Set the limits first
Kubox never sets its own limits — that step is yours. The console shows you exactly what to run, so your security team can read it first.
kubox cloud bootstrap.
Two bootstrap commands — pick by account
The names are similar. The jobs are not.
Both are run once per account, by an administrator, and both are safe to run again.
Connect the account
--hosted-zone to limit it to one zone. Leave it out and the connection touches no DNS at all. See kubox cloud connect for every option.
Read a permission before you grant it
kubox admin aws policy.
Check a connection still works
status
Shows the last recorded result. That check may be days old.
verify
Tests the connection now, from both ends.
verify when you need to know the connection works today. status only repeats the last result, so a green there is not proof.
verify checks from both ends because each catches what the other misses. A role can look correct in your account and still be one AWS will not accept — or accept a connection it should have refused.
Disconnecting is not revoking
This is the distinction worth remembering.
The command disconnects, then lists what is still in your account — the role, the keys, the bucket — and what deleting each one costs you.
Kubox leaves those alone on purpose. They are the record of what was built, and the keys that open it. If Kubox could delete them, Kubox would hold the power this boundary exists to deny it.
Related
Architecture
Where accounts sit among planes and clusters.
Management plane
What is doing the building.
All cloud commands
The full
kubox cloud surface.