Skip to content

Quick start

This page creates your team’s first cluster, in about ten minutes. At the end you have a k3s cluster in your own Hetzner project, you have run kubectl against it, and you can keep it for the Learn path or an app, or delete it with everything the portal created for it.

Your team’s first cluster starts the team’s subscription, and it costs a full month, €29 incl. VAT, or $29 plus applicable sales tax outside the EU, even if you delete it minutes later. While it is the team’s only cluster, deleting it does not credit the rest of the month: the subscription ends with the month already paid. So create it as a cluster you may keep. A cluster you add next to it is charged for the part of the month it exists, and deleting that one credits the rest. Hetzner bills the server by the hour, at its own price. In progress Billing through Paddle has not run yet; Costs and billing has the details.

  • A Hetzner Cloud project that holds nothing else. A Hetzner API token opens its whole project, read and write, so give your clusters a project of their own.
  • An API token of that project with Read & Write permission, created in the Hetzner console under Security → API tokens.
  • kubectl on your computer, and a browser with JavaScript.
  1. In the portal, open PaaSbox Clusters → Hetzner projects and choose Add a Hetzner project. Enter a Project name, paste the token under HCLOUD_TOKEN (read/write) and choose Validate & connect. The portal checks the token by listing your project and stores it encrypted.

  2. Open PaaSbox Clusters and choose New cluster. The first time, a team admin accepts the terms for the team and starts the subscription in Paddle’s checkout In progress.

  3. Name the cluster first. Choose your project, a location near you and the server type cpx22. Under Hetzner token inside the cluster, choose A copy of the project’s token: one token is enough to start; Learn step 1 shows why a cluster you run for long gets a token of its own. Leave everything else as it is.

  4. Choose Create cluster. The cluster’s page shows each step the portal works through. The cluster is ready when pbx-agent on the server reports a healthy Kubernetes API. In the lab that took 2 minutes 46 seconds; 69 seconds of it went into copying the node image into the project, which only the first cluster in a project waits for.

  1. On the cluster’s Access tab, choose the role admin and 1 hour, then Get kubeconfig and Download kubeconfig. Your browser made a key pair for this request, and the kubeconfig was encrypted to it on the server, so the portal could not read it on the way.

  2. Point kubectl at it:

    Terminal window
    export KUBECONFIG=~/Downloads/first-admin.kubeconfig
    kubectl get nodes
    kubectl get pods -A

    One node, first-cp-1, in the state Ready. The pods are what every cluster starts with: CoreDNS, Traefik for ingress, metrics-server, the Hetzner cloud controller and the driver for volumes on the server’s disk.

  3. Run something and reach it:

    Terminal window
    kubectl create deployment hello --image=nginx
    kubectl rollout status deployment/hello
    kubectl port-forward deployment/hello 8080:80

    Open http://localhost:8080: the nginx welcome page, served from your cluster through the Kubernetes API. Stop the port-forward with Ctrl-C.

Keep the cluster if you go on: an app can run on it, and the Learn path starts with a cluster made with deliberate choices. If you create that one first and then delete this one, this one is no longer the team’s only cluster, and the rest of its month is credited.

To delete it:

  1. On the cluster’s Settings tab, under Delete, untick Take a final snapshot first: without a bucket it would land on the server’s disk, which is deleted too. Type first and choose Delete cluster.

  2. The portal deletes the server, the network, the firewall, the IP address and the DNS name. In the lab that took 14 seconds, and no resource with the cluster’s label was left in the project. The node image stays in the project, so the next cluster does not wait for it.

In progress If this was the team’s only cluster, the subscription ends with the month already paid, with no credit; a cluster you create before the month ends uses it.

That is what the approach is built on: a cluster created for a purpose, in minutes. Throwaway clusters for tests come next to a cluster you keep, where each costs only its share of the month (Why isolated clusters for agents).