Skip to content

Add-on catalogue

This page lists every add-on a PaaSbox Clusters cluster can run, with what it installs, its version, its memory and its options. How you switch them on and off, and what happens to their data, is on Choose add-ons.

The memory figures are the estimates the portal adds up when it offers an add-on; the measured figures are under the table.

Add-onDefaultVersionMemory, aboutOptionsStatus
Hetzner cloud controlleralways onchart 1.33.050 MiBnoneBuilt
Local storagealways onLocalPV-LVM 1.10.1120 MiBnoneBuilt
Traefik ingresson, part of k3schart 40.1.4+up40.1.080 MiBaccess logs, client addressesBuilt
Hetzner volumesoffchart 2.21.2120 MiBnoneBuilt
cert-manageroffv1.20.2150 MiBe-mail, issuer, challenge, DNS tokenBuilt HTTP-01; In progress DNS-01
external-dnsoffchart 1.23.050 MiBzones, DNS token, policyIn progress
FluxoffFlux 2.9.5170 MiBnoneBuilt
PaaSbox Platformoff1.0.2150–1230 MiB, by optionsprofile, observability, domain, certificates, …Built
Monitoringoff———Planned
Logsoff———Planned

Flux and the PaaSbox Platform are in release 2026.10.2; the others are in every release so far.

Measured on a cpx22 in the lab run of 2026-10-10, the pods’ own memory (kubectl top): the cloud controller 19 MiB, local storage 87 MiB, Traefik 80 MiB, Hetzner volumes 82 MiB, cert-manager 64 MiB. A fresh cluster with only the always-on add-ons used 1.2 GiB of the server’s 3.8 GiB. Measured in the platform’s lab run: Flux 42 MiB idle and 138 to 189 MiB while the platform installs its parts; the PaaSbox Platform 96 MiB with minimal, 155 to 164 MiB with saas-http01, about 30 MiB more with saas, 826 to 868 MiB with observability.

Add-onRequiresConflicts withSmallest server it is accepted on
PaaSbox PlatformFluxcert-manager4 GB; 8 GB for the profiles saas-http01 and saas with observability
every other add-on———
  • The portal switches a required add-on on together with the one that needs it, refuses to save two conflicting ones as on, and refuses an add-on or an option value on a server with too little memory.
  • pbx-agent applies a required add-on first and the one that needs it only once the first is running; it removes a required add-on only after everything that needs it is gone. pbx-agent has the states it reports.

Connects the cluster to your Hetzner project: the node’s addresses, the private network, and the server type and location as node labels. Always on, no options.

  • It reads the Hetzner token and the network’s ID from the Secret kube-system/hcloud, which pbx-agent writes. When you replace that token in the portal, pbx-agent restarts it.
  • Load balancers are off. Traefik answers on the server’s own ports 80 and 443, and nothing in the cluster creates a Hetzner load balancer that Hetzner would bill you for.

Volumes on the server’s own disk: OpenEBS LocalPV-LVM in the volume group vg0 of the node image. Always on, no options; it is part of the node image and is updated with it.

Storage classDefaultWhat it is
local-lvm-thinyes, the only defaultA thin logical volume; its size is a hard limit
local-lvm-thicknoSpace reserved up front

Local disk speed at no extra cost. A volume lives on the server that first ran its pod. It survives an update of the image in place and a restore in place, but not a move to another server. Backing up its data is yours.

k3s’s own Traefik, the cluster’s ingress controller, with the IngressClass traefik. On a single node it answers on the server’s ports 80 and 443, which the firewall opens to everyone.

OptionDefaultWhat it does
Access logsoffLogs every request to Traefik’s output (kubectl -n kube-system logs deploy/traefik).
Keep client IP addressesoffDelivers requests with the client’s own address instead of the node’s, for access logs and IP allow-lists.

The switch of this add-on adds or removes these settings. It does not turn Traefik off: that is a k3s setting, which the portal does not offer.

Network volumes from your Hetzner project, through Hetzner’s CSI driver: storage class hcloud-volumes, at least 10 GB per volume, billed by Hetzner. A volume survives the server and can be attached to another one. No options.

