# Overview

### [Sign Up](/platform/account/sign-up)

If you haven't already signed up for an account, this is the place to begin.


# Release Notes

Updates and improvements to our cloud platform.

{% hint style="info" %}
You can try the platform for free. [**Start now**](https://my.cloudbit.ch/#/register).
{% endhint %}

## v4.17.4

<figure><img src="/files/6dZJPDjGDjEIfH8xY2tq" alt=""><figcaption></figcaption></figure>

Release date: November 27, 2024

### New Features

With release 4.17.4, our focus was on the latest Kubernetes version v1.30. As a result, our customers can update their Kubernetes clusters to the latest version with just one click. The following Kubernetes topics were also addressed and improved with the same release: cluster certificate expiration, cluster action logic, restart issue upon kernel panic of a node, health check, and how k3s handles CCM and external Load Balancers.

#### Compute

* New images: Flatcar 3975

### Improvements and Fixes

* Kubernetes improvements
* General platform-related improvements and fixes

## v4.17.0

Release date: May 22, 2024

### New Features

#### Compute

* New images: Ubuntu 24.04 LTS, Debian 12.5, CentOS 8.4, Alma Linux 9.3, Rocky Linux 9.3, VyOS 1.3.6, FortiGate 7.4.3, Fedora 39, Fedora CoreOS 39, Flatcar 3815

### Improvements and Fixes

* Cloud Console - Core & Infrastructure Upgrades
* General platform-related improvements and fixes

## v4.16.0

<figure><img src="/files/xsoO6jBnjBdZRWAlob3Q" alt=""><figcaption></figcaption></figure>

Release date: July 03, 2023

### New Features

With release 4.16, our focus was on the [Kubernetes Cluster Autoscaler](https://doc.cloudbit.ch/products/kubernetes/resources/cluster-autoscaler). The cluster autoscaler automatically resizes the number of nodes based on the demands of your workload. When demand is low, the cluster autoscaler scales back down to the minimum size you designate. This can increase the availability of your workload when you need it while controlling costs. You don't need to add or remove nodes or over-provision your nodes manually.

#### Compute

* New images: Debian 12, Rocky Linux 8.8, FortiGate 7.4.0, Fedora 38, Fedora CoreOS 38, Flatcar 3510, FreeBSD 13.2, OpenBSD 7.3

### Improvements and Fixes

* General platform-related improvements and fixes

## v4.15.0

<figure><img src="/files/ijtcBldWHE65Y1Fr1kYV" alt=""><figcaption></figcaption></figure>

Release date: June 08, 2023

### New Features

With release 4.15, our focus was on the integration of [DevPod](https://devpod.sh/). DevPod is a convenient and easy-to-use open-source tool for creating reproducible developer environments. It comes with [native clients](https://devpod.sh/docs/getting-started/install) for macOS, Windows, and Linux. To get started with CloudBit Provider for DevPod, please follow [this link](https://github.com/cloudbit-ch/devpod-provider-cloudbit#getting-started).

#### General

* Voucher-Code support

### Improvements and Fixes

* General platform-related improvements and fixes

## v4.14.0

<figure><img src="/files/rwEpf7jEjcmuTsIklgTn" alt=""><figcaption></figcaption></figure>

Release date: April 05, 2023

### New Features

Like any comprehensive software, our Cloud Console needs regular refactoring under the hood, which has been implemented with this release. So this release contains mainly major core & infrastructure upgrades of the Cloud Console and some new bold new features and integrations.

#### Compute & Kubernetes

* [Pure Storage](https://www.purestorage.com/) Integration (All-flash, Tier 1 Storage-Backend)
* VPN as a Service (Support for VMs with Elastic/Public IPs)
* New images: OpenBSD 7.2, VyOS 1.3.2

### Improvements and Fixes

* Wizard improvements & other small UI bugfixes
* General platform-related improvements and fixes

## v4.13.0

<figure><img src="/files/WDOazhm0SP8HRWNfJbhY" alt=""><figcaption></figcaption></figure>

Release date: December 21, 2022

### New Features

#### VPN & Peering as a Service

The two often-requested services are finally ready for production. Establish a [Site-to-Site VPN](/products/compute/networking/vpn-and-peering#vpn-site-to-site) connection between a private network and your on-premise or other public cloud network with the VPN service. Connect two cross-regional or two regional private networks with just a few clicks with the [Peering](/products/compute/networking/vpn-and-peering#peering) service.

#### User Dashboard

The new user dashboard in the control panel stands out for its beautiful aesthetics and elegance. Besides many useful links like our Quickstart guides, Developer Center, and other widgets, the animated upper area with the overview of all our products stands out.

### Improvements and Fixes

* Small UI bugfixes
* General platform-related improvements and fixes

## v4.12.0

<figure><img src="/files/BRnRDRq7FJmzrpnXkf1C" alt=""><figcaption></figcaption></figure>

Release date: October 12, 2022

### New Features

#### CLI 2.0

With [version 2.0](https://github.com/cloudbit-ch/cli) of our CLI (command-line interface), all products are now fully integrated. In addition to Compute, Networking, and Load Balancers, as of now, Kubernetes and Object Storage can also be managed via the CLI.

#### Terraform Provider

Introducing the [CloudBit Terraform Provider](https://github.com/cloudbit-ch/terraform-provider-cloudbit). Terraform is an Infrastructure-as-Code tool that lets you provision, and version cloud resources safely and efficiently. It enables automated and repeatable provisioning of CloudBit resources.

