Add-on catalogue
This page lists every add-on a PaaSbox Clusters cluster can run, with what it installs, its version, its memory and its options. How you switch them on and off, and what happens to their data, is on Choose add-ons.
The memory figures are the estimates the portal adds up when it offers an add-on; the measured figures are under the table.
| Add-on | Default | Version | Memory, about | Options | Status |
|---|---|---|---|---|---|
| Hetzner cloud controller | always on | chart 1.33.0 | 50 MiB | none | Built |
| Local storage | always on | LocalPV-LVM 1.10.1 | 120 MiB | none | Built |
| Traefik ingress | on, part of k3s | chart 40.1.4+up40.1.0 | 80 MiB | access logs, client addresses | Built |
| Hetzner volumes | off | chart 2.21.2 | 120 MiB | none | Built |
| cert-manager | off | v1.20.2 | 150 MiB | e-mail, issuer, challenge, DNS token | Built HTTP-01; In progress DNS-01 |
| external-dns | off | chart 1.23.0 | 50 MiB | zones, DNS token, policy | In progress |
| Flux | off | Flux 2.9.5 | 170 MiB | none | Built |
| PaaSbox Platform | off | 1.0.2 | 150–1230 MiB, by options | profile, observability, domain, certificates, … | Built |
| Monitoring | off | — | — | — | Planned |
| Logs | off | — | — | — | Planned |
Flux and the PaaSbox Platform are in release 2026.10.2; the others are in every release so far.
Measured on a cpx22 in the lab run of 2026-10-10, the pods’ own memory (kubectl top): the cloud controller 19 MiB, local storage 87 MiB, Traefik 80 MiB, Hetzner volumes 82 MiB, cert-manager 64 MiB. A fresh cluster with only the always-on add-ons used 1.2 GiB of the server’s 3.8 GiB. Measured in the platform’s lab run: Flux 42 MiB idle and 138 to 189 MiB while the platform installs its parts; the PaaSbox Platform 96 MiB with minimal, 155 to 164 MiB with saas-http01, about 30 MiB more with saas, 826 to 868 MiB with observability.
Rules between add-ons
Section titled “Rules between add-ons”| Add-on | Requires | Conflicts with | Smallest server it is accepted on |
|---|---|---|---|
| PaaSbox Platform | Flux | cert-manager | 4 GB; 8 GB for the profiles saas-http01 and saas with observability |
| every other add-on | — | — | — |
- The portal switches a required add-on on together with the one that needs it, refuses to save two conflicting ones as on, and refuses an add-on or an option value on a server with too little memory.
pbx-agentapplies a required add-on first and the one that needs it only once the first is running; it removes a required add-on only after everything that needs it is gone. pbx-agent has the states it reports.
Hetzner cloud controller
Section titled “Hetzner cloud controller”Connects the cluster to your Hetzner project: the node’s addresses, the private network, and the server type and location as node labels. Always on, no options.
- It reads the Hetzner token and the network’s ID from the Secret
kube-system/hcloud, whichpbx-agentwrites. When you replace that token in the portal,pbx-agentrestarts it. - Load balancers are off. Traefik answers on the server’s own ports 80 and 443, and nothing in the cluster creates a Hetzner load balancer that Hetzner would bill you for.
Local storage
Section titled “Local storage”Volumes on the server’s own disk: OpenEBS LocalPV-LVM in the volume group vg0 of the node image. Always on, no options; it is part of the node image and is updated with it.
| Storage class | Default | What it is |
|---|---|---|
local-lvm-thin | yes, the only default | A thin logical volume; its size is a hard limit |
local-lvm-thick | no | Space reserved up front |
Local disk speed at no extra cost. A volume lives on the server that first ran its pod. It survives an update of the image in place and a restore in place, but not a move to another server. Backing up its data is yours.
Traefik ingress
Section titled “Traefik ingress”k3s’s own Traefik, the cluster’s ingress controller, with the IngressClass traefik. On a single node it answers on the server’s ports 80 and 443, which the firewall opens to everyone.
| Option | Default | What it does |
|---|---|---|
| Access logs | off | Logs every request to Traefik’s output (kubectl -n kube-system logs deploy/traefik). |
| Keep client IP addresses | off | Delivers requests with the client’s own address instead of the node’s, for access logs and IP allow-lists. |
The switch of this add-on adds or removes these settings. It does not turn Traefik off: that is a k3s setting, which the portal does not offer.
