Skip to main content
The document a cluster is built from — the -f file of kubox cluster create and the configYAML of a Cluster resource. Its shape is internal/model.Config, the type that parses it. Every field, from internal/model.Config’s yaml tags and doc comments. A field this document does not list is ignored rather than reported, so check each name against this list — a misspelled key is silently dropped, not applied.

Config

ConfigApps
AwsConfig
AzureConfig
string[]
ControllerConfig[]
DNSConfig
ConfigGitOps
IdentityConfig
Identity makes this cluster trust a console, so kubectl works with the same sign-in as everything else. Absent means it trusts nobody and the sealed admin kubeconfig remains the only way in.
Metadata
RbacRole[]
SecretsConfig
ConfigTags[]
ConfigTalos

All types

Every type in the document, in the order the root reaches them. Each is also linked from the field that uses it above.

ConfigApps

string
default:"ghcr.io/kubox-ai"
string

AwsConfig

IngressConfig
InstanceMetadataConfig
InstanceMetadata is how the nodes’ IMDS answers pods. Unset leaves AWS’s defaults, under which any pod can read the node’s credentials. See InstanceMetadataConfig.
AwsNodeGroup[]
string
default:"us-east-1"
Route53Config
AwsSecret[]

AzureConfig

AzureNodeGroup[]
string

ControllerConfig

ControllerConfig holds the configuration for a system controller.
map of any
Config holds controller-specific configuration options.
boolean
Enabled determines whether this controller should be installed. Defaults to true.
string
Name identifies this entry. It is also the controller to install unless Type says otherwise, so an entry naming a controller directly keeps working.
RoleBinding[]
RoleBindings declare ClusterRoleBindings to apply alongside this controller. The subject is a Kubernetes Group (e.g., a Teleport team group). See RoleBinding.
string
Type is the controller implementation to install. It defaults to Name, and lets a cluster run two instances of one controller under different names — an nvidia and a gVisor RuntimeClass, say.

DNSConfig

DNSConfig configures global DNS settings.
string
e.g., “kubox.cloud”

ConfigGitOps

string
default:"./cluster"
WaitForCRD

IdentityConfig

IdentityConfig makes a cluster trust a console, so a person can use kubectl with the same sign-in they use everywhere else.
string
Audience the token must name. Defaults to kubox-cluster:<cluster name>.
string
CABundle validates the discovery fetch, when the serving certificate is not one the node already trusts. Empty means the in-cluster mirror is served by a certificate from the cluster’s own CA.
string
DiscoveryURL is where THIS cluster fetches the issuer’s keys. Defaults to the in-cluster mirror, which is what almost every deployment should use.
GroupBinding[]
GroupBindings grants a ClusterRole to everyone in a group, so access belongs to an organisation rather than a person and removing someone there removes it here. See GroupBinding.
string
GroupsClaim carries organisation membership. Defaults to groups.
string
IssuerURL is what the iss claim in a token says, and must match it exactly.
string
UsernameClaim identifies the person. Defaults to email.

Metadata

string
default:"./cluster/config"
string
MetadataPulumi
Pulumi identifies where the cluster’s infrastructure state is stored: which organisation and project it is kept under, and its location. See MetadataPulumi.

RbacRole

RbacRole is a declarative ClusterRole definition loaded from the cluster config.
string
RbacPolicyRule[]

SecretsConfig

SecretsConfig declares secrets kubox itself materialises at create time, as opposed to aws.secrets which are fetched from AWS Secrets Manager.
GeneratedSecret[]

ConfigTags

string
string

ConfigTalos

string
default:"amd64"
string
Machine
See Machine.
string
string
default:"v1.13.10"

IngressConfig

IngressConfig configures internet ingress through the load balancer.
AppAuthConfig
AppAuth puts the console’s sign-in in front of every route this gateway serves. See AppAuthConfig.
boolean
default:"false"
string[]
HostSubdomains are the names this gateway serves, each one label under the gateway hostname: [“app”, “urban”] is served at app.<gateway> and urban.<gateway>. ”@” is the gateway hostname itself, and needs a Routes entry because it has no name to default a backend from.
integer
default:"30080"
integer
default:"30443"
string
default:"staging"
“staging” or “production”
map of IngressRoute
Routes overrides the backend for a host-subdomain. By default a subdomain routes to Service <subdomain>:80 in the gateway namespace (“kubox”). See IngressRoute.