### Improvements and Fixes

* Small UI bugfixes
* General platform-related improvements and fixes

## v4.11.0

Release date: August 18, 2022

### New Features

#### Object Storage

* Account Management
* Bucket Management
* Instance Management

#### Compute

* New images: Windows Server 2022, FreeBSD 13

### Improvements and Fixes

* Small UI bugfixes
* General platform-related improvements and fixes

## v4.10.1

![](/files/KY1FXYRI9eiR0EudDJ5V)

Release date: June 20, 2022

### New Features

#### General

* New, simplified Platform Status widget

#### Kubernetes

* Auto-renewal of k3s certificates with user notifications
* New Kubernetes version (v1.24.1)
* Online volume resize
* CSI volume metrics
* Expandable Volumes and Snapshot list with the force delete action
* Search and filter options for Persistent Volumes and Load Balancers
* Increased 'max file' handlers in FlatcarOS

#### Compute

* Online Volume resize
* New images: Ubuntu 22.04, Alma Linux, Rocky Linux

### Improvements and Fixes

* Portal speed optimizations
* Small UI bugfixes
* General platform-related improvements and fixes

## v4.9.0

![](/files/rHMgkcWRA3Db5Xa76u1M)

Release date: March 31, 2022

### New Features

#### Kubernetes

* New Kubernetes version (v1.23.3)
* One-click cluster upgrade (improved)
* Kubernetes management features (improved)

#### Compute

* New images: Flatcar 3033

### Improvements and Fixes

* Portal speed and security optimizations
* Updated Kubernetes naming convention (Control Plane & Worker)
* Core improvement of the Kubernetes service
* Core improvement of the Security Groups functionality
* Improved usability of the 3DSecure form
* General platform-related improvements and fixes

## v4.7.0

![](/files/-Mhnt4a3fDgX8gruHgGR)

Release date: August 23, 2021

### New Features

* Cashback (The more you recharge, the more bonus you receive)
* Billing Dashboard
* Usage Dashboard

### Improvements and Fixes

* The billing-engine has been modernized to support the growth of the platform
* General platform related improvements and fixes

## v4.6.0

![](/files/-Mhnsflhapvt3RH23Baj)

Release date: June 02, 2021

### New Features

#### Kubernetes

* One-click cluster upgrade support to newer versions
* One-click revert of cluster upgrade (including configuration changes)
* Native support for platform Load Balancers (via CCM)
* Custom cluster configuration (disable traefik, change log file amount and size)
* Updated CCM and CSI for Helm charts support

### Improvements and Fixes

* General platform related improvements
* Improved Kubernetes cluster creation and deployment of CCM and CSI
* Increased volume size for Kubernetes config drives
* Improved Load Balancer status management
* Upgraded CSI sidecar containers with a memory leak fix
* Fixed issue with crashing sync and status update for Kubernetes
* Fixed issue with mount propagation of root volume mount in Kubernetes
* Fixed issue with Drain-Node actions if k3s is unavailable


# Pricing

Affordable pricing — per hour billing.

{% content-ref url="/pages/-MZDIMnagwnFtdIQdAF2" %}
[Compute](/platform/pricing/compute)
{% endcontent-ref %}

{% content-ref url="/pages/-MZNVsaBG0RtCYsr9t08" %}
[Kubernetes](/platform/pricing/kubernetes)
{% endcontent-ref %}

{% content-ref url="/pages/-MZOMQvbINmZezkp61bQ" %}
[Object Storage](/platform/pricing/object-storage)
{% endcontent-ref %}

### Add-ons

{% content-ref url="/pages/-MZO0rzxBn-Mo-eqJkTN" %}
[Volumes & Snapshots](/platform/pricing/volumes-and-snapshots)
{% endcontent-ref %}

{% content-ref url="/pages/-MZO1hTeI2VPxqA0hQnP" %}
[Load Balancers](/platform/pricing/load-balancers)
{% endcontent-ref %}

{% content-ref url="/pages/-MhXsmxJrLPdeiKNUm9v" %}
[Elastic IPs](/platform/pricing/elastic-ips)
{% endcontent-ref %}

{% content-ref url="/pages/mV4AbVoCsxcsHzHtk9Oq" %}
[VPN & Peering](/platform/pricing/vpn-and-peering)
{% endcontent-ref %}

{% content-ref url="/pages/-MhY3c0zyrlGul\_rxopf" %}
[Licenses](/platform/pricing/licenses)
{% endcontent-ref %}

{% content-ref url="/pages/-MhYNhEkt6rEWqCfOPrT" %}
[Support](/platform/pricing/support)
{% endcontent-ref %}


# Compute

## How Compute pricing works

Compute pricing is based on the underlying required and optional Compute-related resources.

{% hint style="info" %}
Starting at CHF 0.0055/hr or CHF 4/mo
{% endhint %}

### Required resources

{% tabs %}
{% tab title="Balanced VM flavors" %}
Virtual machine flavors with a healthy balance of vCPU, RAM and Storage.

| Flavor        | vCPUs |    RAM | Storage | Hourly price° | Monthly price°¹ |
| ------------- | ----: | -----: | ------: | ------------: | --------------: |
| b1.1x1        |     1 |   1 GB |   10 GB |    CHF 0.0055 |           CHF 4 |
| b1.1x2        |     1 |   2 GB |   25 GB |    CHF 0.0098 |           CHF 7 |
| b1.2x2        |     2 |   2 GB |   50 GB |    CHF 0.0155 |          CHF 11 |
| b1.2x4        |     2 |   4 GB |  100 GB |    CHF 0.0270 |          CHF 20 |
| b1.2x8        |     2 |   8 GB |  150 GB |    CHF 0.0425 |          CHF 31 |
| b1.4x8        |     4 |   8 GB |  200 GB |    CHF 0.0540 |          CHF 39 |
| b1.4x16       |     4 |  16 GB |  300 GB |    CHF 0.0850 |          CHF 62 |
| b1.4x32       |     4 |  32 GB |  400 GB |    CHF 0.1320 |          CHF 96 |
| b1.8x32       |     8 |  32 GB |  500 GB |    CHF 0.1550 |         CHF 113 |
| b1.8x64       |     8 |  64 GB |  600 GB |    CHF 0.2340 |         CHF 171 |
| b1.8x96       |     8 |  96 GB |  800 GB |    CHF 0.3280 |         CHF 239 |
| b1.16x96      |    16 |  96 GB | 1000 GB |    CHF 0.3740 |         CHF 273 |
| b1.16x128     |    16 | 128 GB | 1500 GB |    CHF 0.5130 |         CHF 374 |
| b1.24x128     |    24 | 128 GB | 2000 GB |    CHF 0.6040 |         CHF 441 |
| b1.24x256     |    24 | 256 GB | 2500 GB |    CHF 0.9350 |         CHF 683 |
| b1.32x256     |    32 | 256 GB | 3000 GB |    CHF 1.0260 |         CHF 749 |
| b1.32x512     |    32 | 512 GB | 4000 GB |    CHF 1.6880 |        CHF 1232 |
| {% endtab %}  |       |        |         |               |                 |
| {% endtabs %} |       |        |         |               |                 |

### Optional resources

{% content-ref url="/pages/-MZO0rzxBn-Mo-eqJkTN" %}
[Volumes & Snapshots](/platform/pricing/volumes-and-snapshots)
{% endcontent-ref %}

{% content-ref url="/pages/-MZO1hTeI2VPxqA0hQnP" %}
[Load Balancers](/platform/pricing/load-balancers)
{% endcontent-ref %}

### Included

{% hint style="success" %}
**Elastic IP Address.** Each VM comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Basic Support** according to the best-effort principle.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Kubernetes

### How Kubernetes pricing works

Kubernetes cluster pricing is based on the underlying required and optional Kubernetes-related resources.

