ankra credentials
Commands to list, view, validate, and delete credentials.ankra credentials ankracloud
List and create Ankra Cloud API credentials. One Ankra Cloud credential serves both self-managed clusters (‘ankra cluster ankracloud create’) and Ankra Cloud Kubernetes (‘ankra cluster managed create--provider ankracloud_k8s’).
Ankra Cloud servers take any SSH key credential of the organisation for
--ssh-key-credential-id; create one with, for example,
‘ankra credentials hetzner ssh-key create --name my-key --generate’.
ankra credentials ankracloud create
Create an Ankra Cloud API credential from an API token (act_…). The token is never taken from a flag. It is read from stdin with--token-stdin, else from the ANKRA_CLOUD_API_TOKEN environment variable,
else from a masked prompt on a terminal.
--endpoint names a non-default Ankra Cloud installation (https only); it
defaults to https://cloud.ankra.app.
Examples:
ankra credentials ankracloud list
List Ankra Cloud API credentialsankra credentials aws
Connect and list the AWS credentials (access key pairs and assumable roles) the organisation uses for cost reporting, EKS and self-managed EC2 clusters. Connecting a role:- ‘onboarding
--scopeself_managed’ prints the external id the platform generated and the CloudFormation launch-stack URL that creates a role trusting the platform with that id. Open the URL, launch the stack, and copy the role ARN from its outputs. - ‘create-role
--name<n>--role-arn<arn>--external-id<id>--scopeself_managed’ registers the role. The scope must be the one the stack was launched for; a cost-scoped role cannot build clusters.
--name <n>
--access-key-id <id>’ prompts for the secret access key (masked; pipe it on
stdin in scripts) - it is never taken on the command line.
Once connected, the credential’s id is what ‘ankra cluster aws create
--credential-id’ takes; ‘list’ shows the ids.
SSH key credentials are shared across providers: create one with any
provider’s ssh-key group (for example ‘ankra credentials hetzner ssh-key
create --name ops-key --generate’) and pass its id as
--ssh-key-credential-id.
ankra credentials aws create-keys
Register an IAM access key pair. The access key id is a flag; the secret access key is collected via a masked prompt (or read from stdin when piped) and never taken on the command line, so it stays out of shell history. Example:ankra credentials aws create-role
Register an IAM role the platform can assume. The role has to trust the platform’s principal with the external id ‘onboarding’ handed out, which the launch stack sets up; pass that same external id here. The scope must match the stack the role was created by: a ‘cost’ role cannot build clusters, ‘ankra cluster aws create’ needs ‘provisioning’ or ‘self_managed’. Example:ankra credentials aws list
List AWS credentialsankra credentials aws onboarding
Print what connecting an AWS account through an assumable role needs: the external id the platform generated for the role’s trust policy, the principal the role has to trust, and the CloudFormation launch-stack URL that creates the role with exactly that trust and the permissions the scope needs. Each call generates a fresh external id; the one you launch the stack with is the one ‘create-role--external-id’ has to be given.
Scopes: ‘cost’ (read-only billing access, the default), ‘provisioning’
(EKS) and ‘self_managed’ (EC2 clusters built by ‘ankra cluster aws’).
The launch-stack URL and trust principal are null when the platform is not
configured for the scope (“configured: no”); the role then has to be
created by hand.
ankra credentials azure
Commands to list and create Azure service principal credentials used for Azure Kubernetes Service (AKS).ankra credentials azure create
Store an Azure service principal for AKS. The client secret is read from the AZURE_CLIENT_SECRET environment variable when set, and prompted for (masked) otherwise - it is never accepted as a flag.ankra credentials azure list
List Azure credentialsankra credentials delete
Delete a credentialankra credentials digitalocean
Commands to list and create DigitalOcean API credentials and SSH key credentials.ankra credentials digitalocean create
Create an DigitalOcean API credentialankra credentials digitalocean list
List DigitalOcean API credentialsankra credentials digitalocean ssh-key
Manage SSH key credentialsankra credentials digitalocean ssh-key create
Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:ankra credentials digitalocean ssh-key list
List SSH key credentialsankra credentials get
Get details of a credential by its ID or by its name (as shown inankra credentials list).
ankra credentials hetzner
Commands to list and create Hetzner API credentials and SSH key credentials.ankra credentials hetzner create
Create a Hetzner API credentialankra credentials hetzner list
List Hetzner API credentialsankra credentials hetzner ssh-key
Manage SSH key credentialsankra credentials hetzner ssh-key create
Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:ankra credentials hetzner ssh-key list
List SSH key credentialsankra credentials list
List all credentialsankra credentials morpheus
Commands to list and create HPE Morpheus API credentials and SSH key credentials.ankra credentials morpheus create
Create an HPE Morpheus API credential. The API access token is collected via a masked prompt, never on the command line. An optional SSH jumphost lets the platform reach a Morpheus API that is not directly routable; pass--jumphost-host together with
--jumphost-private-key-file (port defaults to 22, username to root).
Examples:
ankra credentials morpheus list
List HPE Morpheus API credentialsankra credentials morpheus ssh-key
Manage SSH key credentialsankra credentials morpheus ssh-key create
Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:ankra credentials morpheus ssh-key list
List SSH key credentialsankra credentials ovh
Commands to list and create OVH API credentials and SSH key credentials.ankra credentials ovh create
Create an OVH API credential. You will be prompted for the required secrets. Generate your OVH API credentials at https://api.ovh.com/createToken/ with GET, POST, PUT, DELETE rights on /cloud/project/* and /cloud/project. Examples:ankra credentials ovh list
List OVH API credentialsankra credentials ovh ssh-key
Manage SSH key credentials for OVHankra credentials ovh ssh-key create
Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:ankra credentials ovh ssh-key list
List SSH key credentialsankra credentials proxmox
Commands to list and create Proxmox VE API credentials and SSH key credentials.ankra credentials proxmox create
Create a Proxmox VE API credential. The API token secret is collected via a masked prompt, never on the command line. An optional SSH jumphost lets the platform reach a Proxmox VE API that is not directly routable; pass--jumphost-host together with
--jumphost-private-key-file (port defaults to 22, username to root).
Examples:
ankra credentials proxmox list
List Proxmox VE API credentialsankra credentials proxmox ssh-key
Manage SSH key credentialsankra credentials proxmox ssh-key create
Create an SSH key credential. Either provide a public key or generate a new keypair. Examples:ankra credentials proxmox ssh-key list
List SSH key credentialsankra credentials proxmox tailscale
Commands to set or clear the Tailscale/Headscale settings a Proxmox VE credential passes to the VMs it builds.ankra credentials proxmox tailscale clear
Remove the Tailscale/Headscale settings from a Proxmox VE credential. VMs built afterwards no longer join the tailnet; VMs already on it stay there.ankra credentials proxmox tailscale set
Set the Tailscale/Headscale settings a Proxmox VE credential passes to the VMs it builds. Every VM - the bastion/gateway included - joins the tailnet through the QEMU guest agent as it is created. Set this before creating a cluster whose bridge is an SDN vnet: a Proxmox SDN is node-local, so the tailnet join is the only way the platform can reach those VMs. The settings apply to VMs built afterwards; VMs that already exist are not joined retrospectively. The auth key is collected via a masked prompt, never on the command line. Examples:ankra credentials repositories
Read the repositories a GitHub credential’s installation can reach right now, against the repositories Ankra needs from it, and report where they disagree. The accessible list is read live from the provider rather than from the cached count shown inankra credentials list, because that count is only refreshed while the credential reports healthy - so a credential that has stopped being able to read its repository keeps reporting the count it had before it broke.