InstanceMetadataConfig

InstanceMetadataConfig is the IMDS boundary on a node.
string
PodAccess is “blocked” or empty (AWS defaults).

AwsNodeGroup

AwsNodeGroup extends NodeGroup with AWS-specific configuration.
string
string
AwsIAMInstanceProfile is the IAM instance profile this group’s nodes launch with. Empty means the cloud connection’s node profile on a cluster built through one, and no profile on a laptop build; “none” means no profile either way.
integer
default:"1"
map of string
number
default:"0.0"
integer
default:"30"
string
Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster’s node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
string
default:"true"
string
default:"worker"
string
default:"true"
SpotInstance defaults to true, so a node group is spot unless it opts out with spotInstance: “false”.
string[]
SystemExtensions are Talos system extensions baked into this group’s boot image, e.g. “siderolabs/gvisor”.
Taint[]
See Taint.
string

Route53Config

Route53Config configures AWS Route53 DNS record creation.
boolean
default:"false"
Whether to create a subdomain record
string
Optional, defaults to cluster short name

AwsSecret

AwsSecret pulls a secret from AWS Secrets Manager into the cluster.
map of string
Maps each key in the created Secret to a key inside the AWS JSON secret. Empty copies the whole value.
string
Name of the secret in AWS Secrets Manager.
string
Name of the Kubernetes Secret. Defaults to the AWS key.
string
Namespace the Kubernetes Secret is created in. Defaults to “default”.
string
Kind of Kubernetes Secret to create: generic, docker-registry, or tls.

AzureNodeGroup

AzureNodeGroup extends NodeGroup with Azure-specific configuration.
integer
default:"1"
map of string
integer
default:"30"
string
Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster’s node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
string
default:"true"
string
default:"worker"
string[]
SystemExtensions are Talos system extensions baked into this group’s boot image, e.g. “siderolabs/gvisor”.
Taint[]
See Taint.
string

RoleBinding

RoleBinding is a declarative ClusterRoleBinding that grants a role to a group.
string
Name is the ClusterRoleBinding name.
string
Role is the ClusterRole name referenced by the binding.
string
TeleportGroup is the Kubernetes Group subject that receives the role.

WaitForCRD

integer
default:"10"
string
default:"30s"

GroupBinding

GroupBinding grants a ClusterRole to everyone in a group.
string
ClusterRole is an existing role: view, edit, cluster-admin, or your own.
string
Group is the claim value, normally <organisation>:<role>.

MetadataPulumi

string
string
string
string

RbacPolicyRule

RbacPolicyRule mirrors the fields of a Kubernetes rbacv1.PolicyRule.
string[]
string[]
string[]
string[]

GeneratedSecret

GeneratedSecret is a Secret whose values are created once, on first kubox admin create, and then left alone: a value that already exists in the cluster is never regenerated, so re-running create (or rotating by hand) does not break anything that holds the old value. Copies are always re-synced from the primary so they cannot drift.
SecretCopy[]
map of string
data key -> environment variable that seeds it
map of string
data key -> generator (hex16, hex32, alnum16, alnum32, uuid)
string
string
defaults to “default”; created if missing

Machine

KubeletConfig

AppAuthConfig

AppAuthConfig makes the gateway ask the console who somebody is before an app behind it sees the request.
string
AuthoriseURL is the console endpoint the gateway asks about each request, e.g. https://app.kubox.cloud/api/gateway/authorize
boolean
default:"false"

IngressRoute

IngressRoute overrides where a host-subdomain’s HTTPRoute sends traffic. Every field is optional; an unset field keeps the default (Service named after the subdomain, gateway namespace, port 80, gateway default timeout).
boolean
ModelGrant passes the console’s model grant to this route’s backend. Turn it on only for an app that spends its own users’ model access; any other app is safer never seeing one, since whoever holds a grant can open a model session as that user. Needs appAuth, which is what asks the console for the grant in the first place.
string
backend Service namespace; cross-namespace refs get a ReferenceGrant
integer
backend Service port
string
backend Service name
string
Gateway API duration, e.g. “300s”; applied to both request and backendRequest

Taint

string
string
string

SecretCopy

SecretCopy mirrors keys of a GeneratedSecret into another Secret, typically in another namespace, because Kubernetes Secrets are namespaced.
map of string
destination key -> source key; empty copies every key as-is
string
string

KubeletConfig

KubeletConfig represents the kubelet configuration.
map of any
boolean
boolean
map of string