  • hcloud-volumes is not the default class. Name it in a claim (storageClassName: hcloud-volumes) to use it; claims without a class keep going to the local storage.
  • Volumes carry the label pbx-cluster with the cluster’s ID.
  • Switching the add-on off leaves every volume and claim in place. Deleting the cluster deletes its volumes, after detaching any that is still attached.

Certificates from Let’s Encrypt for your Ingresses. Two ClusterIssuers are installed, letsencrypt-staging and letsencrypt-production. An Ingress annotated kubernetes.io/tls-acme: "true" gets the default one; name another with cert-manager.io/cluster-issuer.

OptionDefaultWhat it does
ACME e-mail (required)Let’s Encrypt registers the account under this address and sends expiry warnings to it.
Default issuerproductionstaging certificates are not trusted by browsers but are not rate-limited: use it to try a setup out.
Challengehttp01http01 proves the name through Traefik on port 80 and needs nothing else. dns01 proves it with a TXT record in your Hetzner DNS zone: needed for wildcard certificates and for names this cluster does not serve.
Hetzner DNS API tokenOnly for dns01: a Read & Write token of the Hetzner project that holds the zone, which may be another project than the cluster’s. Stored encrypted and never shown again.

DNS-01 uses Hetzner’s own webhook for cert-manager. Switching cert-manager off keeps the certificates, their Secrets and cert-manager’s resource definitions. With the PaaSbox Platform on, this add-on must be off: the platform brings a cert-manager of its own.

Creates DNS records in your Hetzner DNS zones for your Ingresses and LoadBalancer Services, with Hetzner’s own provider for external-dns. The records are owned by the cluster’s ID, so it never touches a record it did not create.

OptionDefaultWhat it does
Zones (required)The zones it may write to, comma-separated, such as example.com,example.org. Other zones the token can see are left alone.
Hetzner DNS API token (required)A Read & Write token of the Hetzner project that holds the zones, which may be another project than the cluster’s. Stored encrypted and never shown again.
Policyupsert-onlyupsert-only creates and updates records and never deletes one. sync also deletes the records this cluster created once their Ingress or Service is gone.

Built in a lab: switched on, it was running 71 seconds after the save. In release 2026.10.2, which is not published yet.

Flux’s source controller and kustomize controller, version 1.9.5 of each (Flux 2.9.5), in the namespace flux-system: the cluster pulls Kubernetes manifests from Git repositories and applies them. The PaaSbox Platform needs it, and you can point it at a deploy repository of your own as well. No options.

  • It counts as running once both controllers are available.
  • Switching it off stops the controllers and keeps every GitRepository and Kustomization, and Flux’s resource definitions: nothing is deleted, nothing is pruned.

Built in a lab, on 2026-10-10 and 11, with a copy of its controller image and source: the profiles minimal, saas-http01 and saas with a wildcard certificate over DNS-01, observability, an application with Postgres served over HTTPS with Let’s Encrypt staging certificates, its database backed up to S3, and switching on and off. In progress Release 2026.10.2 can be published only once the controller image and the source are public; certificates from Let’s Encrypt’s production service and a restore of a database from its backup have not run yet.

Turns the cluster into a platform for your SaaS applications: you, or your agent, write SaaSApplication objects (kubectl get saasapp) and get Postgres with backups to S3, Redis, TLS certificates, release hooks and schedules. Your applications stay yours. It requires Flux and replaces the cert-manager add-on.

What it installs:

  • the saas-platform controller in the namespace saas-platform-system, with its two resource definitions, SaaSApplication and Platform, which stay when the add-on is switched off;
  • the Git source its parts are installed from, at the version the release pins, and the ConfigMap cluster-settings;
  • with wildcard certificates, the DNS token as a Secret in the namespace cert-manager;
  • one Platform named after the cluster, which installs cert-manager itself, CloudNativePG for Postgres (profiles saas-http01 and saas) and, with observability, the observability stack.
OptionDefaultWhat it does
Profilesaas-http01saas-http01: Postgres (CloudNativePG with backups and restores) and a Let’s Encrypt certificate per application by HTTP-01. saas: the same with one wildcard certificate for the default domain by DNS-01, which needs a DNS API token. minimal: certificates only, for applications on SQLite.
ObservabilityoffMetrics, logs, traces, alerting and Grafana for the cluster and its applications. It needs about 0.9 GiB: with Postgres, use a server with 8 GB or more.
Default domainApplications without a hostname of their own are served as <name>.<domain>. Point *.<domain> at the server with a DNS A record. Required with wildcard certificates.
CertificatesprofileHow applications under the default domain get certificates. profile: as the profile says (saas: wildcard, the others: one per application). wildcard: one certificate for *.<domain> by DNS-01. perApplication: one each by HTTP-01 (Let’s Encrypt allows 50 new ones per domain and week). none: no certificates.
ACME e-mail (required)Let’s Encrypt registers the account under this address and sends expiry warnings to it. Required since version 1.0.2: without it no certificate issuer is created.
Let’s Encryptproductionstaging issues certificates browsers do not trust, without production’s rate limits: to try a setup out.
DNS API tokenOnly for wildcard certificates: a token of the DNS API that holds the default domain’s zone, a Hetzner project’s API token or a PaaSbox DNS team token. Required with wildcard certificates. Stored encrypted and never shown again.
DNS APIHetzner’sOnly for wildcard certificates: the Hetzner-compatible DNS API. Empty is Hetzner’s own; the PaaSbox DNS service is https://dns.paasbox.com/v1.

Memory, by options, and the smallest server it is accepted on:

OptionsMemory, aboutSmallest server
minimal150 MiB4 GB
saas-http01 (the default)300 MiB4 GB
saas330 MiB4 GB
any profile with observability1050–1230 MiB4 GB for minimal, 8 GB for saas-http01 and saas

The platform’s figures are upper bounds the portal plans with; the lab measured less in every profile. On a cpx22 (4 GB) with Flux and saas-http01 and no application, the lab’s node had 1.4 GiB of memory available: room for one small application. With observability there is none, which is why observability with Postgres needs 8 GB.

  • At create, the form offers the profiles minimal and saas-http01, observability, and an ACME e-mail filled in with your address. It switches Flux on with the platform and refuses a server type with too little memory, naming the smallest that fits. saas needs a default domain and a DNS token, which only the cluster’s Add-ons tab asks for. In progress Creating a cluster with the platform through the REST API or the MCP tools is refused: they pass no ACME e-mail yet.
  • It counts as running once its Platform reports Ready; while Flux installs its parts it stays pending, for minutes. In the lab a part that failed once was tried again by Flux only after an hour; until the platform’s next version, the add-on can stay pending that long.
  • Switching it off while any SaaSApplication exists changes nothing: the add-on reports failed with the applications’ names. Delete them first. Then the platform installs nothing more and removes what it installed, unless something still uses it: a database, or an application that needs one of its parts, keeps everything in place, and the add-on reports why. The Platform’s annotation platform.paasbox.com/allow-removal: <entry> removes an entry anyway, databases included.
  • Postgres backups are set per application, in the SaaSApplication, with the application’s own bucket and keys. The platform needs no bucket of its own.
  • It needs Traefik: applications are served through it.
  • Removing it takes the CRDs it took over. Switched on in place of the cert-manager add-on, the platform takes over cert-manager’s resource definitions. When you switch the platform off, Flux deletes them, and with them every Certificate in the cluster. CloudNativePG’s resource definitions go the same way once no database is left.

Planned As add-ons of their own, after the launch.

  • Monitoring: kube-state-metrics, node-exporter and a scraping agent. Either sent to a remote-write endpoint of yours, or kept in the cluster for a number of days.
  • Logs: a collector on the node. Either sent to an endpoint of yours, or kept in the cluster.

Both stay in your cluster or go to your endpoint. Nothing of either flows to the portal. Until then, the PaaSbox Platform’s observability option In progress is the way to metrics and logs inside the cluster.

  • Your apps. PaaSbox Clusters deploys none; with the PaaSbox Platform, you or your agent write the SaaSApplication.
  • Free-form Helm values. Each add-on has the options above and no others.
  • Cloud Viewer. In progress Pairing Cloud Viewer with the portal installs nothing in the cluster: it reads status from the portal, not from the cluster.