Glossary
Glossary: terms around Clusterward and Kubernetes on Scaleway
Short definitions of the terms used in the cockpit, the guide and the product pages, each with a link to the detailed page. Alphabetical, in four blocks.
Terms
A to Z
A
- Add-on
- A component that Clusterward installs and updates on a cluster: ingress controller, cert-manager, metrics-server, Reflector. Versions come from a maintained catalog with Kubernetes compatibility information.More on Cluster updates →
- Adopting a record
- Putting an existing DNS record of a registered zone under Clusterward’s management. It is then changed like its own, for example during a cutover, but never deleted at the provider.More on DNS & certificates →
- API token
- Access for scripts and CI pipelines, sent as a Bearer header. Carries a role, an application scope and an expiry date, and appears in the audit log under its own name.More on Security & access →
- App catalog
- Templates for ready-made applications, maintained and live-tested by Clusterward. The first is WordPress: fill in four fields, and a database, disk, cron job and certificate are created.More on WordPress →
- Application
- A project in the cockpit: a repository with builds, environments and services. Applications can be organized into groups, for example per customer.More on Deployments →
- Audit log
- The record of every change in the workspace, with person, time, action and object. Secret values never appear in it, only their type.More on Security & access →
B
- Backup
- A copy that can be restored: automatic snapshots and individual backups of databases, snapshots of volumes, dumps from offboardings. Restores happen alongside what is running.More on Backups →
- Basic auth
- Password protection for a host at the ingress level. The credentials come from an environment variable of the service; if it is missing, the deployment aborts.More on Networking & ingress →
- Bucket
- An S3 bucket on Scaleway Object Storage, private or public, with a bucket policy and optionally a dedicated IAM key for the application.More on Object Storage →
- Build
- The description of how an image is produced: repository, branch, Dockerfile, image name and tag, built by Kaniko in the cluster or by GitHub Actions. A Git service references a build.More on Deployments →
C
- Certificate watcher
- The daily run that checks all certificates and reports any certificate with less than 14 days remaining or without Ready status, once per day.More on Notifications →
- Chart disk
- A disk that a Helm chart creates itself, for example for a built-in database. Clusterward shows it on the Helm service, backs it up via snapshot and restores it.More on Volumes →
- Chart secret
- A write-only secret of a Helm service. The values reference it with ${secret.NAME}; Clusterward inserts the value only at deploy time.More on Secrets →
- Circuit breaker
- A cap on connections and pending requests to a service with Envoy Gateway. Protects an overloaded application instead of continuing to flood it.More on Networking & ingress →
- Configuration check
- The comparison between what is defined in the cockpit and what is running in the cluster: matches, differs, missing or not managed.More on Cluster updates →
- Cutover
- Moving a service from one ingress controller to another: both load balancers serve the hosts with valid certificates, Clusterward moves its own DNS records and completes the switch one hour after every host points to the new address. A running cutover can be aborted.More on DNS & certificates →
D
- Data export
- The entire configuration of a workspace as a JSON file, under System → Security. Passwords, keys and secret values are never included.More on Security →
- Deployment
- The rollout of a service into its environment: build, registry check, server-side apply of the objects, health check. Runs in the background; the progress is shown in the cockpit.More on Deployments →
- DNS zone
- A domain hosted at Cloudflare that is registered in the cockpit with a verified token. Only in registered zones does Clusterward create records automatically; it compares them with Cloudflare every hour and only changes its own or adopted records.More on DNS & certificates →
- Dump
- The backup of a database before an offboarding, as a pg_dump or SQL file in the workspace’s backup bucket, with configurable retention. Without a successful dump, nothing is deleted.More on Managed databases →
E
- Environment
- A namespace on exactly one cluster, such as the staging or production environment of an application, with its own services, variables and hosts. The namespace name is set once and never changes.More on Deployments →
