Least-privilege permissions
Create the API key on a Scaleway IAM application dedicated to Ankra, not on a person’s account, and scope every policy rule to the one project Ankra manages. Do not grant Organization-wide scope,IAMFullAccess, billing administration or KubernetesSystemMastersGroupAccess. Scaleway groups permissions into named permission sets:
The runtime key is installed in the cluster, which is why it should be a separate, narrower application than the provisioning one. Every credential for one cluster must target the same project. Saving a credential proves it can read the project, not that it holds every permission a later create or delete needs - run the cluster preflight too.
Creating a Scaleway credential
1
Create an API key in Scaleway
In the Scaleway console, create an IAM application with a policy scoped to your project (see the table above), then generate an API key for it. Copy the access key (
SCW...) and the secret key - Scaleway shows the secret key once. Note the Project ID from the project’s settings.2
Add to Ankra (UI)
Go to Credentials → Add → Scaleway (or Add Scaleway Credential in the cluster wizard), then provide:
- Name: a unique identifier, for example
scw-prod - Access Key: the
SCW...access key - Secret Key: the secret key
- Project ID: the project’s UUID
3
Or via CLI
ankra credentials scaleway ssh-key create --name my-key --generate.
The access key and secret key can be rotated from the credential’s Rotation tab without recreating the credential. The Project ID is fixed: a credential always points at the same project.