{% hint style="info" %}
Starting at CHF 0.042/hr or CHF 30/mo
{% endhint %}

### Required resources

{% tabs %}
{% tab title="Worker nodes" %}
A cluster requires at least three (3) of the following worker node flavors to operate.

| Flavor²      | vCPUs |   RAM | Hourly price° | Monthly price°¹ |
| ------------ | ----: | ----: | ------------: | --------------: |
| k1.1x2       |     1 |  2 GB |    CHF 0.0090 |           CHF 7 |
| k1.2x2       |     2 |  2 GB |    CHF 0.0110 |           CHF 8 |
| k1.2x4       |     2 |  4 GB |    CHF 0.0150 |          CHF 11 |
| k1.2x8       |     2 |  8 GB |    CHF 0.0230 |          CHF 17 |
| k1.4x8       |     4 |  8 GB |    CHF 0.0270 |          CHF 20 |
| k1.4x16      |     4 | 16 GB |    CHF 0.0430 |          CHF 31 |
| k1.4x32      |     4 | 32 GB |    CHF 0.0750 |          CHF 55 |
| k1.8x32      |     8 | 32 GB |    CHF 0.0830 |          CHF 61 |
| k1.8x64      |     8 | 64 GB |    CHF 0.1470 |         CHF 107 |
| k1.8x96      |     8 | 96 GB |    CHF 0.2110 |         CHF 154 |
| k1.16x96     |    16 | 96 GB |    CHF 0.2270 |         CHF 166 |
| {% endtab %} |       |       |               |                 |

{% tab title="Control plane" %}
The following fee for the control plane (master node) per cluster applies irrespective of the cluster size.

| Flavor²       | vCPUs |  RAM | Hourly price° | Monthly price°¹ |
| ------------- | ----: | ---: | ------------: | --------------: |
| k1.2x4        |     2 | 4 GB |    CHF 0.0150 |          CHF 11 |
| {% endtab %}  |       |      |               |                 |
| {% endtabs %} |       |      |               |                 |

### Optional resources

{% content-ref url="/pages/-MZO0rzxBn-Mo-eqJkTN" %}
[Volumes & Snapshots](/platform/pricing/volumes-and-snapshots)
{% endcontent-ref %}

{% content-ref url="/pages/-MZO1hTeI2VPxqA0hQnP" %}
[Load Balancers](/platform/pricing/load-balancers)
{% endcontent-ref %}

### Included

{% hint style="success" %}
**Elastic IP Address.** Each Kubernetes node comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Basic Support** according to the best-effort principle.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.\
² All Kubernetes flavors are deployed with a 60 GB root volume by default.


# Object Storage

### How Object Storage pricing works

The price for Object Storage consists of a standard package of 250 GB with a fixed price. Any additional storage beyond this is charged per GB and hour.

{% hint style="info" %}
Starting at CHF 0.0068/hr or CHF 5/mo
{% endhint %}

### Standard Package

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------: | --------------: |
| 250 GB  |    CHF 0.0068 |           CHF 5 |

### Additional Storage

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------: | --------------: |
| 1 GB    |   CHF 0.00002 |        CHF 0.02 |

### Included

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Basic Support** according to the best-effort principle.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Volumes & Snapshots

### How Volumes pricing works

The price for Volumes is calculated on the basis of the smallest unit of 1 GB. When creating volumes, the smallest unit is always 10 GB. After that, you can always expand volumes with the smallest unit of 1 GB. Charges accrue hourly for as long as the Volume exists.

### How Snapshots pricing works

Snapshots are always associated with Volumes. As Snapshots are 1:1 block storage level copies of a Volume, the per GB pricing and the method of calculation are exactly the same. Charges accrue hourly for as long as the Snapshot exists.

### Pricing per GB

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------: | --------------: |
| 1 GB    |   CHF 0.00015 |         CHF 0.1 |

### Pricing examples

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------: | --------------: |
| 10 GB   |    CHF 0.0015 |           CHF 1 |
| 50 GB   |    CHF 0.0075 |           CHF 5 |
| 100 GB  |    CHF 0.0150 |          CHF 10 |
| 200 GB  |    CHF 0.0300 |          CHF 20 |
| 250 GB  |    CHF 0.0375 |          CHF 25 |
| 500 GB  |    CHF 0.0750 |          CHF 50 |
| 1000 GB |    CHF 0.1500 |         CHF 100 |

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Load Balancers

### How Load Balancers pricing works

The Load Balancer service is charged per load balancing service unit. You can run more than one Load Balancer. Charges accrue hourly for as long as the Load Balancer exists.

### Pricing

| Plan     | Hourly price° | Monthly price°¹ |
| -------- | ------------: | --------------: |
| Standard |    CHF 0.0041 |           CHF 3 |

### Included

{% hint style="success" %}
**Elastic IP Address.** Each Load Balancer comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Elastic IPs

### How Elastic IPs pricing works

It is important to note that each Compute instance, Load Balancer unit, or Kubernetes node comes with a free, public Elastic IPv4 address. Any additional Elastic IP not attached to an instance will be charged accordingly. Charges accrue hourly for as long as the Elastic IP exists.

### Pricing per Elastic IP

| Item          | Hourly price° | Monthly price°¹ |
| ------------- | ------------: | --------------: |
| 1 public IPv4 |      CHF 0.01 |        CHF 7.30 |

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# VPN & Peering

### How VPN pricing works

The VPN service is charged per Site-to-Site VPN connection. You can run more than one Site-to-Site VPN connection. Charges accrue hourly for as long as the VPN connection exists.

