Skip to main content
Choose Scaleway Instances when you want a Kubernetes cluster on Scaleway servers in a project you own, with the nodes on a private network and no public addresses. Ankra creates the Instances, the Private Network and a Public Gateway in your Scaleway project, installs Kubernetes and the Scaleway cloud integration, and then operates the cluster for you - this is an Ankra Managed cluster. Scaleway bills you directly.
Closed beta. Scaleway as a cluster provider is in closed beta. The workflow is stable but the surface may still change, and it is enabled per organisation on request - until it is, Scaleway does not appear in the create dialog or among the credential providers, and its endpoints are not served. Contact support to have it turned on for your organisation.
If you would rather have Scaleway run the control plane, use Scaleway Kapsule instead - see Scaleway Kapsule.

Before you start

  • A Scaleway project, ideally one dedicated to Ankra: every resource Ankra creates is scoped to that one project.
  • An API key on a Scaleway IAM application with project-scoped permissions, stored as a Scaleway credential. A second, narrower key for the in-cluster components is recommended - see Scaleway specifics.
  • An SSH key credential. Scaleway clusters take exactly one. See SSH Key Credentials.
  • A region and a zone in that region, for example fr-par and fr-par-1, and either a private CIDR for a new Private Network (a prefix between /20 and /29) or an existing Private Network in the region.

Create the cluster

1

Open the create dialog

Go to Clusters, click Create cluster and pick Scaleway under Ankra Managed.
2

Credentials

Pick the Scaleway credential, the Runtime credential the in-cluster controller and CSI driver use (Reuse provisioning credential is the default), the SSH Key, then the Region and Zone. Regions and zones load live from your project.
3

Network

Choose Create a dedicated network and enter the Network CIDR, or Use an existing network in the region. Pick the Gateway type, set Gateway allowed IPs to the CIDRs that may reach the bastion (empty keeps Scaleway’s defaults), and the Managed bastion SSH port. Storage retention on teardown decides what happens to persistent volumes and load balancers when the cluster is deleted: Retain persistent storage (recommended) or Delete provider storage during teardown.
4

Compute

Set the control-plane count (1, 3 or 5) and instance type, then one or more worker node pools, each with an instance type, count and optional autoscaling. Instance types can be filtered by ARM or Intel/AMD. The cost summary is marked incomplete: the gateway, flexible IP, storage, load balancer and transfer charges are not in it.
5

Kubernetes

Keep kubeadm (the default, Cilium only) or pick K3s with a choice of CNI, and optionally the version. On kubeadm, etcd runs stacked on the control plane or on 3 or 5 dedicated nodes. See Choices fixed at create time.
6

GitOps

Optionally connect a Git repository; without one the scaleway-cloud-provider stack is still deployed, just not committed. Two checkboxes are on by default:
  • Include Networking Stack - Traefik, cert-manager and a Let’s Encrypt ClusterIssuer, with Traefik behind a Scaleway Load Balancer.
  • Include DNS Integration - external-dns, so Ingress hostnames publish their DNS records automatically.
7

Review

Name the cluster and click Run preflight. The checks read your project live; when they pass, click Create cluster. A progress view follows the network, gateway, Instances, Kubernetes installation and Ankra Agent.

Verify

  1. The cluster moves from Provisioning to Online in the clusters list once the Ankra Agent has connected.
  2. Point kubectl at it through Ankra (this needs a Cluster Access grant) and check the nodes:
    Every control plane and worker should be Ready. See Accessing Clusters with kubectl.

What Ankra created in your project

  • A Private Network with its IPAM subnet, unless you adopted an existing one. An adopted network is never deleted.
  • A Public Gateway (v2) with a flexible IP, attached to the Private Network. It is the nodes’ route to the internet and runs the managed SSH bastion.
  • A security group that opens the Kubernetes and CNI overlay ports only to the cluster’s private CIDR - never publicly.
  • The Instances for the control plane, workers and any dedicated etcd nodes, with private addresses only, and a generated SSH key.
  • The scaleway-cloud-provider stack in kube-system: the Scaleway cloud controller manager (Load Balancers for LoadBalancer Services) and the CSI driver (block volumes), both using the runtime credential.

Scaleway specifics

  • Region and zone. Private Networks are regional; Instances, block volumes, security groups and the Public Gateway are zonal. The zone must belong to the region (fr-par-1 in fr-par).
  • Runtime credential. The runtime credential’s key is installed in the cluster for the controller and CSI driver, so give it a second IAM application with narrower permissions than the provisioning one - see Scaleway Credentials. It must target the same project. Without one, the provisioning credential is reused.
  • The bastion is the gateway’s. SSH goes through the Public Gateway’s managed bastion as the user bastion on port 61000 by default - not port 22 on a VM. Settings → Access shows the commands, and GET /api/v1/clusters/scaleway/{cluster_id}/access-info returns the host, port and users. Restrict Gateway allowed IPs to your own addresses. ankra cluster scaleway bastion status reports its health; there is no bastion resize.
  • Storage classes. scw-bssd (the default) deletes a volume when its claim is deleted; scw-bssd-retain keeps it. That Kubernetes reclaim policy is separate from the cluster’s retention_policy, which decides what a cluster teardown does with tagged volumes and load balancers.
  • Stopping keeps the Instances. A stop powers the Instances off and keeps them with their volumes, so the cluster comes back with its state. Root storage, the Public Gateway, flexible IPs, load balancers and retained volumes keep billing while it is stopped.
  • Estimates are incomplete. Scaleway’s APIs do not return gateway, flexible IP, block storage or load balancer prices, so the wizard total leaves them out. Check Scaleway’s pricing and your billing console.

Operate it

Day-2 tasks work the same way on every Ankra Managed provider, with the CLI name scaleway:

Troubleshooting