Hetzner volumes
Section titled “Hetzner volumes”Network volumes from your Hetzner project, through Hetzner’s CSI driver: storage class hcloud-volumes, at least 10 GB per volume, billed by Hetzner. A volume survives the server and can be attached to another one. No options.
hcloud-volumesis not the default class. Name it in a claim (storageClassName: hcloud-volumes) to use it; claims without a class keep going to the local storage.- Volumes carry the label
pbx-clusterwith the cluster’s ID. - Switching the add-on off leaves every volume and claim in place. Deleting the cluster deletes its volumes, after detaching any that is still attached.
cert-manager
Section titled “cert-manager”Certificates from Let’s Encrypt for your Ingresses. Two ClusterIssuers are installed, letsencrypt-staging and letsencrypt-production. An Ingress annotated kubernetes.io/tls-acme: "true" gets the default one; name another with cert-manager.io/cluster-issuer.
| Option | Default | What it does |
|---|---|---|
| ACME e-mail (required) | Let’s Encrypt registers the account under this address and sends expiry warnings to it. | |
| Default issuer | production | staging certificates are not trusted by browsers but are not rate-limited: use it to try a setup out. |
| Challenge | http01 | http01 proves the name through Traefik on port 80 and needs nothing else. dns01 proves it with a TXT record in your Hetzner DNS zone: needed for wildcard certificates and for names this cluster does not serve. |
| Hetzner DNS API token | Only for dns01: a Read & Write token of the Hetzner project that holds the zone, which may be another project than the cluster’s. Stored encrypted and never shown again. |
DNS-01 uses Hetzner’s own webhook for cert-manager. Switching cert-manager off keeps the certificates, their Secrets and cert-manager’s resource definitions. With the PaaSbox Platform on, this add-on must be off: the platform brings a cert-manager of its own.
external-dns
Section titled “external-dns”Creates DNS records in your Hetzner DNS zones for your Ingresses and LoadBalancer Services, with Hetzner’s own provider for external-dns. The records are owned by the cluster’s ID, so it never touches a record it did not create.
| Option | Default | What it does |
|---|---|---|
| Zones (required) | The zones it may write to, comma-separated, such as example.com,example.org. Other zones the token can see are left alone. | |
| Hetzner DNS API token (required) | A Read & Write token of the Hetzner project that holds the zones, which may be another project than the cluster’s. Stored encrypted and never shown again. | |
| Policy | upsert-only | upsert-only creates and updates records and never deletes one. sync also deletes the records this cluster created once their Ingress or Service is gone. |
Built in a lab: switched on, it was running 71 seconds after the save. In release 2026.10.2, which is not published yet.
Flux’s source controller and kustomize controller, version 1.9.5 of each (Flux 2.9.5), in the namespace flux-system: the cluster pulls Kubernetes manifests from Git repositories and applies them. The PaaSbox Platform needs it, and you can point it at a deploy repository of your own as well. No options.
- It counts as running once both controllers are available.
- Switching it off stops the controllers and keeps every GitRepository and Kustomization, and Flux’s resource definitions: nothing is deleted, nothing is pruned.
PaaSbox Platform
Section titled “PaaSbox Platform”Built in a lab, on 2026-10-10 and 11, with a copy of its controller image and source: the profiles minimal, saas-http01 and saas with a wildcard certificate over DNS-01, observability, an application with Postgres served over HTTPS with Let’s Encrypt staging certificates, its database backed up to S3, and switching on and off. In progress Release 2026.10.2 can be published only once the controller image and the source are public; certificates from Let’s Encrypt’s production service and a restore of a database from its backup have not run yet.
Turns the cluster into a platform for your SaaS applications: you, or your agent, write SaaSApplication objects (kubectl get saasapp) and get Postgres with backups to S3, Redis, TLS certificates, release hooks and schedules. Your applications stay yours. It requires Flux and replaces the cert-manager add-on.
What it installs:
- the saas-platform controller in the namespace
saas-platform-system, with its two resource definitions,SaaSApplicationandPlatform, which stay when the add-on is switched off; - the Git source its parts are installed from, at the version the release pins, and the ConfigMap
cluster-settings; - with wildcard certificates, the DNS token as a Secret in the namespace
cert-manager; - one
Platformnamed after the cluster, which installs cert-manager itself, CloudNativePG for Postgres (profilessaas-http01andsaas) and, with observability, the observability stack.