### How Peering pricing works

The Peering service is charged per peering connection (interconnection of two private networks). You can run more than one peering connection. Charges accrue hourly for as long as the VPN connection exists.

### Pricing

| Connection type | Hourly price° | Monthly price°¹ |
| --------------- | ------------- | --------------- |
| VPN             | CHF 0.05      | CHF 40          |
| Peering         | CHF 0.11      | CHF 80          |

### Included

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Licenses

### How License pricing works

Licenses for paid operating systems or third-party software are usually tied to a product. The best example is a Windows-based Compute instance. Charges accrue hourly.

### Pricing

| Item                                        | Hourly price° | Monthly price°¹ |
| ------------------------------------------- | ------------: | --------------: |
| Microsoft Windows Server (Standard Edition) |    CHF 0.0137 |          CHF 10 |

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Support

### Plans

The CloudBit platform does not have a paid support plan option. Since it is a budget-cloud, only a free, basic support plan is offered on a best effort basis.

| Plan  | Channel          | Response time                                                                         |
| ----- | ---------------- | ------------------------------------------------------------------------------------- |
| Basic | Ticketing System | <p>Best effort (no specific guarantee).</p><p>We usually respond within 24 hours.</p> |

{% hint style="info" %}
**Looking for Premium Support?**\
Then we recommend the premium cloud services of our partner company [Flow Swiss](https://flow.swiss).
{% endhint %}


# Billing FAQ

## What's your billing model?

It's a consumption-based billing model. Essentially, it’s a lot like a prepaid mobile phone plan, where payment is made in advance (prepaid principle). You prepay for credits, which are then balanced against the consumption of services. This results in no minimum contract terms or any other liabilities.

## How am I billed?

Billing for **Compute, Kubernetes, Object Storage**, and other related services is based on a hourly basis. Our automatic system gathers usage data every hour after which we deduct the usage from your account balance. Monthly prices are displayed for easier comparisons and they are approximations assuming a 30 day month.

## Do you charge for stopped virtual machine instances?

Yes. Instances in a stopped state continue to reserve dedicated system resources (CPU, RAM, Storage, IP) and therefore incur charges until you destroy the instance. If you wish to no longer accumulate charges for a virtual machine, please use the delete button in the control panel.

## What payment methods do you accept?

Currently we accept MasterCard, Visa and American Express. If you are an Enterprise and Bank Transfer (PO approach) is your only method, please contact us. Bitcoin as payment method will be supported soon.

## What currency do you charge in?

As a Swiss company, CloudBit only charges in Swiss franc (CHF). 1 CHF is usually equal to 1 USD. [Here](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) you can check the current and historical exchange rates.

## What is the minimum amount for adding credit to my account?&#x20;

There’s a minimum amount of 10 CHF you can add. That's about 10 USD.

## What is Auto-recharge and how does it work?

If enabled, Auto-recharge automatically adds credit to your accounts balance when it falls below a certain amount. If disabled, the customer is responsible for manually recharging the credit.

## Can I test the service before paying for it?

Yes. We offer all customers 20 CHF worth of free credits that you can use to try the service before making any payments. Certain functionalities are however restricted before the first payment to prevent abusive behaviour.

## Can I get a refund if I don't use the service?

We do not issue refunds for unused services or credits.


# Account


# Sign Up

If you haven't already signed up for an account, this is the place to begin.

## Registration

1. [Sign up](https://my.cloudbit.ch/#/register) for a free trial account and receive a preloaded balance to test out the functionality.
2. Start working right away by provisioning your cloud environment.
3. If you like the CloudBit Cloud Platform, you have the option to upgrade your account to a full paid account.

{% hint style="info" %}
Please note that we block all disposable email domains, including free providers like google, yahoo, etc.
{% endhint %}

## Verification

As an additional safeguard of the registration process, we also perform an SMS verification. For this a working mobile number is required.&#x20;


# Closing account

## How can I close my organizations account?

**Option 1 (allow an account to expire)**

It is not necessary to request the closing of the account, as it is **automatically** closed depending on the balance status. To make sure that no additional costs are incurred, it is important to **delete all objects** first (such as VM instances, Elastic IP's, etc). The advantage of this option is that you can reuse any existing (positive) balance at a later date. After several months of general inactivity on the platform, the account is automatically closed.&#x20;

**Option 2 (immediate closing)**

If for some reason you wish to have your account deleted immediately, please contact our support. First of all you have to make sure that all your objects have already been deleted. The remaining balance will also be cleared and cannot be requested again in the future.


# Compute

## Introduction

Our suite of compute products lets you create the infrastructure you want, whether you want to build applications by managing your own infrastructure with instances, implement modern container-based methodology with Kubernetes.

### Plans and Pricing <a href="#plans-and-pricing" id="plans-and-pricing"></a>

We offer different kinds of products, you can view all available plans on the [pricing page](https://www.cloudbit.ch/pricing/).

{% hint style="info" %}
&#x20;You are still billed for Instances / Kubernetes clusters that are powered off because the compute resources for the Instance stay reserved on the hypervisor, even when they are not in use. To end billing, destroy the instance or Kubernetes cluster.
{% endhint %}

### Bandwidth

Each organisation includes free outbound data transfer: 20000 TB/month. Outbound data transfer is shared between all services each billing cycle. Additional transfer is billed at CHF 90 / 1TB, but most users don't exceed the amount included with their services.

### Region

cloudbit Platform is based in a data center in Switzerland.


# Instances

Instances are Linux or Windows-based virtual machines (VMs) that run on top of virtualized hardware in different regions.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.cloudbit.ch). Click **Create Instance**.<br>
2. Name your instance. The hostname is also set from the selected name during the initial creation.<br>
3. Choose the image distribution and version of your choice. Several Linux, FreeBSD, Windows, Container, and Firewall image distributions are available.<br>
4. Choose the configuration (flavor) for your instance that determines its vCPUs, RAM, Disk, and price.<br>
5. Confirm the network topology. If you have more than one **Private Network**, you can select the one you want. By default, each instance is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the instance to be reachable only internally, uncheck the **IPv4** checkbox. <br>
6. **Linux-based** distributions:\
   Select an existing SSH key or create a new one by clicking the **(+) Plus** button.\
   The use of "User data" aka cloud-init[^2], is optional and only intended for advanced users.\
   \
   **Windows-based** distributions:\
   Specify a password for the Administrator user account.\
   \
   Click on **Finish**. Deploying an instance takes a few minutes.<br>
7. Once the instance is created, follow the [detailed guide](/products/compute/instances/how-to/connect-to-instances) on how to connect to it.

