Skip to main content
Scaleway credentials store an API key (access key and secret key) and the Scaleway Project ID it works in. Ankra uses them to build Scaleway clusters on Instances and to create or import Scaleway Kapsule clusters. The key is validated when you save it: Ankra reads the project with it, so a wrong key or Project ID is refused immediately.
Closed beta. Scaleway credentials are part of the Scaleway provider, which is in closed beta. The workflow is stable but the surface may still change, and it is enabled per organisation on request - until it is, Scaleway does not appear among the credential providers and its endpoints are not served. Contact support to have it turned on for your organisation.

Least-privilege permissions

Create the API key on a Scaleway IAM application dedicated to Ankra, not on a person’s account, and scope every policy rule to the one project Ankra manages. Do not grant Organization-wide scope, IAMFullAccess, billing administration or KubernetesSystemMastersGroupAccess. Scaleway groups permissions into named permission sets: The runtime key is installed in the cluster, which is why it should be a separate, narrower application than the provisioning one. Every credential for one cluster must target the same project. Saving a credential proves it can read the project, not that it holds every permission a later create or delete needs - run the cluster preflight too.

Creating a Scaleway credential

1

Create an API key in Scaleway

In the Scaleway console, create an IAM application with a policy scoped to your project (see the table above), then generate an API key for it. Copy the access key (SCW...) and the secret key - Scaleway shows the secret key once. Note the Project ID from the project’s settings.
2

Add to Ankra (UI)

Go to Credentials → Add → Scaleway (or Add Scaleway Credential in the cluster wizard), then provide:
  • Name: a unique identifier, for example scw-prod
  • Access Key: the SCW... access key
  • Secret Key: the secret key
  • Project ID: the project’s UUID
Click Test connection, then save.
3

Or via CLI

Clusters on Scaleway Instances also need an SSH key credential - create one with ankra credentials scaleway ssh-key create --name my-key --generate.
The access key and secret key can be rotated from the credential’s Rotation tab without recreating the credential. The Project ID is fixed: a credential always points at the same project.

Listing Scaleway credentials

The credential’s Capacity tab shows the project’s usage swept across zones - servers with their vCPU and memory, storage and load balancers. Scaleway does not expose quota headroom through its APIs, so the tab shows usage only.

Troubleshooting