> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an AWS EC2 cluster (browser session)

> Browser session authentication; RBAC permission `clusters.create`. Creates a self-managed k3s / kubeadm cluster on EC2 (ADR 0015), in a VPC Ankra creates when `vpc_id` is omitted (from `network_ip_range` over `availability_zones`, NAT-gateway egress by default) or in the customer's VPC when `vpc_id`, `node_subnet_ids` and `bastion_subnet_id` are given. The preflight runs first and the first error item is the refusal. Defaults: t3.medium nodes, a t3.small bastion, Ubuntu 24.04 on amd64, a 40 GiB encrypted gp3 root volume, one control plane and one worker, Cilium for either distribution, 10.0.0.0/16 for a created VPC over one zone (three when `control_plane_count` >= 3). `egress_mode` omitted is `nat_gateway` for a created VPC and, for an adopted one, resolved by preflight (`existing` when every node subnet already has egress, `bastion_nat` when none has and none carries a foreign instance). Flannel is accepted but cannot enforce the IMDS guard, so the preflight reports a warning for it; the AWS cloud-controller-manager is always installed. Answers 404 while the organisation's `aws_provider` feature flag is off.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json post /org/clusters/aws
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Organisation IAM
    description: >-
      Custom organisation roles and scoped role assignments for member and
      service-account identities.
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: Ankra Cloud Clusters
    description: >-
      Provision and manage self-managed kubeadm / k3s clusters on Ankra Cloud
      servers: a private network, a NAT router and a bastion per cluster.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Pipelines
    description: Pipeline definitions and the approval of the authority they declare.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Management
    description: >-
      Customer agent lifecycle, authenticated identity and organisation
      automation controls.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Ankra Cloud Credentials
    description: >-
      Ankra Cloud API tokens, shared by the self-managed and managed Ankra Cloud
      lanes.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /org/clusters/aws:
    post:
      tags:
        - AWS Clusters
      summary: Create an AWS EC2 cluster (browser session)
      description: >-
        Browser session authentication; RBAC permission `clusters.create`.
        Creates a self-managed k3s / kubeadm cluster on EC2 (ADR 0015), in a VPC
        Ankra creates when `vpc_id` is omitted (from `network_ip_range` over
        `availability_zones`, NAT-gateway egress by default) or in the
        customer's VPC when `vpc_id`, `node_subnet_ids` and `bastion_subnet_id`
        are given. The preflight runs first and the first error item is the
        refusal. Defaults: t3.medium nodes, a t3.small bastion, Ubuntu 24.04 on
        amd64, a 40 GiB encrypted gp3 root volume, one control plane and one
        worker, Cilium for either distribution, 10.0.0.0/16 for a created VPC
        over one zone (three when `control_plane_count` >= 3). `egress_mode`
        omitted is `nat_gateway` for a created VPC and, for an adopted one,
        resolved by preflight (`existing` when every node subnet already has
        egress, `bastion_nat` when none has and none carries a foreign
        instance). Flannel is accepted but cannot enforce the IMDS guard, so the
        preflight reports a warning for it; the AWS cloud-controller-manager is
        always installed. Answers 404 while the organisation's `aws_provider`
        feature flag is off.
      operationId: create_aws_cluster_browser
      parameters:
        - description: Must match the ankra_csrf browser cookie.
          in: header
          name: X-Ankra-CSRF
          required: true
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateAwsClusterRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AwsCreateClusterResponse'
          description: Successful response
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Invalid request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Unauthenticated
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Permission or CSRF check failed
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Resource not found
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Conflicting or unsafe lifecycle state
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation failed
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContractDetailError'
          description: Provider or internal failure
      security:
        - SessionCookie: []
components:
  schemas:
    CreateAwsClusterRequest:
      description: >-
        POST /clusters/aws body. Two network shapes (ADR 0015 §3): omit vpc_id
        and Ankra creates the VPC from network_ip_range over availability_zones
        (one public /24 and one private /20 per zone, an internet gateway, and
        NAT gateways as the default egress), all torn down with the cluster;
        pass vpc_id with node_subnet_ids and bastion_subnet_id to adopt an
        existing VPC, whose network Ankra never modifies. Nodes never receive a
        public IP; the bastion holds the elastic IP and is the SSH hop (and the
        NAT instance in bastion_nat mode).
      properties:
        name:
          type: string
        description:
          anyOf:
            - type: string
            - type: 'null'
        credential_id:
          type: string
          format: uuid
          description: >-
            An organisation aws credential: a keys credential, or a role
            onboarded with scope provisioning or self_managed (cost-scoped roles
            are refused).
