Skip to content

Limits and quotas

Every number PaaSbox Clusters holds you to, in one place, grouped by subject. Each row says where the limit comes from, so you know whether to change your request, ask me, or wait.

LimitValueWhere
Clusters per team10 at once, more on request. Clusters being deleted, deleted or detached do not count. The create page says when the team has reached them; ask for a higher limit.The portal, before create
Servers per cluster1: single node is the only topology offeredThe create form
API keys25 active keys per team, created by a team admin In progressThe API keys page
An API key’s lifetime30 days, 90 days (the default), a year, or no expiry In progressThe API keys page
Creating a cluster while an invoice is unpaidRefused until the payment method is updated In progressThe portal, before create
LimitValueWhere
Cluster nameUp to 100 charactersThe create form
DNS labelLower-case letters, digits and hyphens, at most 32, no hyphen at either end; unique in the team; made from the name when left empty; cannot change laterThe create form
The Kubernetes API’s name<DNS label>.<team>.k3s. followed by PaaSbox’s zoneThe portal
A detached cluster’s API nameKept for 30 days, then removedThe portal
LimitValueWhere
Server linesCPX and CCX (amd64), CAX (arm64) In progress. No CX: the CX line boots with BIOS only, and the node image needs UEFI.The create form; an adopted CX server is refused
Server types offeredThose Hetzner sells in the chosen location, not deprecated, for an architecture the release has an image for. The list is read from your project and kept for 10 minutes.The create form
Memory a fresh cluster uses1.2 GiB of a cpx22’s 3.8 GiB, measured in a lab on 2026-10-10—
Memory per add-onThe estimates in the add-on catalogue: 50–150 MiB for each of the first six, 170 MiB for Flux, 150–1230 MiB for the PaaSbox PlatformThe portal adds them up
Smallest server for an add-onPaaSbox Platform: 4 GB; 8 GB for the profiles saas-http01 and saas with observability. No other add-on has one.The portal refuses smaller servers

The portal works through these steps; a step that does not finish in its time fails the create, and the cluster’s page shows which one.

StepTime limit
Check the token and the request5 minutes
Copy the node image into the project (the first cluster per project only; the upload itself is stopped after 40 minutes)60 minutes
Network, firewall, primary IP5 minutes each
DNS name10 minutes
Server10 minutes
Enrollment of pbx-agent10 minutes
Kubernetes API healthy10 minutes
Ready5 minutes
The enrollment token in the server’s user dataSingle use, valid for 30 minutes
LimitValueWhere
ScheduleA cron expression of five fields, in UTC; default 0 */6 * * *, every six hoursThe backup settings
Snapshots kept1 to 500; default 28, which is seven days at the default scheduleThe backup settings
Bucket nameUp to 63 charactersThe backup settings
FolderUp to 200 charactersThe backup settings
S3 endpointA host name, with a port if needed; no https://, no pathThe backup settings
Missed snapshotsA mail when no scheduled snapshot was taken for two cycles and 15 minutesThe portal
LimitValueWhere
Lifetime10 minutes, 30 minutes, 1, 2, 4, 8, 12 or 24 hours; through the API any number of seconds from 600 to 86,400 In progressThe Access tab
Rolesadmin and view. Team admins may ask for both; members for view, and for admin when a team admin allowed it. A view kubeconfig cannot list nodes.The portal
Collecting itThe sealed kubeconfig waits at the portal for 5 minutes and can be taken onceThe portal
LimitValueWhere
At the same timeOne operation per clusterThe portal and pbx-agent
Upgrades at the same time, across all clusters5The portal
A paused releaseTwo failures among the first five upgrades to a release pause itThe portal
How long a queued operation may wait for pbx-agent before it expiressnapshot 1 hour, restore 30 minutes, upgrade 1 hour, kubeconfig 5 minutes, revoke 1 hour, key rotation 1 day, bucket check 30 minutes, diagnostics 1 hourThe portal
An operation bound to the maintenance windowWaits for the window; one that missed it moves to the next window if that window starts within 14 days of the request, and expires otherwiseThe portal
Patch upgradesPlanned once an hour, into the next windowThe portal
The upgrade’s health gate20 minutes after the reboot, then the node boots the previous image In progresspbx-agent
pbx-agent’s own keysRotated when they are 90 days oldThe portal, daily
Lines of log in a failure reportThe last 200pbx-agent
LimitValueWhere
SyncAbout every 30 seconds (± 5); the portal answers at most one sync per agent per 10 secondsBoth
Managed objects re-appliedEvery 10 minutes, so a change by hand to one is overwrittenpbx-agent
A cluster counts as not reportingAfter 5 minutes without a sync; a push to a paired Cloud Viewer after 15 minutes In progress; a mail to the team’s admins after 24 hoursThe portal
A certificate that expiresA mail 30 days before the earliest expiryThe portal
Request bodiesAt most 256 KiBThe portal
Clock differenceAt most 60 seconds; a signature is refused again for 120 secondsThe portal
Retries after an errorFrom 5 seconds, doubling, up to 5 minutespbx-agent
A self-updateRolled back after 10 minutes without a successful sync; that version is not tried again for 6 hourspbx-agent
Finished operations remembered30 dayspbx-agent

In progress The API and the MCP tools are code, not run against a real cluster yet; REST API and MCP tools have the calls.

LimitValueWhere
Calls120 per minute per API key, or per person in a signed-in browserThe portal
Calls that change something20 of those per minuteThe portal
How it countsFixed windows of one minute, shared by REST and MCPThe portal
When it is reached429 with the problem code rate_limited and the seconds until the window turnsThe portal

In progress The billing through Paddle is being built.

LimitValueWhere
An unpaid invoiceMails to the team’s admins on day 1, 7 and 13; after 14 days the team’s clusters are detached. Nothing is deleted.The portal