Skip to main content

ankra credentials

Commands to list, view, validate, and delete credentials.

ankra credentials ankracloud

List and create Ankra Cloud API credentials. One Ankra Cloud credential serves both self-managed clusters (‘ankra cluster ankracloud create’) and Ankra Cloud Kubernetes (‘ankra cluster managed create --provider ankracloud_k8s’). Ankra Cloud servers take any SSH key credential of the organisation for --ssh-key-credential-id; create one with, for example, ‘ankra credentials hetzner ssh-key create --name my-key --generate’.

ankra credentials ankracloud create

Create an Ankra Cloud API credential from an API token (act_…). The token is never taken from a flag. It is read from stdin with --token-stdin, else from the ANKRA_CLOUD_API_TOKEN environment variable, else from a masked prompt on a terminal. --endpoint names a non-default Ankra Cloud installation (https only); it defaults to https://cloud.ankra.app. Examples:
Flags

ankra credentials ankracloud list

List Ankra Cloud API credentials
Flags

ankra credentials aws

Connect and list the AWS credentials (access key pairs and assumable roles) the organisation uses for cost reporting, EKS and self-managed EC2 clusters. Connecting a role:
  1. ‘onboarding --scope self_managed’ prints the external id the platform generated and the CloudFormation launch-stack URL that creates a role trusting the platform with that id. Open the URL, launch the stack, and copy the role ARN from its outputs.
  2. ‘create-role --name <n> --role-arn <arn> --external-id <id> --scope self_managed’ registers the role. The scope must be the one the stack was launched for; a cost-scoped role cannot build clusters.
Connecting an access key pair instead: ‘create-keys --name <n> --access-key-id <id>’ prompts for the secret access key (masked; pipe it on stdin in scripts) - it is never taken on the command line. Once connected, the credential’s id is what ‘ankra cluster aws create --credential-id’ takes; ‘list’ shows the ids. SSH key credentials are shared across providers: create one with any provider’s ssh-key group (for example ‘ankra credentials hetzner ssh-key create --name ops-key --generate’) and pass its id as --ssh-key-credential-id.

ankra credentials aws create-keys

Register an IAM access key pair. The access key id is a flag; the secret access key is collected via a masked prompt (or read from stdin when piped) and never taken on the command line, so it stays out of shell history. Example:
Flags

ankra credentials aws create-role

Register an IAM role the platform can assume. The role has to trust the platform’s principal with the external id ‘onboarding’ handed out, which the launch stack sets up; pass that same external id here. The scope must match the stack the role was created by: a ‘cost’ role cannot build clusters, ‘ankra cluster aws create’ needs ‘provisioning’ or ‘self_managed’. Example:
Flags

ankra credentials aws list

List AWS credentials
Flags

ankra credentials aws onboarding

Print what connecting an AWS account through an assumable role needs: the external id the platform generated for the role’s trust policy, the principal the role has to trust, and the CloudFormation launch-stack URL that creates the role with exactly that trust and the permissions the scope needs. Each call generates a fresh external id; the one you launch the stack with is the one ‘create-role --external-id’ has to be given. Scopes: ‘cost’ (read-only billing access, the default), ‘provisioning’ (EKS) and ‘self_managed’ (EC2 clusters built by ‘ankra cluster aws’). The launch-stack URL and trust principal are null when the platform is not configured for the scope (“configured: no”); the role then has to be created by hand.
Flags

ankra credentials azure

Commands to list and create Azure service principal credentials used for Azure Kubernetes Service (AKS).

ankra credentials azure create

Store an Azure service principal for AKS. The client secret is read from the AZURE_CLIENT_SECRET environment variable when set, and prompted for (masked) otherwise - it is never accepted as a flag.
Flags

ankra credentials azure list

List Azure credentials
Flags

ankra credentials delete

Delete a credential
Flags

ankra credentials digitalocean

Commands to list and create DigitalOcean API credentials and SSH key credentials.

ankra credentials digitalocean create

Create an DigitalOcean API credential
Flags

ankra credentials digitalocean list

List DigitalOcean API credentials
Flags

ankra credentials digitalocean ssh-key

Manage SSH key credentials

ankra credentials digitalocean ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials digitalocean ssh-key list

List SSH key credentials
Flags

ankra credentials get

Get details of a credential by its ID or by its name (as shown in ankra credentials list).
Flags

ankra credentials hetzner

Commands to list and create Hetzner API credentials and SSH key credentials.