        ssh_key_credential_id:
          type: string
          format: uuid
        region:
          type: string
          description: Region slug, validated against ec2:DescribeRegions.
        vpc_id:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            An existing VPC to adopt; node_subnet_ids and bastion_subnet_id are
            then required and network_ip_range / availability_zones /
            nat_gateway_single_zone are refused. Omitted (or empty): Ankra
            creates the VPC (network_ownership created).
        node_subnet_ids:
          anyOf:
            - type: array
              items:
                type: string
              minItems: 1
            - type: 'null'
          description: >-
            Adopted VPC only: private subnets the nodes spread across; one or
            more, their zones become the cluster's zone pool. Refused (422) when
            no vpc_id is given - a created VPC lays out its own subnets.
        bastion_subnet_id:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Adopted VPC only: a public subnet (internet-gateway default route)
            for the bastion. Refused (422) when no vpc_id is given.
        network_ip_range:
          type: string
          default: 10.0.0.0/16
          description: >-
            Created VPC only: the IPv4 CIDR the VPC is created with, /16 to /20
            as a network address; it must hold a private /20 and a public /24
            per availability zone (the preflight's cidr item says what it
            holds). Refused (422) alongside vpc_id.
        availability_zones:
          anyOf:
            - type: array
              items:
                type: string
            - type: 'null'
          description: >-
            Created VPC only: the zones the VPC is laid out over, in the order
            the spread walks them (the bastion and the first control plane land
            in the first). Each must exist and be available in the region; more
            than one needs control_plane_count >= 3. Omitted: the preflight
            picks one zone when control_plane_count < 3 and three otherwise,
            from the region's available zones in name order, and reports them as
            resolved_availability_zones. Refused (422) alongside vpc_id.
        nat_gateway_single_zone:
          type: boolean
          default: false
          description: >-
            Created VPC with nat_gateway egress only: false creates one NAT
            gateway (and elastic IP) per zone; true creates one in the first
            zone that every private subnet routes through - cheaper, one egress
            failure domain. Refused (422) when true alongside vpc_id.
        egress_mode:
          anyOf:
            - type: string
              enum:
                - nat_gateway
                - bastion_nat
                - existing
              description: >-
                Which modes apply depends on the network shape. Created VPC:
                nat_gateway (default; Ankra-created NAT gateways with their own
                elastic IPs) or bastion_nat (the bastion is the NAT instance);
                existing is refused (422). Adopted VPC: omitted is resolved by
                preflight; existing keeps the subnets' NAT routing; bastion_nat
                makes the bastion the NAT instance behind one Ankra-owned route
                table and is refused when a node subnet carries instances Ankra
                did not create; nat_gateway is refused (422) because it would
                re-point the customer's route tables.
            - type: 'null'
        bastion_instance_type:
          type: string
          default: t3.small
        bastion_allowed_ips:
          type: array
          items:
            type: string
          description: >-
            IPv4 CIDRs allowed to SSH to the bastion. Optional: omitted or empty
            means 0.0.0.0/0 (open to everyone; key-only, password login off,
            sshd rate-limited on the host). Name your own CIDRs to restrict it;
            preflight reports the exposure as bastion_ssh_exposure.
        control_plane_count:
          type: integer
          default: 1
          minimum: 1
          maximum: 9
          description: >-
            At least 3 when the cluster spans more than one availability zone
            (an adopted VPC's node subnets, or a created VPC's
            availability_zones); it also decides how many zones a created VPC
            defaults to (1 below 3, 3 otherwise).
        control_plane_type:
          type: string
          default: t3.medium
        worker_count:
          default: 1
          maximum: 100
          minimum: 0
          type: integer
        worker_type:
          type: string
          default: t3.medium
        node_groups:
          anyOf:
            - type: array
              items:
                $ref: '#/components/schemas/AwsCreateNodeGroupRequest'
            - type: 'null'
        distribution:
          type: string
          enum:
            - k3s
            - kubeadm
          default: kubeadm
        kubernetes_version:
          anyOf:
            - type: string
            - type: 'null'
        etcd_topology:
          type: string
          enum:
            - stacked
            - external
          default: stacked
        etcd_node_count:
          type: integer
          default: 3
        etcd_type:
          type: string
          default: t3.medium
        cni:
          type: string
          enum:
            - flannel
            - calico
            - cilium
          default: cilium
          description: >-
            Defaults to cilium for both distributions: the AWS stack's IMDS
            guard is a network policy only Cilium and Calico enforce. flannel is
            accepted with a preflight warning; kubeadm requires cilium.