## Images

We offer a wide variety of different distribution images you can use for your Instances. Besides regular server operating systems, we also offer container and firewall distributions, as listed below.

| Distribution     | Available Versions                                              |
| ---------------- | --------------------------------------------------------------- |
| Ubuntu           | 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS                      |
| Debian           | 10, 11                                                          |
| RHEL Derivatives | Alma Linux 8, 8.5, 9                                            |
|                  | Cent OS 7, 8.1, 8.3                                             |
|                  | Rocky Linux 8.5                                                 |
|                  | VzLinux 8                                                       |
| Windows Server   | 2016 Standard, 2019 Standard, 2019 Core Standard, 2022 Standard |
| Fedora           | 31, 32, 34, 35                                                  |
| FreeBSD          | 12.2, 13.1                                                      |

| Container Distribution | Available Versions     |
| ---------------------- | ---------------------- |
| Fedora Core OS         | 31, 34, 35             |
| RancherOS              | 1.5.5                  |
| Flatcar                | 2512, 2765, 3033, 3227 |

| Firewall Distribution . | Available Versions                       |
| ----------------------- | ---------------------------------------- |
| VyOS (Crux)             | 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.3.1 |
| FortiGate               | 6.2.3, 6.4.0, 7.0.0                      |

## Regional Availability

Instances are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* At the moment, IPv6 is not supported.

{% content-ref url="/pages/-MG2iHywkzo8sIf\_jHfz" %}
[Connect to instances](/products/compute/instances/how-to/connect-to-instances)
{% endcontent-ref %}

{% content-ref url="/pages/-MG2iRRnLGmCiw1y\_b3A" %}
[Destroy instances](/products/compute/instances/how-to/destroy-instances)
{% endcontent-ref %}

[^1]: Publicly-accessible static IP address

[^2]: Cloud-init is an industry-standard instance initialization tool that allows you to inject customized configurations at creation time


# How-to


# Connect to instances

{% tabs %}
{% tab title="Connect to Linux (Container) instances" %}

## Connect to Linux (Container) Instances

During the launch of an instance, a default user will be created, and this user will have **no** password set. Instead, your SSH key is copied to the VM and you will be able to login to the machine via SSH using the default username. The default username varies between Operating Systems. Here are the usernames for our official distributions:

| Distribution                 | Username |
| ---------------------------- | -------- |
| Ubuntu Linux                 | ubuntu   |
| Debian Linux                 | debian   |
| CentOS Linux                 | centos   |
| Fedora Linux / Fedora CoreOS | fedora   |
| Rancher Linux                | rancher  |
| VyOS                         | vyos     |
| Fortigate                    | admin    |

To connect by using a terminal on Linux, macOS, or Windows Subsystem for Linux:

1. Open your terminal, and enter the command\
   \
   &#x20;`ssh username@185.xx.xx.xx`

   \
   Substitute in your instance's [Elastic IP](#user-content-fn-1)[^1] address after the `@`. The username is mentioned above in the list for your desired distribution.<br>
2. Press `ENTER` and answer `yes` to the prompt that confirms the connection.<br>
3. When you've logged in, your command prompt changes, and you'll see a welcome screen.

{% hint style="info" %}
Windows users can alternatively connect with [PuTTY](https://www.chiark.greenend.org.uk/~sgtatham/putty/).
{% endhint %}
{% endtab %}

{% tab title="Connect to Windows Instances" %}

## Connect to Windows Instances

To access a Windows Instance, use the RDP protocol and an RDP client for your operating system:

* Windows: [How to use Remote Desktop](https://support.microsoft.com/en-us/help/4028379/windows-10-how-to-use-remote-desktop)
* macOS: [Microsoft Remote Desktop](https://apps.apple.com/us/app/microsoft-remote-desktop-10/id1295203466?mt=12)
* Linux: [FreeRDP](http://www.freerdp.com)

Specify the [Elastic IP](#user-content-fn-1)[^1] address in the client and provide the *default username* **Administrator** and the password specified during the deployment (wizard).
{% endtab %}
{% endtabs %}

[^1]: Publicly-accessible static IP address


# Destroy instances

Deleting an instance permanently and irreversibly destroys the instance and its contents. To destroy a Instance from the [control panel](https://my.flow.swiss/#/compute/instances), click on the Instance's name to access its main page and select **Delete** from the action menu (top in the right corner).


# Volumes

Volumes are virtual disks based on SSD-only, high availability storage devices to serve as your instances system and storage disks. Beside your instances primary Volume you can add multiple additional Volumes to provide additional data storage for Instances.&#x20;

Volumes function as generic block devices, so you can treat attached volumes like locally connected storage drives. This lets you partition, format, and manage volumes with familiar tools and techniques.

You can move the Volumes between instances and resize them at any time.

## Snapshots

You can take snapshots of Volumes. Volume snapshots save all the contents from the volume, there are 1:1 block storage level copies of a Volume at the moment of creation.

Snapshots can be used to revert an Instance back to an earlier state or to create a new instance based on the snapshot.

## Plans and Pricing

For pricing details please consult our [pricing page](https://www.cloudbit.ch/pricing/).

## Regional Availability

Volumes are available in all regions. They are region-specific resources and can only be assigned to Instances within the same region.

## Limits

* To increase an attached volume you have to power-off / shutdown your instance.
* Volumes cannot be assigned to more than one instance at a time.


