cloud-connectors ssh-keys generate
platform cloud-connectors ssh-keys sync
platform cloud-connectors provider-ssh-keysRemoving a credential
Deleting a credential removes NuPaaS's ability to act at that provider. Anything already provisioned keeps running — the servers are yours and live in your provider account — but NuPaaS can no longer enumerate, resize or terminate them, and DNS automation for zones that credential covered stops.
Revoke the key at the provider as well. Deleting the record here stops NuPaaS using it; only the provider can make it stop working.
platform cloud-connectors credentials delete --id <credentialId>