Skip to content

Choose add-ons

A cluster comes with a short list of add-ons that you switch on and off, each with the few options it offers. This page shows how, and what happens to an add-on’s data when you switch it off. There are no free-form Helm values: every add-on and every option is tested as part of a release, and the list is the same for every cluster on that release.

Add-onDefaultWhat it isStatus
Hetzner cloud controller (hcloud-ccm)always onConnects the cluster to your Hetzner project. No switch.Built
Local storage (local-storage)always onVolumes on the server’s own disk, storage class local-lvm-thin, the default. Part of the node image.Built
Traefik ingress (traefik)onk3s’ own ingress controller, on the server’s ports 80 and 443.Built
Hetzner volumes (hcloud-csi)offNetwork volumes from your project, storage class hcloud-volumes.Built
cert-manager (cert-manager)offCertificates from Let’s Encrypt for your Ingresses.Built HTTP-01; DNS-01 In progress
external-dns (external-dns)offDNS records in your Hetzner DNS zones for your Ingresses.In progress
Flux (flux), from release 2026.10.2offFlux’s source and kustomize controllers.Built in a lab; not published yet In progress
PaaSbox Platform (paasbox-platform), from release 2026.10.2offApps as a SaaSApplication, with Postgres, Redis and certificates.Built in a lab; not published yet In progress
Monitoring, logs——Planned

The add-on catalogue has every option, version and memory figure.

You need to be a team admin, and the cluster must be running.

  1. Open the cluster’s Add-ons tab. Each add-on of the cluster’s release is listed with its version, about how much memory it uses, its options, and what the cluster reports for it (the cluster reports: pending, applied, failed or removed, with a message when there is one).

  2. Change the switch or the options of one add-on and choose Save. The portal says that the add-on is saved and that the node applies it at its next sync.

  3. Watch the state. pbx-agent installs the add-on as a k3s HelmChart, or tunes a component k3s ships with a HelmChartConfig, and reports applied once its health check passes; until then it reports pending with what it waits for. No add-on change restarts k3s.

Traefik is part of k3s: its switch adds or removes only the portal’s tuning, access logs and client addresses, and Traefik keeps running either way. Turning Traefik off is the k3s setting disable: [traefik], which the portal does not offer.

The PaaSbox Platform needs Flux, and it cannot run next to cert-manager, because it brings its own. The form shows such rules and offers the other switch under In the same save:, for example Switch Flux on too or Switch cert-manager off in the same save; a save that breaks a rule is refused with the reason. pbx-agent follows the same rules, and applies a required add-on first.

The page adds up the memory of the add-ons that are on. An add-on, or an option of one, that needs a larger server than the cluster has is refused with the size it needs: the PaaSbox Platform with Postgres (saas-http01 or saas) and observability needs 8 GB or more. Choose your setup has the measured figures.

Some options are tokens, such as the DNS token of cert-manager and external-dns. The portal stores them encrypted, sends them to pbx-agent encrypted to the node’s key, and never shows them again; leave the field empty to keep the stored value. In the cluster they go into a Secret named pbx-addon-<name> in kube-system, which the chart reads, never into the HelmChart itself: k3s encrypts Secrets at rest, but not other objects, and a snapshot carries those in clear.

You, or your agent, write a SaaSApplication, and the platform gives it Postgres with backups, Redis, TLS certificates and release hooks. Built in a lab: on 2026-10-11 Flux and the platform ran upcheck on real Hetzner servers, with Let’s Encrypt’s staging service. The release that carries them, 2026.10.2, is In progress: not published yet. Learn step 2 deploys an app on it.

  • Switching it on needs Flux: tick Switch Flux on too, and Switch cert-manager off in the same save if that add-on is on. The add-on stays pending while Flux installs cert-manager, CloudNativePG and the issuers, and is applied once the platform reports ready. In the lab Flux alone was applied 71 seconds after its save, and Flux with the minimal profile in one save after 2 minutes 53 seconds.
  • If it stays pending: a part of the platform that failed once is tried again only after an hour. Learn step 2 shows how to ask Flux to try it now.
  • Profiles: saas-http01 (the default: Postgres, and a certificate per app over HTTP-01), saas (one wildcard certificate over DNS-01, which needs a Default domain and a DNS token; in the lab it was ready 4 minutes after the save) and minimal (certificates only). Observability adds metrics, logs, traces and Grafana; it was applied 104 seconds after its save in the lab, and with Postgres it needs a server with 8 GB or more. The create form offers minimal and saas-http01; saas is chosen here.
  • ACME e-mail is required: Let’s Encrypt registers its account under this address. Let’s Encrypt chooses production (the default) or staging, which issues certificates browsers do not trust, without production’s rate limits. The lab used staging; production has not run yet.
  • Switching it off while a SaaSApplication exists changes nothing: the add-on reports failed: not switched off: SaaSApplications still run on the platform and names them; delete them first. After that, a database that still exists keeps everything in place, and the add-on reports failed with the platform’s message. The annotation platform.paasbox.com/allow-removal on the platform, naming what may go, lets the removal go ahead; removing Postgres that way deletes every database with it. In the lab, Flux and the platform switched off in one save were removed after 70 seconds.
  • Certificates after the platform: when you switch the platform off, Flux also deletes the cert-manager CRDs it took over from the cert-manager add-on, and with them every Certificate. If you switch the cert-manager add-on on again, it starts without them, and your Ingresses have to get their certificates anew. CloudNativePG’s CRDs go the same way once the databases are gone, by design.

In the lab a cpx22 with Flux and saas-http01 and no app had 1.4 GiB of memory left: room for one app of upcheck’s size (559 to 606 MiB measured).

Switching an add-on off removes its chart and keeps your volumes and claims. cert-manager keeps its CRDs, the certificates it issued and their Secrets; its ClusterIssuers go with its chart. After the PaaSbox Platform has run, that no longer holds: the platform takes cert-manager’s CRDs over, and switching it off deletes them (above). Flux keeps its CRDs, so your GitRepositories and Kustomizations stay. Hetzner volumes stay in your project, and Hetzner keeps billing them until you delete them or the cluster; deleting the cluster deletes them.

Every object an add-on manages carries the label pbx.io/managed=true. pbx-agent applies the cluster’s configuration again every ten minutes, also without a change in the portal, so a change made by hand to such an object is overwritten. To control an add-on yourself, switch it off in the portal and install your own, under a name of your own. pbx-agent leaves what it did not install alone.

If an add-on cannot be applied, the Add-ons tab shows failed with the reason. pbx-agent keeps the objects that add-on already has: a failed change never uninstalls a running chart.