-f file of kubox cluster create and the configYAML of a Cluster resource. Its shape is internal/model.Config, the type that parses it.
Every field, from internal/model.Config’s yaml tags and doc comments. A field this document does not list is ignored rather than reported, so check each name against this list — a misspelled key is silently dropped, not applied.
Config
ConfigApps
AwsConfig
AzureConfig
string[]
ControllerConfig[]
DNSConfig
ConfigGitOps
IdentityConfig
Identity makes this cluster trust a console, so kubectl works with the same sign-in as everything else. Absent means it trusts nobody and the sealed admin kubeconfig remains the only way in.
Metadata
RbacRole[]
SecretsConfig
ConfigTags[]
ConfigTalos
All types
Every type in the document, in the order the root reaches them. Each is also linked from the field that uses it above.ConfigApps
string
default:"ghcr.io/kubox-ai"
string
AwsConfig
IngressConfig
See IngressConfig.
InstanceMetadataConfig
InstanceMetadata is how the nodes’ IMDS answers pods. Unset leaves AWS’s defaults, under which any pod can read the node’s credentials.
See InstanceMetadataConfig.
AwsNodeGroup[]
See AwsNodeGroup.
string
default:"us-east-1"
Route53Config
See Route53Config.
AzureConfig
AzureNodeGroup[]
See AzureNodeGroup.
string
ControllerConfig
ControllerConfig holds the configuration for a system controller.map of any
Config holds controller-specific configuration options.
boolean
Enabled determines whether this controller should be installed. Defaults to true.
string
Name identifies this entry. It is also the controller to install unless Type says otherwise, so an entry naming a controller directly keeps working.
RoleBinding[]
RoleBindings declare ClusterRoleBindings to apply alongside this controller. The subject is a Kubernetes Group (e.g., a Teleport team group).
See RoleBinding.
string
Type is the controller implementation to install. It defaults to Name, and lets a cluster run two instances of one controller under different names — an nvidia and a gVisor RuntimeClass, say.
DNSConfig
DNSConfig configures global DNS settings.string
e.g., “kubox.cloud”
ConfigGitOps
string
default:"./cluster"
WaitForCRD
See WaitForCRD.
IdentityConfig
IdentityConfig makes a cluster trust a console, so a person can use kubectl with the same sign-in they use everywhere else.string
Audience the token must name. Defaults to kubox-cluster:<cluster name>.
string
CABundle validates the discovery fetch, when the serving certificate is not one the node already trusts. Empty means the in-cluster mirror is served by a certificate from the cluster’s own CA.
string
DiscoveryURL is where THIS cluster fetches the issuer’s keys. Defaults to the in-cluster mirror, which is what almost every deployment should use.
GroupBinding[]
GroupBindings grants a ClusterRole to everyone in a group, so access belongs to an organisation rather than a person and removing someone there removes it here.
See GroupBinding.
string
GroupsClaim carries organisation membership. Defaults to groups.
string
IssuerURL is what the
iss claim in a token says, and must match it exactly.string
UsernameClaim identifies the person. Defaults to email.
Metadata
string
default:"./cluster/config"
string
MetadataPulumi
Pulumi identifies where the cluster’s infrastructure state is stored: which organisation and project it is kept under, and its location.
See MetadataPulumi.
RbacRole
RbacRole is a declarative ClusterRole definition loaded from the cluster config.string
RbacPolicyRule[]
See RbacPolicyRule.
SecretsConfig
SecretsConfig declares secrets kubox itself materialises at create time, as opposed to aws.secrets which are fetched from AWS Secrets Manager.GeneratedSecret[]
See GeneratedSecret.
ConfigTags
string
string
ConfigTalos
string
default:"amd64"
string
string
string
default:"v1.13.10"
IngressConfig
IngressConfig configures internet ingress through the load balancer.AppAuthConfig
AppAuth puts the console’s sign-in in front of every route this gateway serves.
See AppAuthConfig.
boolean
default:"false"
string[]
HostSubdomains are the names this gateway serves, each one label under the gateway hostname: [“app”, “urban”] is served at app.<gateway> and urban.<gateway>. ”@” is the gateway hostname itself, and needs a Routes entry because it has no name to default a backend from.
integer
default:"30080"
integer
default:"30443"
string
default:"staging"
“staging” or “production”
map of IngressRoute
Routes overrides the backend for a host-subdomain. By default a subdomain routes to Service <subdomain>:80 in the gateway namespace (“kubox”).
