Documentation/First success
First success · v0.0.1

Configure the first cloud provider

Select a provider by maturity, enter write-only credentials, validate once and confirm discovery before lifecycle work.

AudiencePlatform operatorsReading time12 minutesCommands in context1 guided stepsReviewed sourcefcc5871 · 30 July 2026
RC

Exact release scope. This page documents the reviewed v0.0.1 source at fcc5871. Check release status before enabling a gated capability.

Choose by support boundary

Providerv0.0.1 postureRecommended use
Hetzner CloudStable · production-gatedSupported controlled path with environment approval
Amazon Web ServicesDisabled in v0.0.1Unavailable in v0.0.1; do not enable
Microsoft AzureDisabled in v0.0.1Unavailable in v0.0.1; do not enable
IONOS CloudStable · production-gatedSupported controlled path with environment approval

Prepare a scoped credential

  • Use a dedicated project, subscription or account boundary
  • Grant only the documented validation, discovery and lifecycle permissions
  • Apply provider-side quota and budget alerts
  • Deliver the credential through the write-only UI/API field
  • Never place provider secrets in screenshots, plans, OperationRun options or support bundles

Register and validate

  1. 01

    Settings → Cloud providers → Add account

    Select the explicit provider type and a human-readable account name.

  2. 02

    Enter credential material

    The value is accepted write-only. ClusterPilot returns only secret-safe metadata.

  3. 03

    Validate once

    Validation uses the registered adapter. Invalid credentials return typed ProblemDetails; transport failures do not trigger browser retry loops.

  4. 04

    Review capabilities

    Confirm provider maturity, supported operations, regions/images/sizes and warnings before creating infrastructure.

When validation fails

SymptomLikely boundarySafe response
Invalid credentialsProvider rejected identityRotate/re-enter scoped material and validate once
Outbound request blockedAllowed-host or SSRF policyReview exact provider endpoint; do not widen to wildcard
Rate limitedProvider quotaHonor Retry-After and stop client retry loops
Circuit openRepeated provider failureRepair dependency, then use the serialized reset workflow
Discovery incompletePermission, region or provider APICompare capability warnings and provider audit logs