Before you start
- A Scaleway project, ideally one dedicated to Ankra: every resource Ankra creates is scoped to that one project.
- An API key on a Scaleway IAM application with project-scoped permissions, stored as a Scaleway credential. A second, narrower key for the in-cluster components is recommended - see Scaleway specifics.
- An SSH key credential. Scaleway clusters take exactly one. See SSH Key Credentials.
- A region and a zone in that region, for example
fr-parandfr-par-1, and either a private CIDR for a new Private Network (a prefix between/20and/29) or an existing Private Network in the region.
Create the cluster
- Dashboard
- CLI
- API
1
Open the create dialog
Go to Clusters, click Create cluster and pick Scaleway under Ankra Managed.
2
Credentials
Pick the Scaleway credential, the Runtime credential the in-cluster controller and CSI driver use (Reuse provisioning credential is the default), the SSH Key, then the Region and Zone. Regions and zones load live from your project.
3
Network
Choose Create a dedicated network and enter the Network CIDR, or Use an existing network in the region. Pick the Gateway type, set Gateway allowed IPs to the CIDRs that may reach the bastion (empty keeps Scaleway’s defaults), and the Managed bastion SSH port. Storage retention on teardown decides what happens to persistent volumes and load balancers when the cluster is deleted: Retain persistent storage (recommended) or Delete provider storage during teardown.
4
Compute
Set the control-plane count (1, 3 or 5) and instance type, then one or more worker node pools, each with an instance type, count and optional autoscaling. Instance types can be filtered by ARM or Intel/AMD. The cost summary is marked incomplete: the gateway, flexible IP, storage, load balancer and transfer charges are not in it.
5
Kubernetes
Keep kubeadm (the default, Cilium only) or pick K3s with a choice of CNI, and optionally the version. On kubeadm, etcd runs stacked on the control plane or on 3 or 5 dedicated nodes. See Choices fixed at create time.
6
GitOps
Optionally connect a Git repository; without one the
scaleway-cloud-provider stack is still deployed, just not committed. Two checkboxes are on by default:- Include Networking Stack - Traefik, cert-manager and a Let’s Encrypt ClusterIssuer, with Traefik behind a Scaleway Load Balancer.
- Include DNS Integration - external-dns, so Ingress hostnames publish their DNS records automatically.
7
Review
Name the cluster and click Run preflight. The checks read your project live; when they pass, click Create cluster. A progress view follows the network, gateway, Instances, Kubernetes installation and Ankra Agent.
Verify
- The cluster moves from Provisioning to Online in the clusters list once the Ankra Agent has connected.
-
Point
kubectlat it through Ankra (this needs a Cluster Access grant) and check the nodes:Every control plane and worker should beReady. See Accessing Clusters with kubectl.
What Ankra created in your project
- A Private Network with its IPAM subnet, unless you adopted an existing one. An adopted network is never deleted.
- A Public Gateway (v2) with a flexible IP, attached to the Private Network. It is the nodes’ route to the internet and runs the managed SSH bastion.
- A security group that opens the Kubernetes and CNI overlay ports only to the cluster’s private CIDR - never publicly.
- The Instances for the control plane, workers and any dedicated etcd nodes, with private addresses only, and a generated SSH key.
- The
scaleway-cloud-providerstack inkube-system: the Scaleway cloud controller manager (Load Balancers forLoadBalancerServices) and the CSI driver (block volumes), both using the runtime credential.
Scaleway specifics
- Region and zone. Private Networks are regional; Instances, block volumes, security groups and the Public Gateway are zonal. The zone must belong to the region (
fr-par-1infr-par). - Runtime credential. The runtime credential’s key is installed in the cluster for the controller and CSI driver, so give it a second IAM application with narrower permissions than the provisioning one - see Scaleway Credentials. It must target the same project. Without one, the provisioning credential is reused.
- The bastion is the gateway’s. SSH goes through the Public Gateway’s managed bastion as the user
bastionon port61000by default - not port 22 on a VM. Settings → Access shows the commands, andGET /api/v1/clusters/scaleway/{cluster_id}/access-inforeturns the host, port and users. Restrict Gateway allowed IPs to your own addresses.ankra cluster scaleway bastion statusreports its health; there is no bastion resize. - Storage classes.
scw-bssd(the default) deletes a volume when its claim is deleted;scw-bssd-retainkeeps it. That Kubernetes reclaim policy is separate from the cluster’sretention_policy, which decides what a cluster teardown does with tagged volumes and load balancers. - Stopping keeps the Instances. A stop powers the Instances off and keeps them with their volumes, so the cluster comes back with its state. Root storage, the Public Gateway, flexible IPs, load balancers and retained volumes keep billing while it is stopped.
- Estimates are incomplete. Scaleway’s APIs do not return gateway, flexible IP, block storage or load balancer prices, so the wizard total leaves them out. Check Scaleway’s pricing and your billing console.
Operate it
Day-2 tasks work the same way on every Ankra Managed provider, with the CLI namescaleway:
- Node groups and legacy worker scaling
- Control plane
- Restart a node and the bastion
- SSH access and keys
- Upgrade Kubernetes
- Stop and start
- Terminate a cluster