# Keypairs

Using Keypairs (SSH keys) allows you to secure SSH access to instances (VMs). You can generate a key pair on a client from which you will connect to instances via SSH. The private key will be stored on the client, and the public key will need to be uploaded and specified during instance creation. It will be injected into the instance by cloud-init and used for OpenSSH authentication.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.cloudbit.ch). Click **Create Key Pair.**<br>
2. Name your Keypair.<br>
3. Under **Keypair**, paste your public key in the empty field or upload a file by clicking on "or select file". The Keypair should have the following format:\
   \
   `ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQClkRUh/9D7QmZSPvWqJc1NBqs07t77s8lAwrVzsZMgP/vFZJtXQCRJ2NTxQOoJk7q1QEPqJtidIIz/oau2QkvOWvWB/gorbI2iCDDkK1j9XBsnp+DVmu126lAcGUb/V0U/5J3PCHYE2K4gKNoiQShIQbp/7JTsNCxwLaz2oZ5/brG5X+it6triEhRG/lqh6QiVvGWiQPaJTp6mBSQQF6AAaEMXLXeQkBiVW+UrV6bSC+tV5A5aBMwNP8L90TXl/sBoqlpuDMnIXOPwPt8UFSos/AR7hMl1JueRohuG26PNwwZ2NDCH+Uk3ER4hXZmIWEup99QJA3pmFGhJADIFy/Qh`<br>
4. Click on **Next**. In the summary window, click on **Finish** to complete the process. The new Keypair can now be used when creating new instances.

## Adding Keypairs to an existing instance

For security reasons, you can’t add or modify the Keypairs (SSH keys) on your instance using the control panel after you create it, but you have several options to add and modify them via the command line. If you currently have SSH access to the instance, you can upload keys:

* **From your local computer, using `ssh-copy-id`**, which is included in many Linux distribution's OpenSSH packages.<br>
* **From your local computer by piping the contents of the public key** into the `~/.ssh/authorized_keys` file. This is a good choice if you don’t have `ssh-copy-id`.<br>
* **By SSHing to your instance and adding the public key manually**, which is necessary if you do not have password-based SSH access.

## Regional Availability

Keypairs are available in all regions.

## Limitations

Keypairs are only supported for Linux and Unix-based instances.


# Networking


# Private Networks

A Private Network (also known as VPC) is a virtual version of a physical network (Layer 2) implemented inside of our production network using VXLAN encapsulation. Private Networks provide the following:

* Internal connectivity for your Compute Instances, including Kubernetes Clusters.
* Complete isolation of network traffic from other Private Networks.
* Integrated DHCP, IP, and DNS management enable easy network configuration.<br>

## Default Networks

Each region comes with a Private Network by default. The default network is an auto-created Private Network with the following addressing scheme:

* Region BIT1: 172.31.0.0/20

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.cloudbit.ch). Click **Create Private Network.**<br>
2. Name your Private Network and compose a description.<br>
3. Under **CIDR**, specify the IP address allocation in CIDR notation for your Private Network (for example, 10.11.12.0/24).<br>
4. Under **Gateway IP**, specify the IP address that serves as an entrance to other networks, such as the internet (for example, 10.11.12.1).<br>
5. Under **Allocation Pool Start**, specify the IP address that will serve as the start of the DHCP allocation pool. (for example, 10.11.12.100).<br>
6. Under **Allocation Pool End**, specify the IP address that will serve as the end of the DHCP allocation pool. (for example, 10.11.12.200).<br>
7. Under **Domain Name Servers**, specify the IP addresses that will serve as the DNS for your Private Network. (for example, 1.1.1.1, 8.8.8.8).<br>
8. Under **Region**, choose a data center Region where your Private Network should be created and click on **Save**. Creating a new Private Network takes a few minutes.

## Pricing

Private Networks are free of charge.

## Regional Availability

Private Networks are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limitations

Only one subnet per Private Network is supported.


# Routers

Routers provide L3 services such as routing and Source Network Address Translation (SNAT) between Virtual Private Cloud (VPC) network and public (WAN) networks, or different Virtual Private Cloud (VPC) networks:

* A Router between Virtual Private Cloud (VPC) network and public network provides access to public networks, such as the Internet, for VMs connected to this virtual network.<br>
* A virtual router between different Virtual Private Cloud (VPC) networks provides communication for VMs connected to these Virtual Private Cloud (VPC) networks.

With virtual routers, you can do the following:

* Create virtual routers
* Change external or internal router interfaces
* Create, edit, and delete static routes
* Change a router name
* Delete a router

## Plans and Pricing

Routers are free.

## Regional Availability

Routers are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limitations

* At the moment only IPv4 is supported.


# Security Groups

Security Groups place a barrier between your servers and other machines on the network to protect them from external attacks. Security Groups are network-based firewalls and stop traffic at the network layer before it reaches the server.

A security group consists set of network access rules that control incoming and outgoing traffic to instances assigned to this group. With security group rules, you can specify the type and direction of traffic that is allowed access to a virtual interface port. Traffic that does not satisfy any rule is dropped.

For each region, a default security group is automatically created in the control panel. This group allows all traffic on all ports for all protocols. When you attach a network interface to an instance, the interface is associated with the default security group, unless you explicitly select a custom security group.

When you add rules to security groups or remove them, the changes are enforced at runtime.

## Quickstart

{% hint style="info" %}
As standard, each organization's account comes with a default Security Group per data center region. The default group allows all traffic on all ports for all protocols.
{% endhint %}

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.cloudbit.ch). Click **Create Security Group**.<br>
2. Name your Security Group, compose a description and choose a data center Regio&#x6E;**.** Click on **Save** to create a new Security Grou&#x70;**.**<br>
3. To edit and manage the newly created Security Group, click on it in the list.<br>
4. Create a new rule by clicking on the **(+) Plus** button under the **Rules** tab.<br>
5. Under **Direction**, specify whether the rule should apply to inbound "Ingress" or outbound "Egress" traffic.<br>
6. Under **Protocol**, choose the protocol. The values Any, TCP, UDP, and ICMP are available for selection. Depending on the choice, you have the possibility to set further parameters. For TCP and UDP, you can specify the "Start port" and "End port", and for ICMP, the "Type" and "Code.<br>
7. Under **Remote**, specify the remote resource to which this rule should be applied. The values Any, Subnet, and Group are available for selection. Depending on the choice, you have the possibility to set further parameters. For the Subnet, you can specify the CIDR notation (for example, 10.11.12.0/24 or /32 for a single address). For Group, you can specify an existing Security Group.<br>
8. Click **Save** to add the rule to the Security Group. To assign the newly created Security Group, including the rules you created, to an instance, navigate to Compute > Instances > Instance > Security Groups.