| Option | Default | What it does |
|---|---|---|
| Profile | saas-http01 | saas-http01: Postgres (CloudNativePG with backups and restores) and a Let’s Encrypt certificate per application by HTTP-01. saas: the same with one wildcard certificate for the default domain by DNS-01, which needs a DNS API token. minimal: certificates only, for applications on SQLite. |
| Observability | off | Metrics, logs, traces, alerting and Grafana for the cluster and its applications. It needs about 0.9 GiB: with Postgres, use a server with 8 GB or more. |
| Default domain | Applications without a hostname of their own are served as <name>.<domain>. Point *.<domain> at the server with a DNS A record. Required with wildcard certificates. | |
| Certificates | profile | How applications under the default domain get certificates. profile: as the profile says (saas: wildcard, the others: one per application). wildcard: one certificate for *.<domain> by DNS-01. perApplication: one each by HTTP-01 (Let’s Encrypt allows 50 new ones per domain and week). none: no certificates. |
| ACME e-mail (required) | Let’s Encrypt registers the account under this address and sends expiry warnings to it. Required since version 1.0.2: without it no certificate issuer is created. | |
| Let’s Encrypt | production | staging issues certificates browsers do not trust, without production’s rate limits: to try a setup out. |
| DNS API token | Only for wildcard certificates: a token of the DNS API that holds the default domain’s zone, a Hetzner project’s API token or a PaaSbox DNS team token. Required with wildcard certificates. Stored encrypted and never shown again. | |
| DNS API | Hetzner’s | Only for wildcard certificates: the Hetzner-compatible DNS API. Empty is Hetzner’s own; the PaaSbox DNS service is https://dns.paasbox.com/v1. |
Memory, by options, and the smallest server it is accepted on:
| Options | Memory, about | Smallest server |
|---|---|---|
minimal | 150 MiB | 4 GB |
saas-http01 (the default) | 300 MiB | 4 GB |
saas | 330 MiB | 4 GB |
| any profile with observability | 1050–1230 MiB | 4 GB for minimal, 8 GB for saas-http01 and saas |
The platform’s figures are upper bounds the portal plans with; the lab measured less in every profile. On a cpx22 (4 GB) with Flux and saas-http01 and no application, the lab’s node had 1.4 GiB of memory available: room for one small application. With observability there is none, which is why observability with Postgres needs 8 GB.
- At create, the form offers the profiles
minimalandsaas-http01, observability, and an ACME e-mail filled in with your address. It switches Flux on with the platform and refuses a server type with too little memory, naming the smallest that fits.saasneeds a default domain and a DNS token, which only the cluster’s Add-ons tab asks for. In progress Creating a cluster with the platform through the REST API or the MCP tools is refused: they pass no ACME e-mail yet. - It counts as running once its
PlatformreportsReady; while Flux installs its parts it stays pending, for minutes. In the lab a part that failed once was tried again by Flux only after an hour; until the platform’s next version, the add-on can stay pending that long. - Switching it off while any
SaaSApplicationexists changes nothing: the add-on reportsfailedwith the applications’ names. Delete them first. Then the platform installs nothing more and removes what it installed, unless something still uses it: a database, or an application that needs one of its parts, keeps everything in place, and the add-on reports why. ThePlatform’s annotationplatform.paasbox.com/allow-removal: <entry>removes an entry anyway, databases included. - Postgres backups are set per application, in the
SaaSApplication, with the application’s own bucket and keys. The platform needs no bucket of its own. - It needs Traefik: applications are served through it.
- Removing it takes the CRDs it took over. Switched on in place of the cert-manager add-on, the platform takes over cert-manager’s resource definitions. When you switch the platform off, Flux deletes them, and with them every Certificate in the cluster. CloudNativePG’s resource definitions go the same way once no database is left.
Monitoring and logs
Section titled “Monitoring and logs”Planned As add-ons of their own, after the launch.
- Monitoring: kube-state-metrics, node-exporter and a scraping agent. Either sent to a remote-write endpoint of yours, or kept in the cluster for a number of days.
- Logs: a collector on the node. Either sent to an endpoint of yours, or kept in the cluster.
Both stay in your cluster or go to your endpoint. Nothing of either flows to the portal. Until then, the PaaSbox Platform’s observability option In progress is the way to metrics and logs inside the cluster.
Not an add-on
Section titled “Not an add-on”- Your apps. PaaSbox Clusters deploys none; with the PaaSbox Platform, you or your agent write the
SaaSApplication. - Free-form Helm values. Each add-on has the options above and no others.
- Cloud Viewer. In progress Pairing Cloud Viewer with the portal installs nothing in the cluster: it reads status from the portal, not from the cluster.