ankra credentials hetzner create

Create a Hetzner API credential
Flags

ankra credentials hetzner list

List Hetzner API credentials
Flags

ankra credentials hetzner ssh-key

Manage SSH key credentials

ankra credentials hetzner ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials hetzner ssh-key list

List SSH key credentials
Flags

ankra credentials list

List all credentials
Flags

ankra credentials morpheus

Commands to list and create HPE Morpheus API credentials and SSH key credentials.

ankra credentials morpheus create

Create an HPE Morpheus API credential. The API access token is collected via a masked prompt, never on the command line. An optional SSH jumphost lets the platform reach a Morpheus API that is not directly routable; pass --jumphost-host together with --jumphost-private-key-file (port defaults to 22, username to root). Examples:
Flags

ankra credentials morpheus list

List HPE Morpheus API credentials
Flags

ankra credentials morpheus ssh-key

Manage SSH key credentials

ankra credentials morpheus ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials morpheus ssh-key list

List SSH key credentials
Flags

ankra credentials ovh

Commands to list and create OVH API credentials and SSH key credentials.

ankra credentials ovh create

Create an OVH API credential. You will be prompted for the required secrets. Generate your OVH API credentials at https://api.ovh.com/createToken/ with GET, POST, PUT, DELETE rights on /cloud/project/* and /cloud/project. Examples:
Flags

ankra credentials ovh list

List OVH API credentials
Flags

ankra credentials ovh ssh-key

Manage SSH key credentials for OVH

ankra credentials ovh ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials ovh ssh-key list

List SSH key credentials
Flags

ankra credentials proxmox

Commands to list and create Proxmox VE API credentials and SSH key credentials.

ankra credentials proxmox create

Create a Proxmox VE API credential. The API token secret is collected via a masked prompt, never on the command line. An optional SSH jumphost lets the platform reach a Proxmox VE API that is not directly routable; pass --jumphost-host together with --jumphost-private-key-file (port defaults to 22, username to root). Examples:
Flags

ankra credentials proxmox list

List Proxmox VE API credentials
Flags

ankra credentials proxmox ssh-key

Manage SSH key credentials

ankra credentials proxmox ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials proxmox ssh-key list

List SSH key credentials
Flags

ankra credentials proxmox tailscale

Commands to set or clear the Tailscale/Headscale settings a Proxmox VE credential passes to the VMs it builds.

ankra credentials proxmox tailscale clear

Remove the Tailscale/Headscale settings from a Proxmox VE credential. VMs built afterwards no longer join the tailnet; VMs already on it stay there.

ankra credentials proxmox tailscale set

Set the Tailscale/Headscale settings a Proxmox VE credential passes to the VMs it builds. Every VM - the bastion/gateway included - joins the tailnet through the QEMU guest agent as it is created. Set this before creating a cluster whose bridge is an SDN vnet: a Proxmox SDN is node-local, so the tailnet join is the only way the platform can reach those VMs. The settings apply to VMs built afterwards; VMs that already exist are not joined retrospectively. The auth key is collected via a masked prompt, never on the command line. Examples:
Flags

ankra credentials repositories

Read the repositories a GitHub credential’s installation can reach right now, against the repositories Ankra needs from it, and report where they disagree. The accessible list is read live from the provider rather than from the cached count shown in ankra credentials list, because that count is only refreshed while the credential reports healthy - so a credential that has stopped being able to read its repository keeps reporting the count it had before it broke.
Flags

ankra credentials scaleway

Commands to list and create Scaleway API credentials and SSH key credentials.

ankra credentials scaleway create

Create a Scaleway API credential from a project-scoped IAM application key. The secret key is collected via a masked prompt, never on the command line - Scaleway shows it once, so store it in a secret manager. The project id is required: it is not derivable from the key, and every resource Ankra creates is scoped to that one project. Examples:
Flags

ankra credentials scaleway list

List Scaleway API credentials
Flags

ankra credentials scaleway ssh-key

Manage SSH key credentials

ankra credentials scaleway ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials scaleway ssh-key list

List SSH key credentials
Flags

ankra credentials upcloud

Commands to list and create UpCloud API credentials and SSH key credentials.

ankra credentials upcloud create

Create an UpCloud API credential
Flags

ankra credentials upcloud list

List UpCloud API credentials
Flags

ankra credentials upcloud ssh-key

Manage SSH key credentials

ankra credentials upcloud ssh-key create

Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:
Flags

ankra credentials upcloud ssh-key list

List SSH key credentials
Flags

ankra credentials validate

Validate a credential name