## Disable Network Security

You have the ability to disable the security group feature per network interface of an instance. This feature is mostly required when you use a firewall distribution.

## Plans and Pricing

Security Groups are free.

## Regional Availability

Security Groups are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limitations

* You can manage only IPv4 security group rules.


# Elastic IPs

Elastic IPs (Floating IPs) are publicly-accessible static IP addresses that you can assign to Instances and instantly remap between other Instances in the same region.

You can use elastic IPs to create server infrastructures without single points of failure, but a elastic IP alone does not automatically provide high availability. For a setup to be highly available, you need to implement a failover mechanism to automate the process of detecting failures of the active server and reassigning the elastic IP to a passive server.

## Plans and Pricing

One Elastic IP is free when assigned to a Instance. For pricing details please consult our [pricing page](/platform/pricing/elastic-ips).

## Regional Availability

Elastic IPs are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* Elastic IPs cannot be assigned to more than one instances at a time.<br>
* At the moment, we do not support IPv6 elastic IPs. All elastic IPs are IPv4.<br>
* Reverse DNS Records (rDNS) have to be requested via support ticket.


# Load Balancers

CloudBit Load Balancers are a fully-managed, highly available network load balancing service. Load balancers distribute traffic to groups of Instances or Kubernetes Clusters, which decouples the overall health of a backend service from the health of a single server to ensure that your services stay online.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.cloudbit.ch). Click **Create Load Balancer.**<br>
2. Name your Load Balance&#x72;**.**<br>
3. Confirm the network topology. If you have more than one **Private Network**, you can select the one you want. By default, each Load Balancer is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the Load Balancer to be reachable only internally, uncheck the **IPv4** checkbox. Click on **Finish**. Deploying a Load Balancer takes a few minutes.<br>
4. To edit and manage the newly created Load Balancer, click on it in the list.<br>
5. Create a new pool by clicking on the **(+) Plus** button under the **Balancing Pools** tab.<br>
6. Under **Forwarding Rule**, choose the protocol. Enable **Proxy Protocol** only if you want to preserve the client IP for SSL passthrough.<br>
7. Under **Load Balancer Port**, specify the listener port.<br>
8. Under **Balancing Algorithm**, choose the [algorithm](#balancing-algorithms). Enable **Sticky Session** only if you want to enable the Session Persistence feature. Click on **Next** to proceed.<br>
9. Under **Members Port**, specify the backend port. It can be the same port number as in step 7 (listener) or its own port number.<br>
10. Under **Members**, add the Load Balancer members. Click on **Next** to proceed.<br>
11. Under **Protocol**, choose the protocol that the Health Monitor should use to monitor the availability of the pool members. Click on **Finish** to create a new Balancing Pool.<br>

## Protocol Support

A single Load Balancer can be configured to handle multiple protocols and ports. You can control traffic routing with configurable rules that specify the ports and protocols that the load balancer should listen on, as well as the way that it should select and forward requests to the backend servers.

Because CloudBit Load Balancers are network load balancers, not application load balancers, they do not support directing traffic to specific backends based on URLs, cookies, HTTP headers, etc.

**HTTP**

Standard HTTP balancing directs requests based on standard HTTP mechanisms. The load balancer sets the `X-Forwarded-For`, `X-Forwarded-Proto`, and `X-Forwarded-Port` headers to give the backend servers information about the original request.

If user sessions depend on the client always connecting to the same backend, a cookie can be sent to the client to enable sticky sessions.

**HTTPS AND HTTP**

You can balance secure traffic using either HTTPS or HTTP. Both protocols can be configured with:

* **SSL termination**, which handles the SSL decryption at the load balancer after you add your SSL certificate and private key. <br>
* **SSL passthrough**, which forwards encrypted traffic to your backend Droplets. This is a good for end-to-end encryption and distributing the SSL decryption overhead, but you’ll need to manage the SSL certificates yourself.

**TCP / UDP**

TCP / UDP balancing is available for applications that do not speak HTTP. For example, deploying a load balancer in front of a database cluster like Galera would allow you to spread requests across all available machines.

#### PROXY Protocol <a href="#proxy-protocol" id="proxy-protocol"></a>

[PROXY protocol](https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt) is a way to send client connection information (like origin IP addresses and port numbers) to the final backend server rather than discarding it at the load balancer. This information can be helpful for use cases like analyzing traffic logs or changing application functionality based on geographical IP.

## Balancing Algorithms

* **Least Connections**. Requests will be forwarded to the VM with the least number of active connections.<br>
* **Round Robin**. All VMs will receive requests in the round-robin manner.<br>
* **Source IP**. Requests from a unique source IP address will be directed to the same VM.

Enable/disable the **Sticky session** option to enable/disable session persistence. The load balancer will generate a cookie that will be inserted into each response. The cookie will be used to send future requests to the same VM.

## Plans and Pricing

For pricing details, please consult the [pricing page](/platform/pricing/load-balancers).

## Regional Availability

Load Balancers are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* At the moment, IPv6 is not supported.

[^1]: Publicly-accessible static IP address


# Balancing Pools

## Manage the Balancing Pools

A load balancer can have one or more balancing pools. The balancing and health monitor properties are defined in the balancing pools. To see a list of balancing pools of a load balancer, click on its name.

To edit the balancing settings (such as the balancing algorithm and session persistence) or health monitor parameters, click the properties icon in the right corner.

You can monitor its performance and health on the Status, see its parameters on the Properties, and manage its members on the Members tab.

## Members

Each balancing pool contains one or more members (instances). The traffic is redirected to these using the configured balancing algorithm. To view the members to a balancing pool, click its name. You have the possibility to add, disable and remove members at runtime.&#x20;

## Health Monitor

A health monitor is a scheduled HTTP, TCP, UDP Connect or ICMP request that you can configure to run on a repeating basis to ensure that a service is healthy. You can manually set the health monitor parameters in the Balancers Detail view.


# Certificates

Some services, like load balancer SSL termination require SSL certificates. To add a new certificate you need to fill in four fields:

* **Name**\
  This is a name you choose to identify the certificate in the interface. It can only contain letters, numbers, periods, and dashes.<br>
* **Certificate**\
  This is the actual SSL public key or certificate file.<br>
* **Private key**\
  This is the secret key associated with the certificate.

