Skip to main content
An Ankra Cloud credential stores an Ankra Cloud API token. One credential serves both cluster types on Ankra Cloud: self-managed Ankra Cloud clusters and managed Ankra Cloud Kubernetes.
Closed beta. Ankra Cloud as a cluster provider is in closed beta. The workflow is stable but the surface may still change, and it is enabled per organisation on request - until it is, Ankra Cloud is not offered as a credential provider. Contact support to have it turned on for your organisation.
The token is validated when you save it: Ankra lists the zones and plans of the account (GET /v1/zones and GET /v1/plans), so a rejected or mistyped token is refused immediately. The token never appears in an error message or on the credential’s page.

What Ankra Accesses

For self-managed clusters, Ankra provisions the infrastructure directly: For Ankra Cloud Kubernetes, Ankra uses the managed Kubernetes API instead:

Creating an Ankra Cloud credential

1

Create an Ankra Cloud API token

  1. Sign in to the Ankra Cloud console
  2. Open Settings → API tokens (owners and admins)
  3. Create a token and copy it (prefixed with act_; shown once)
The token acts with the current role of the user who created it. That user must be allowed to operate the account - create servers, networks, routers and Kubernetes clusters. A read-only user’s token passes the save-time check but fails when Ankra provisions.
2

Add to Ankra

Go to Credentials → Add → Ankra Cloud, then provide:
  • Name: a unique identifier (e.g. ankra-cloud-prod)
  • API Token: the act_... token from the previous step
  • API endpoint (optional): only for a private or development Ankra Cloud. It must be an https:// URL; leave it empty to use https://cloud.ankra.app
Click Test connection to verify the token, then save. You can also add the credential inline from either create-cluster wizard.
For self-managed clusters you also need an SSH key credential. Ankra Cloud Kubernetes needs none.
The token can be rotated later from the credential’s Rotation tab without recreating the credential - everything using it picks up the new token automatically.

Runtime credential

A self-managed cluster runs the Ankra Cloud cloud controller manager and CSI driver inside the cluster, and they need a token too. The create wizard’s Runtime credential picks which Ankra Cloud credential they get: by default the provisioning credential, or a second, dedicated one. A dedicated runtime credential limits what a compromised workload in the cluster could reach through that token. Ankra stores it in the Secret ankra-cloud in kube-system, SOPS-encrypted when the stack is committed to Git.

Listing Ankra Cloud credentials

Troubleshooting