- Envoy Gateway
- The second ingress controller alongside ingress-nginx, based on the Kubernetes Gateway API. A service on the Envoy class is rendered as a Gateway with HTTPRoutes.More on DNS & certificates →
- External Secrets Operator
- A Kubernetes operator that syncs secrets from external sources such as the Scaleway Secret Manager into the cluster. In Clusterward, it is an add-on, selectable per cluster as the delivery method.More on Secrets →
H
- Health check
- The wait after a rollout until the pods are ready; two minutes by default, configurable per service. If it expires, the rollout counts as not ready in time, but it keeps running in the cluster.More on Deployments →
I
- IAM key
- An API key of a Scaleway project. Stored as a provisioning profile or S3 provider, it is verified before saving, encrypted and never shown again.More on Cluster provisioning →
- Image digest
- The unique fingerprint of a container image (sha256). Clusterward rolls out by digest so that a moving tag like latest doesn’t decide what runs.More on Deployments →
- Ingress class
- Determines which ingress controller serves a host. A service can pin a class or follow the cluster’s default class.More on DNS & certificates →
- Invitation
- How a new user gets access: a link by email with which they set their own password. They set up 2FA on their first sign-in.More on Security →
- IP allowlist
- The address ranges from which a workspace can be reached, checked before sign-in. Recognizes Cloudflare addresses and prevents you from locking out your own address.More on Your own workspace →
- Isolated environment
- An environment with network policies: only the cluster’s ingress controllers and its own pods get in, and the nodes’ metadata service stays out of reach. The policies follow the installed controllers; with the manage level the isolation can be removed again.More on Security & access →
K
- Kaniko
- The image builder that runs as a job in the cluster: clone the repository, build the Dockerfile, push to the registry – without a Docker daemon and without a build server.More on Deployments →
- Kapsule
- Scaleway’s managed Kubernetes. Clusterward provisions Kapsule clusters with private nodes and an API allowlist, or connects existing ones via kubeconfig.More on Cluster provisioning →
- Kubeconfig
- The access file for a Kubernetes cluster. When a cluster is connected, it is verified and stored encrypted; for provisioned clusters, Clusterward replaces the admin token with the operator identity.More on Cluster provisioning →
L
- Lockout
- Sign-in protection: an address with too many failed attempts is blocked for one hour, and for a day if it happens again. Addresses on the allowlist never are.More on Security →
M
- Managed database
- A Scaleway RDB instance for PostgreSQL or MySQL, which Clusterward creates with a private endpoint only. Databases with their own role per service are created on it.More on Managed databases →
N
- Network settings
- Timeouts, retries, rate limits, CORS, basic auth and further rules per service, described once and translated for nginx and Envoy. Every field shows the controller’s default.More on Networking & ingress →
O
- Offboarding
- Tearing down a customer: first a dump of every database and an archive of every non-empty bucket, then the pipeline in reverse. An error during the backup stops everything before anything is changed.More on Tenant pipelines →
- Operator identity
- A ServiceAccount in the cluster with a ClusterRole that may manage workloads but does not write cluster roles or CRDs. Rotatable from the cockpit; replaces the admin token.More on Security & access →
- Origin certificate
- A self-signed certificate that Clusterward issues on Envoy Gateway for hosts without a certificate of their own behind the Cloudflare proxy. Cloudflare encrypts all the way to the cluster with it instead of failing with error 525.More on Networking & ingress →
P
- Pipeline
- An ordered list of blocks that Clusterward runs for every new customer: database, domain, bucket, environment, workload. With preflight, retry and rollback.More on Tenant pipelines →
- Preflight
- The check before an onboarding starts: database names against the instance, hosts against all domains, buckets via HEAD. A conflict blocks the start; an inconclusive check triggers a warning.More on Tenant pipelines →
- Previous run
- The output of a container before its last restart. After a crash, that is usually where you’ll find the cause; the current log starts fresh.More on Logs & monitoring →
- Provisioning profile
