Choose a credential type
Registry
Helm chart and container registries (HTTP and OCI).
Git
GitHub, GitLab, and other Git providers for GitOps.
Hetzner
Hetzner Cloud API token for cluster provisioning.
OVH
OVHcloud application keys and Public Cloud project.
DigitalOcean
DigitalOcean personal access token for droplets and DOKS.
UpCloud
UpCloud subaccount API access for servers and UKS.
Scaleway (Closed Beta)
Project-scoped API key for Scaleway Instances clusters and Kapsule.
AWS
IAM role or access keys for cost, inventory, EKS, and self-managed clusters on EC2.
Google Cloud (GCP)
Service account - read-only for cost and discovery, or with provisioning roles for GKE.
Azure
Service principal for provisioning AKS.
Proxmox VE
Proxmox API URL and token for self-managed clusters.
Morpheus
Morpheus appliance URL and access token.
Ankra Cloud (Closed Beta)
Ankra Cloud API token for self-managed clusters and Ankra Cloud Kubernetes.
SSH Key
SSH keys for server access on self-managed clusters.
Compare credential types
Using credentials
Credentials are selected by name where they’re needed:- Registries: when adding a Helm registry, pick the registry credential from the dropdown.
- Clusters: when provisioning or importing a cluster, pick the matching cloud credential (and an SSH key for self-managed clusters).
- GitOps: the Git connection is used automatically when syncing configuration.
Managing credentials
View credentials
Go to Credentials to see all stored credentials as cards - each card shows the provider, credential type, health, and when it was last updated. Filter by name or provider, sort, and select multiple cards for bulk deletion. The title and the search, filter and sort row stay in place while the cards scroll. Before you have added a credential, the page offers a shortcut to each kind (source control, cloud providers, container registries, access keys) that opens the provider list at that group. Credentials Ankra manages for the organisation, such as registry robot logins, stay hidden until you choose to show them. When a search or filter matches nothing, Clear filters resets both. Opening a credential shows its identity - provider, availability, whether it is in use, and when it was created - with the rest organised into tabs:- Overview - the identity fields the credential authenticates with (secret values stay masked or in the platform’s secret store) and a Verify connection check that probes the provider API with the stored credential.
- Capacity - the live capacity and usage report, for cloud providers (see below).
- Used by - the clusters running on this credential and any operations currently holding it.
- Rotation - in-place secret rotation, for providers that support it.
Capacity and usage
Open any cloud provider credential and switch to the Capacity tab for a live capacity report read from the provider with that credential:- Hetzner shows project usage: servers with their combined vCPUs, memory, and disk, volumes, load balancers, floating and primary IPs, networks, firewalls, and SSH keys. Hetzner does not expose project limits through its API, so the view shows usage only.
- Proxmox VE shows the total resources of the cluster behind the credential: each node with used and total CPU and memory, storage pools (shared pools counted once), and how many guests are running with the vCPUs and memory allocated to them.
- UpCloud shows the account’s resource limits (CPU cores, memory, storage, IPs, networks, load balancers) as usage bars, plus remaining credits.
- DigitalOcean shows account limits (droplets, floating and reserved IPs) with usage against them, droplet resource sums, volumes, and load balancers.
- OVHcloud shows the project’s per-region quotas: vCPUs, instances, memory, and volume storage as usage bars per region and in total, plus volume and load balancer counts.
- Scaleway shows project usage swept across zones: servers with real vCPU and memory sums, storage, and load balancers. Scaleway does not expose quota headroom through its APIs, so the view shows usage only.
- HPE Morpheus shows each cloud on the appliance with used and total memory and storage plus CPU load, and the appliance’s instance and host counts.
- Azure shows the subscription’s virtual machine and AKS cluster counts, with regional vCPU and VM quota bars for the regions currently in use.
Update a credential
Identity fields are fixed - a credential always points at the same account or infrastructure. What changes is the secret material, and that rotates in place:- Click on the credential name
- Open the Rotation tab
- Enter the new secret and click Verify & rotate
Rotating a credential automatically applies to everything using it. No need to reconfigure registries or clusters.
Delete a credential
- Go to Credentials
- Click the menu (⋮) next to the credential
- Select Delete
AI and MCP access
Ankra’s AI and MCP clients can list and inspect credentials (secret fields are always redacted), validate names, delete unused credentials, and plan and apply a GitHub credential rotation - but they can never create a credential, because that would mean passing the secret itself to the AI, which the platform refuses. See the MCP Tool Reference.Security
Storage
Credentials are stored securely in a dedicated secret store (HashiCorp Vault or OpenBao):- Encrypted at rest
- Access controlled per organisation
- Audit logging for all access
Troubleshooting
Authentication errors
For provider-specific troubleshooting, see the individual credential pages (for example GCP).
API access
Manage credentials via the Ankra API:POST /api/v1/credentials/{provider} with the fields that provider needs; the API reference lists them.
See the API Reference for complete documentation.