See IngressRoute.
InstanceMetadataConfig
InstanceMetadataConfig is the IMDS boundary on a node.string
PodAccess is “blocked” or empty (AWS defaults).
AwsNodeGroup
AwsNodeGroup extends NodeGroup with AWS-specific configuration.string
string
AwsIAMInstanceProfile is the IAM instance profile this group’s nodes launch with. Empty means the cloud connection’s node profile on a cluster built through one, and no profile on a laptop build; “none” means no profile either way.
integer
default:"1"
map of string
number
default:"0.0"
integer
default:"30"
string
Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster’s node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
string
default:"true"
string
default:"worker"
string
default:"true"
SpotInstance defaults to true, so a node group is spot unless it opts out with spotInstance: “false”.
string[]
SystemExtensions are Talos system extensions baked into this group’s boot image, e.g. “siderolabs/gvisor”.
string
Route53Config
Route53Config configures AWS Route53 DNS record creation.boolean
default:"false"
Whether to create a subdomain record
string
Optional, defaults to cluster short name
AwsSecret
AwsSecret pulls a secret from AWS Secrets Manager into the cluster.map of string
Maps each key in the created Secret to a key inside the AWS JSON secret. Empty copies the whole value.
string
Name of the secret in AWS Secrets Manager.
string
Name of the Kubernetes Secret. Defaults to the AWS key.
string
Namespace the Kubernetes Secret is created in. Defaults to “default”.
string
Kind of Kubernetes Secret to create: generic, docker-registry, or tls.
AzureNodeGroup
AzureNodeGroup extends NodeGroup with Azure-specific configuration.integer
default:"1"
map of string
integer
default:"30"
string
Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster’s node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
string
default:"true"
string
default:"worker"
string[]
SystemExtensions are Talos system extensions baked into this group’s boot image, e.g. “siderolabs/gvisor”.
string
RoleBinding
RoleBinding is a declarative ClusterRoleBinding that grants a role to a group.string
Name is the ClusterRoleBinding name.
string
Role is the ClusterRole name referenced by the binding.
string
TeleportGroup is the Kubernetes Group subject that receives the role.
WaitForCRD
integer
default:"10"
string
default:"30s"
GroupBinding
GroupBinding grants a ClusterRole to everyone in a group.string
ClusterRole is an existing role: view, edit, cluster-admin, or your own.
string
Group is the claim value, normally
<organisation>:<role>.MetadataPulumi
string
string
string
string
RbacPolicyRule
RbacPolicyRule mirrors the fields of a Kubernetes rbacv1.PolicyRule.string[]
string[]
string[]
string[]
GeneratedSecret
GeneratedSecret is a Secret whose values are created once, on firstkubox admin create, and then left alone: a value that already exists in the cluster is never regenerated, so re-running create (or rotating by hand) does not break anything that holds the old value. Copies are always re-synced from the primary so they cannot drift.
SecretCopy[]
See SecretCopy.
map of string
data key -> environment variable that seeds it
map of string
data key -> generator (hex16, hex32, alnum16, alnum32, uuid)
string
string
defaults to “default”; created if missing
Machine
KubeletConfig
See KubeletConfig.
AppAuthConfig
AppAuthConfig makes the gateway ask the console who somebody is before an app behind it sees the request.string
AuthoriseURL is the console endpoint the gateway asks about each request, e.g. https://app.kubox.cloud/api/gateway/authorize
boolean
default:"false"
IngressRoute
IngressRoute overrides where a host-subdomain’s HTTPRoute sends traffic. Every field is optional; an unset field keeps the default (Service named after the subdomain, gateway namespace, port 80, gateway default timeout).boolean
ModelGrant passes the console’s model grant to this route’s backend. Turn it on only for an app that spends its own users’ model access; any other app is safer never seeing one, since whoever holds a grant can open a model session as that user. Needs appAuth, which is what asks the console for the grant in the first place.
string
backend Service namespace; cross-namespace refs get a ReferenceGrant
integer
backend Service port
string
backend Service name
string
Gateway API duration, e.g. “300s”; applied to both request and backendRequest
Taint
string
string
string
SecretCopy
SecretCopy mirrors keys of a GeneratedSecret into another Secret, typically in another namespace, because Kubernetes Secrets are namespaced.map of string
destination key -> source key; empty copies every key as-is
string
string
KubeletConfig
KubeletConfig represents the kubelet configuration.map of any
boolean
boolean
map of string