Choose add-ons
A cluster comes with a short list of add-ons that you switch on and off, each with the few options it offers. This page shows how, and what happens to an add-on’s data when you switch it off. There are no free-form Helm values: every add-on and every option is tested as part of a release, and the list is the same for every cluster on that release.
The list
Section titled “The list”| Add-on | Default | What it is | Status |
|---|---|---|---|
Hetzner cloud controller (hcloud-ccm) | always on | Connects the cluster to your Hetzner project. No switch. | Built |
Local storage (local-storage) | always on | Volumes on the server’s own disk, storage class local-lvm-thin, the default. Part of the node image. | Built |
Traefik ingress (traefik) | on | k3s’ own ingress controller, on the server’s ports 80 and 443. | Built |
Hetzner volumes (hcloud-csi) | off | Network volumes from your project, storage class hcloud-volumes. | Built |
cert-manager (cert-manager) | off | Certificates from Let’s Encrypt for your Ingresses. | Built HTTP-01; DNS-01 In progress |
external-dns (external-dns) | off | DNS records in your Hetzner DNS zones for your Ingresses. | In progress |
Flux (flux), from release 2026.10.2 | off | Flux’s source and kustomize controllers. | Built in a lab; not published yet In progress |
PaaSbox Platform (paasbox-platform), from release 2026.10.2 | off | Apps as a SaaSApplication, with Postgres, Redis and certificates. | Built in a lab; not published yet In progress |
| Monitoring, logs | — | — | Planned |
The add-on catalogue has every option, version and memory figure.
Switch an add-on on or off
Section titled “Switch an add-on on or off”You need to be a team admin, and the cluster must be running.
-
Open the cluster’s Add-ons tab. Each add-on of the cluster’s release is listed with its version, about how much memory it uses, its options, and what the cluster reports for it (the cluster reports:
pending,applied,failedorremoved, with a message when there is one). -
Change the switch or the options of one add-on and choose Save. The portal says that the add-on is saved and that the node applies it at its next sync.
-
Watch the state.
pbx-agentinstalls the add-on as a k3sHelmChart, or tunes a component k3s ships with aHelmChartConfig, and reportsappliedonce its health check passes; until then it reportspendingwith what it waits for. No add-on change restarts k3s.
Traefik is part of k3s: its switch adds or removes only the portal’s tuning, access logs and client addresses, and Traefik keeps running either way. Turning Traefik off is the k3s setting disable: [traefik], which the portal does not offer.
Add-ons that need or exclude others
Section titled “Add-ons that need or exclude others”The PaaSbox Platform needs Flux, and it cannot run next to cert-manager, because it brings its own. The form shows such rules and offers the other switch under In the same save:, for example Switch Flux on too or Switch cert-manager off in the same save; a save that breaks a rule is refused with the reason. pbx-agent follows the same rules, and applies a required add-on first.
What fits in the server’s memory
Section titled “What fits in the server’s memory”The page adds up the memory of the add-ons that are on. An add-on, or an option of one, that needs a larger server than the cluster has is refused with the size it needs: the PaaSbox Platform with Postgres (saas-http01 or saas) and observability needs 8 GB or more. Choose your setup has the measured figures.
Options that are secrets
Section titled “Options that are secrets”Some options are tokens, such as the DNS token of cert-manager and external-dns. The portal stores them encrypted, sends them to pbx-agent encrypted to the node’s key, and never shows them again; leave the field empty to keep the stored value. In the cluster they go into a Secret named pbx-addon-<name> in kube-system, which the chart reads, never into the HelmChart itself: k3s encrypts Secrets at rest, but not other objects, and a snapshot carries those in clear.
The PaaSbox Platform
Section titled “The PaaSbox Platform”You, or your agent, write a SaaSApplication, and the platform gives it Postgres with backups, Redis, TLS certificates and release hooks. Built in a lab: on 2026-10-11 Flux and the platform ran upcheck on real Hetzner servers, with Let’s Encrypt’s staging service. The release that carries them, 2026.10.2, is In progress: not published yet. Learn step 2 deploys an app on it.
- Switching it on needs Flux: tick Switch Flux on too, and Switch cert-manager off in the same save if that add-on is on. The add-on stays
pendingwhile Flux installs cert-manager, CloudNativePG and the issuers, and isappliedonce the platform reports ready. In the lab Flux alone was applied 71 seconds after its save, and Flux with theminimalprofile in one save after 2 minutes 53 seconds. - If it stays pending: a part of the platform that failed once is tried again only after an hour. Learn step 2 shows how to ask Flux to try it now.
- Profiles:
saas-http01(the default: Postgres, and a certificate per app over HTTP-01),saas(one wildcard certificate over DNS-01, which needs a Default domain and a DNS token; in the lab it was ready 4 minutes after the save) andminimal(certificates only). Observability adds metrics, logs, traces and Grafana; it was applied 104 seconds after its save in the lab, and with Postgres it needs a server with 8 GB or more. The create form offersminimalandsaas-http01;saasis chosen here. - ACME e-mail is required: Let’s Encrypt registers its account under this address. Let’s Encrypt chooses
production(the default) orstaging, which issues certificates browsers do not trust, without production’s rate limits. The lab used staging; production has not run yet. - Switching it off while a
SaaSApplicationexists changes nothing: the add-on reportsfailed: not switched off: SaaSApplications still run on the platformand names them; delete them first. After that, a database that still exists keeps everything in place, and the add-on reportsfailedwith the platform’s message. The annotationplatform.paasbox.com/allow-removalon the platform, naming what may go, lets the removal go ahead; removing Postgres that way deletes every database with it. In the lab, Flux and the platform switched off in one save were removed after 70 seconds. - Certificates after the platform: when you switch the platform off, Flux also deletes the cert-manager CRDs it took over from the cert-manager add-on, and with them every Certificate. If you switch the cert-manager add-on on again, it starts without them, and your Ingresses have to get their certificates anew. CloudNativePG’s CRDs go the same way once the databases are gone, by design.
In the lab a cpx22 with Flux and saas-http01 and no app had 1.4 GiB of memory left: room for one app of upcheck’s size (559 to 606 MiB measured).
Switching off keeps your data
Section titled “Switching off keeps your data”Switching an add-on off removes its chart and keeps your volumes and claims. cert-manager keeps its CRDs, the certificates it issued and their Secrets; its ClusterIssuers go with its chart. After the PaaSbox Platform has run, that no longer holds: the platform takes cert-manager’s CRDs over, and switching it off deletes them (above). Flux keeps its CRDs, so your GitRepositories and Kustomizations stay. Hetzner volumes stay in your project, and Hetzner keeps billing them until you delete them or the cluster; deleting the cluster deletes them.
Changes by hand are overwritten
Section titled “Changes by hand are overwritten”Every object an add-on manages carries the label pbx.io/managed=true. pbx-agent applies the cluster’s configuration again every ten minutes, also without a change in the portal, so a change made by hand to such an object is overwritten. To control an add-on yourself, switch it off in the portal and install your own, under a name of your own. pbx-agent leaves what it did not install alone.
When an add-on fails
Section titled “When an add-on fails”If an add-on cannot be applied, the Add-ons tab shows failed with the reason. pbx-agent keeps the objects that add-on already has: a failed change never uninstalls a running chart.