> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Scaleway Credentials

> Store a project-scoped Scaleway API key in Ankra to build clusters on Scaleway Instances and to create or import Scaleway Kapsule clusters.

export const CliVersion = ({since, command, note}) => {
  const latestStableCli = "0.20.0";
  const parse = version => String(version).split(".").map(part => parseInt(part, 10) || 0);
  const requested = parse(since);
  const stable = parse(latestStableCli);
  let isPrerelease = false;
  for (let index = 0; index < 3; index += 1) {
    if (requested[index] > stable[index]) {
      isPrerelease = true;
      break;
    }
    if (requested[index] < stable[index]) {
      break;
    }
  }
  const containerStyle = {
    display: "flex",
    alignItems: "baseline",
    gap: "0.6rem",
    margin: "1rem 0",
    padding: "0.6rem 0.9rem",
    border: "1px solid rgba(128, 128, 128, 0.35)",
    borderRadius: "0.5rem",
    fontSize: "0.9em",
    lineHeight: 1.5
  };
  const pillStyle = {
    flex: "none",
    padding: "0.1rem 0.5rem",
    borderRadius: "999px",
    background: "rgba(128, 128, 128, 0.18)",
    fontFamily: "ui-monospace, SFMono-Regular, Menlo, monospace",
    fontSize: "0.85em",
    fontWeight: 600,
    whiteSpace: "nowrap"
  };
  const keepTogether = {
    whiteSpace: "nowrap"
  };
  return <div style={containerStyle} data-cli-version={since}>
      <span style={pillStyle}>CLI v{since}+</span>
      <span>
        {command ? <span>
            <span style={keepTogether}>
              <code>ankra {command}</code>
            </span>{" "}
            needs
          </span> : <span>The commands on this page need</span>}{" "}
        the ankra CLI <strong style={keepTogether}>v{since} or later</strong>
        {isPrerelease ? <span>
            {" "}
            - a pre-release today, so enable the{" "}
            <a href="/integrations/ankra-cli#beta-pre-release-channel">beta channel</a> before
            upgrading
          </span> : null}
        . Check yours with{" "}
        <span style={keepTogether}>
          <code>ankra --version</code>
        </span>
        ; <a href="/integrations/ankra-cli#upgrading-the-cli">upgrade</a> with{" "}
        <span style={keepTogether}>
          <code>ankra upgrade</code>
        </span>
        .{note ? <span> {note}</span> : null}
      </span>
    </div>;
};

Scaleway credentials store an API key (access key and secret key) and the Scaleway Project ID it works in. Ankra uses them to build [Scaleway clusters](/guides/scaleway-clusters) on Instances and to create or import [Scaleway Kapsule](/guides/managed-kubernetes#scaleway-kapsule-closed-beta) clusters. The key is validated when you save it: Ankra reads the project with it, so a wrong key or Project ID is refused immediately.

<Warning>
  **Closed beta.** Scaleway credentials are part of the Scaleway provider, which is in closed beta. The workflow is stable but the surface may still change, and it is enabled per organisation on request - until it is, Scaleway does not appear among the credential providers and its endpoints are not served. [Contact support](/platform/support) to have it turned on for your organisation.
</Warning>

## Least-privilege permissions

Create the API key on a Scaleway **IAM application** dedicated to Ankra, not on a person's account, and scope every policy rule to the one project Ankra manages. Do not grant Organization-wide scope, `IAMFullAccess`, billing administration or `KubernetesSystemMastersGroupAccess`. Scaleway groups permissions into named [permission sets](https://www.scaleway.com/en/docs/iam/reference-content/permission-sets/):

| Application | Used for | Permission sets |
| - | - | - |
| **Provisioning** | Building and deleting Instances clusters | `ProjectReadOnly`, `InstancesFullAccess`, `SSHKeysFullAccess`, `PrivateNetworksFullAccess`, `VPCFullAccess`, `VPCGatewayFullAccess`, `IPAMReadOnly`, `LoadBalancersFullAccess`, `BlockStorageFullAccess` |
| **Runtime** | The cloud controller and CSI driver inside an Instances cluster (the cluster's **Runtime credential**) | `ProjectReadOnly`, `InstancesFullAccess`, `BlockStorageFullAccess`, `LoadBalancersFullAccess`, `PrivateNetworksReadOnly`, `VPCReadOnly` |
| **Kapsule** | Creating, importing and operating Kapsule clusters | `ProjectReadOnly`, `KubernetesFullAccess`, `InstancesReadOnly`, `PrivateNetworksReadOnly`, `VPCReadOnly`, `VPCGatewayReadOnly`, `LoadBalancersFullAccess`, `BlockStorageFullAccess` |

The runtime key is installed in the cluster, which is why it should be a separate, narrower application than the provisioning one. Every credential for one cluster must target the same project. Saving a credential proves it can read the project, not that it holds every permission a later create or delete needs - run the cluster preflight too.

## Creating a Scaleway credential

<Steps>
  <Step title="Create an API key in Scaleway">
    In the Scaleway console, create an IAM application with a policy scoped to your project (see the table above), then generate an API key for it. Copy the access key (`SCW...`) and the secret key - Scaleway shows the secret key once. Note the Project ID from the project's settings.
  </Step>

  <Step title="Add to Ankra (UI)">
    Go to **Credentials** → **Add** → **Scaleway** (or **Add Scaleway Credential** in the cluster wizard), then provide:

    * **Name**: a unique identifier, for example `scw-prod`
    * **Access Key**: the `SCW...` access key
    * **Secret Key**: the secret key
    * **Project ID**: the project's UUID

    Click **Test connection**, then save.
  </Step>

  <Step title="Or via CLI">
    <CliVersion since="0.14.0" />

    ```bash theme={null}
    ankra credentials scaleway create --name scw-prod \
      --project-id <project-id> \
      --access-key <access-key>
    # You will be securely prompted for the secret key
    ```
  </Step>
</Steps>

Clusters on Scaleway Instances also need an [SSH key credential](/platform/credentials/ssh-key) - create one with `ankra credentials scaleway ssh-key create --name my-key --generate`.

<Note>
  The access key and secret key can be rotated from the credential's **Rotation** tab without recreating the credential. The Project ID is fixed: a credential always points at the same project.
</Note>

## Listing Scaleway credentials

<CodeGroup>
  ```bash CLI theme={null}
  ankra credentials scaleway list
  ```

  ```bash cURL theme={null}
  curl https://platform.ankra.app/api/v1/credentials/scaleway \
    -H "Authorization: Bearer $ANKRA_API_TOKEN"
  ```
</CodeGroup>

The credential's **Capacity** tab shows the project's usage swept across zones - servers with their vCPU and memory, storage and load balancers. Scaleway does not expose quota headroom through its APIs, so the tab shows usage only.

## Troubleshooting

| Issue | Solution |
| - | - |
| Saving fails with `Scaleway credential validation failed` | Check the Project ID and that the API key is active and allowed to read that project |
| Saving fails with a timeout | Ankra could not reach the Scaleway API; retry |
| A cluster create or delete fails with `403` | The IAM application lacks a permission set from the table above. Add it to the application's policy rather than widening the key to the Organization |