- The verified IAM key of a Scaleway project in which Clusterward may create clusters, databases and registries. Every cluster remembers its profile.More on Cluster provisioning →
- Provisioning source
- A registered application that Clusterward polls for onboarding and offboarding requests. That way, your software orders its own customers; there is no inbound machine access.More on SaaS vendors →
- Proxy protocol
- The Scaleway Load Balancer option that passes the real client address to the ingress controller. Enabled by default for new clusters; a prerequisite for access lists and per-visitor login limits.More on Cluster provisioning →
R
- Rate limit
- A limit on requests per second or minute, optionally with burst, for address ranges or per header value such as an API key.More on Networking & ingress →
- Recovery code
- One of ten one-time codes that stand in for the authenticator if your phone is lost. They are shown once, after 2FA has been set up.More on Security →
- Restart
- Re-applies the current image with the current configuration, without rebuilding the image. The way to activate changed environment variables.More on Deployments →
- Restore
- The way back: a database from a backup into a new database, a volume from a snapshot, a service to an earlier version.More on Backups →
- Rotation
- A secret gets a new value as a new version. Clusterward detects versions in the Secret Manager and restarts the service on request.More on Secrets →
S
- Secret
- An environment variable that can only be overwritten once saved. No interface returns its value, and the audit log records only its name.More on Secrets →
- Secret Manager
- Scaleway’s managed service for versioned secrets. Clusterward creates secrets there, organized by app, environment and service.More on Secrets →
- Service
- The deployable unit in an environment: an application from Git, a container image or a Helm chart, with port, resources, scaling, domains, variables and volumes.More on Deployments →
- Setup password
- The protection of a new site from the app catalog until its installer has completed: the username “setup” and a password from the run page. “Open to everyone” removes it.More on WordPress →
- Snapshot
- A backup of the storage behind a volume, as a Scaleway Block Storage snapshot – on a schedule, or once before the data is deleted.More on Volumes & snapshots →
- SQL console
- The query window under Operations for PostgreSQL and MySQL: one statement per query, with its own read-only login, in a read-only transaction and with every query in the audit log.More on the SQL console →
- Sticky session
- Binds a visitor’s requests to the same instance, via a cookie or, with Envoy, via a header.More on Networking & ingress →
T
- Tenant
- A customer of your application, created by a pipeline run: its own namespace, database, buckets and host, with a lifecycle from onboarding to offboarding.More on Tenant pipelines →
U
- Uptime check
- An external HTTPS check of a domain, anywhere from every minute to every 15 minutes. After two failures, the site counts as unreachable and a message goes out to your channels.More on Logs & monitoring →
- Usage
- The history of a service’s CPU, memory and instances from 15 minutes to 30 days, as a share of the limit, with the request and restarts – for Helm services too. Clusterward records it itself every minute.More on Logs & monitoring →
V
- Variable bus
- The values that pipeline blocks publish, such as a database URL or hostname, and that later steps resolve only at execution time. Passwords never appear in the run.More on Tenant pipelines →
- Volume
- A persistent storage volume of a service on Scaleway Block Storage, with mount path, size and storage class. Survives undeploy and can only grow.More on Volumes & snapshots →
W
- Wildcard certificate
- A certificate for all subdomains of a base domain, issued via DNS-01 and mirrored into every namespace. Avoids the Let’s Encrypt limit when you have many customer subdomains.More on DNS & certificates →
- Workspace
- Your own, separated part of the Clusterward control plane: its own database, its own data key, its own backup bucket, its own address. Everything you create belongs to this workspace alone.More on Your own workspace →
Further reading
Missing a term?
The terms follow the language used in the cockpit. How they fit together in everyday work is shown in the Getting started guide; the differences from other tools are explained in the comparisons with Qovery and DIY.
See the terms in the cockpit
In the demo, we show workspace, pipeline, tenant and cutover on a real cluster instead of in a glossary.