        cni_features:
          $ref: '#/components/schemas/AwsCNIFeatures'
        k3s_disabled_components:
          anyOf:
            - type: array
              items:
                type: string
            - type: 'null'
        ubuntu_series:
          type: string
          default: '24.04'
        architecture:
          type: string
          enum:
            - amd64
          default: amd64
          description: >-
            arm64 is refused with a 422 naming the pending image-catalogue audit
            (ADR 0015 §6).
        root_volume_gib:
          type: integer
          default: 40
          minimum: 20
          maximum: 2000
          description: Encrypted gp3 root volume of every instance.
        gitops_credential_name:
          type: string
        gitops_repository:
          type: string
        gitops_branch:
          type: string
          default: master
        gitops_provider:
          type: string
          enum:
            - github
            - bitbucket_cloud
          default: github
          description: >-
            GitOps provider of the repository the cluster is bootstrapped onto.
            Omitted is github, where gitops_repository is owner/name.
            bitbucket_cloud names the repository by gitops_workspace and
            gitops_repo_slug (or gitops_repository as workspace/repo_slug) and
            binds it as a Bitbucket Cloud repository.
        gitops_workspace:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Bitbucket Cloud workspace of the GitOps repository. Only with
            gitops_provider bitbucket_cloud; provided together with
            gitops_repo_slug.
        gitops_repo_slug:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            Bitbucket Cloud repository slug of the GitOps repository. Only with
            gitops_provider bitbucket_cloud; provided together with
            gitops_workspace.
        include_networking:
          type: boolean
          default: true
        include_dns:
          type: boolean
          default: true
        retention_policy:
          type: string
          enum:
            - delete
            - retain
          default: retain
        external_cloud_provider:
          type: boolean
          default: true
          description: >-
            Must be true when present: the AWS cloud-controller-manager is
            mandatory.
        environment:
          anyOf:
            - type: string
            - type: 'null'
        criticality:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - name
        - credential_id
        - ssh_key_credential_id
        - region
        - bastion_allowed_ips
      type: object
    AwsCreateClusterResponse:
      example:
        cluster_id: 11111111-2222-4333-8444-555555555555
        name: aws-prod
        kind: aws
        state: creating
        operation_id: null
      properties:
        cluster_id:
          type: string
          format: uuid
        name:
          type: string
        kind:
          type: string
          const: aws
        state:
          type: string
        operation_id:
          anyOf:
            - type: string
              format: uuid
            - type: 'null'
      required:
        - cluster_id
        - name
        - kind
        - state
        - operation_id
      type: object
    ContractDetailError:
      example:
        detail: Cluster not found
      properties:
        detail:
          oneOf:
            - type: string
            - additionalProperties: true
              properties: {}
              type: object
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    AwsCreateNodeGroupRequest:
      properties:
        autoscaling:
          anyOf:
            - properties:
                enabled:
                  type: boolean
                max_count:
                  type: integer
                min_count:
                  type: integer
              required:
                - enabled
                - min_count
                - max_count
              type: object
            - type: 'null'
        count:
          default: 1
          maximum: 100
          minimum: 0
          type: integer
        instance_type:
          type: string
        labels:
          additionalProperties:
            type: string
          type: object
        name:
          type: string
        taints:
          items:
            $ref: '#/components/schemas/AwsNodeTaint'
          type: array
        availability_zone:
          anyOf:
            - type: string
              description: >-
                Pins every node of the group to one of the node subnets' zones;
                omitted spreads the group.
            - type: 'null'
      required:
        - name
        - instance_type
      type: object
    AwsCNIFeatures:
      properties:
        ebpf_dataplane:
          default: false
          type: boolean
        hubble:
          default: false
          type: boolean
        kube_proxy_replacement:
          default: false
          type: boolean
        wireguard_encryption:
          default: false
          type: boolean
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
    AwsNodeTaint:
      properties:
        effect:
          enum:
            - NoSchedule
            - PreferNoSchedule
            - NoExecute
          type: string
        key:
          type: string
        value:
          default: ''
          type: string
      required:
        - key
        - effect
      type: object
  securitySchemes:
    SessionCookie:
      description: Browser session. Mutations also require X-Ankra-CSRF.
      in: cookie
      name: ankra_session
      type: apiKey

````