Connect Cloud Viewer
Cloud Viewer is my app for infrastructure on Hetzner: what every resource costs, logs and metrics from inside your servers, uptime checks from outside, and alerts. Paired with the PaaSbox portal, it also shows your clusters, read-only, and pushes an alert to your phone when a snapshot or an upgrade fails or pbx-agent stops reporting.
What you need
Section titled “What you need”- A team admin in the portal and an admin of the Cloud Viewer team. Pairing hands a read-only view of your clusters to another product, so both sides ask for an admin.
- Cloud Viewer on your phone, or its web app.
Pair the two
Section titled “Pair the two”-
In the portal, open Cloud Viewer in the menu, or PaaSbox Clusters → Cloud Viewer. The page Connect Cloud Viewer opens.
-
Choose Create a pairing code. The portal shows a QR code and the same code as text, three groups of four characters. It works once and is valid for 10 minutes.
-
On a phone, scan the QR code with the camera. Cloud Viewer opens and asks you to confirm; tap Connect. In the web app, open Settings → PaaSbox clusters and enter the code under Connect PaaSbox; case and dashes do not matter.
-
Back in the portal, the Cloud Viewer team appears under Connections, with when it was connected, when it last read and its last alert delivery. Send test sends a test delivery.
What you see in Cloud Viewer
Section titled “What you see in Cloud Viewer”Under Settings → PaaSbox clusters, each cluster with its state, its k3s version and release, its nodes, the last snapshot, the next maintenance window, and flags for what needs attention: pbx-agent no longer reporting, failing snapshots, a failed upgrade, a certificate about to expire, a restart waiting for the window. A link opens the cluster in the portal, where the actions are.
Each cluster also comes with a suggested uptime check for the certificate of its Kubernetes API. Choosing it opens Cloud Viewer’s check form filled in; nothing is added until you confirm it there.
Push alerts
Section titled “Push alerts”The portal sends Cloud Viewer a signed message when:
| Event | Severity |
|---|---|
| Two scheduled snapshots in a row did not arrive | warning |
| An upgrade failed | critical |
pbx-agent has not reported for 15 minutes, and again when it reports | warning, then resolved |
| A certificate has under 30 days left | warning |
| A cluster stopped at a step while being created, deleted or restored | critical |
Cloud Viewer turns each into a push notification once, and stays quiet while the same problem is open. Push alerts come with Cloud Viewer’s Pro and Team plans, like its other alerts. Paired or not, the portal also mails the team’s admins about failing snapshots, a failed upgrade, an expiring certificate, and pbx-agent silent for 24 hours.
What it reads, and what it never does
Section titled “What it reads, and what it never does”- It connects to the portal, never to a cluster. Nothing is installed in your cluster for it.
- It is read-only. Its token reads your team’s cluster summaries: no operations, no kubeconfigs, no secrets.
- No cluster credential and no Hetzner token moves between the two products. To see the servers themselves, add a read-only Hetzner token in Cloud Viewer, as you would without PaaSbox.
- PaaSbox’s data is an addition. When the portal cannot be reached, Cloud Viewer shows the last answer it had and works as before.
Disconnect
Section titled “Disconnect”Choose Revoke next to the connection in the portal, or disconnect in Cloud Viewer under Settings → PaaSbox clusters. Either side ends it for both. Pairing the same PaaSbox team again replaces the old connection.
PaaSbox Clusters does not watch your apps, their endpoints or your servers’ disks and memory; Cloud Viewer does, with its uptime checks and its own agent, under its own plans.