{% hint style="info" %}
The **Certificate chain** must already be included in the certificate file. This is the full trust chain between the trusted certificate authority’s certificate and your domain’s certificate.
{% endhint %}

## Plans and Pricing

The storage of Certificates is free.

## Regional Availability

Certificates are available in all regions. They are region-specific resources and can only be assigned to items within the same region.


# VPN & Peering

VPN and Peering are two different managed connectivity services that use the same technology in the background but can be used independently of each other. Both services use the Internet Key Exchange (IKE) and IP Security (IPsec) protocols to establish secure connections and are based on strongSwan's IPsec solution.&#x20;

## VPN (Site-to-Site)

Our managed VPN service allows you to easily establish a Site-to-Site VPN connection between one of your private networks at CloudBit and your on-premise or other public cloud networks. The traffic that flows between VPN endpoints is encrypted.

## Peering

Our managed Peering service allows you to easily connect two cross-regional or two regional private networks with just a few clicks. Peering allows resources in one private network to communicate with resources in the other private network as if they were on the same network. The traffic that flows between Peering endpoints is encrypted.

## Quickstart

1. Start by navigating to "Compute" > "Networking" > "VPN & Peering" in the [Control Panel](https://my.cloudbit.ch).<br>
2. Click the **(+) Plus** button in the **VPN & Peering** tab.<br>
3. Choose the Connection Type. If you have selected **Peering**, follow step 4. If you have selected **VPN**, follow steps 5 to 9.<br>
4. Under **Local Private Network**, choose the local private network, and under **Remote Private Network**, the remote private network you would like to peer. Please note that only networks can be selected where the CIDR does not overlap and that both private networks must be connected to a [Router](/products/compute/networking/routers) of a public type.\
   \
   Click on **Finish**. Establishing a new peering connection takes a few minutes.<br>
5. Under **Local Private Network**, choose the local private network. Under **Remote Public IP,** specify the public IP of the remote VPN endpoint. Under **Remote CIDRs**, specify the CIDRs (Subnets) of the remote site.<br>
6. Under **IKE Policy**, specify parameters for the Internet Key Exchange (IKE) policy that will be used to establish a VPN connection. Or keep the default best practices.<br>
7. Under **IPsec Policy**, specify parameters for the IP Security (IPsec) policy that will be used to encrypt the VPN traffic. Or keep the default best practices.<br>
8. Under **VPN Configuration**, specify the matching configuration parameters necessary to connect to the remote VPN endpoint. Please note that the configuration parameters on both VPN endpoints must match for the connection to be established successfully.<br>
9. Name your VPN connection and click on **Finish**. Establishing a new VPN connection takes a few minutes.

## Limitations

Instances (VMs) with an [Elastic IP](#user-content-fn-1)[^1] attached cannot currently be reached via managed VPN or Peering connections. Only instances with a private IP can be addressed via this type of connection. This limitation will be lifted in Q1-2023.

[^1]: Publicly-accessible static IP address


# Kubernetes

CloudBit Kubernetes is a managed Kubernetes service lets you deploy scalable and secure Kubernetes clusters without the complexities of administrating the control plane. We manage the Kubernetes control plane and the underlying containerized infrastructure. \
\
Clusters are compatible with standard Kubernetes toolchains and integrate natively with our Load Balancers and block storage volumes.

There are no restrictions on the API objects you can create as long as the underlying Kubernetes version supports them. We offer the latest version of Kubernetes as well as earlier patch levels of the latest minor version for special use cases. You can also install popular tools like Helm, metrics-server, and Istio.

## Nodes

Worker and Master nodes are built on instaces, but unlike standalone instances, worker nodes are managed with the Kubernetes command-line client `kubectl` and are not accessible with SSH. On both the control plane and the worker nodes, CloudBit maintains the system updates, security patches, operating system configuration and installed packages.

Worker nodes are automatically deleted and respawned when needed, and you can manually rebuild worker nodes.

## Persistent Data

You can persist data in Kubernetes clusters to block storage volumes using the CloudBit CSI plugin, the CSI Plugin is already preinstalled and is used for the default storage class.

You can also persist data to CloudBit object storage by using the S3 API to interact with the storage from your application.

## Load Balancing

The CloudBit Kubernetes Cloud Controller supports provisioning external CloudBit Load Balancers.

## VPC Support

Clusters are added to a VPC network for the datacenter region by default. This keeps traffic between clusters and other applicable resources from being routed outside the datacenter over the public internet.

## Plans and Pricing

The cost of a Kubernetes cluster is based on the cluster’s resources:

* Nodes (Workers and Master / Control plane ) are built on Instances.<br>
* Integration Load Balancers is charged at the same rate as common Load Balancers.<br>
* Integration with block storage volumes is charged at the same rate as volumes.

All charges for Kubernetes clusters appear in the Kubernetes detail view section. For pricing details please consult our [pricing page](https://www.cloudbit.ch/pricing/).

## Regional Availability

Kubernetes Clusters are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* At the moment IPv6 is not supported.<br>
* The control plane is not highly available and may be temporarily unavailable during upgrades or maintenance. This does not affect running clusters and does not make the cluster workers or workloads unavailable if external load balancers are used.


# Clusters

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.cloudbit.ch). Click **Create Kubernetes Cluster**.<br>
2. Choose the default configuration for your worker nodes, which determines their RAM, vCPUs, and price. If you need more than three worker nodes, click the **(+) Plus** sign on the card.<br>
3. Confirm the network topology. If you have more than one **Private Network**, you can select the one you want. By default, each cluster is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the cluster to be reachable only internally, uncheck the **IPv4** checkbox.<br>
4. Name your cluster and click on **Finish**. Deploying the cluster takes a few minutes.<br>
5. Download the cluster configuration file by clicking the **(**•••**) More** button and then **Download Kube-Config**.<br>
6. Once the cluster is created, use [kubectl](https://kubernetes.io/docs/tasks/tools/), the official Kubernetes command-line tool, to connect and interact with the cluster. If you prefer an intuitive graphical interface, then the free third-party tool [Lens](https://k8slens.dev/desktop.html) is right for you.

[^1]: Publicly-accessible static IP address


# Resources


# Volumes Features (CSI)

The availability of a specific CSI feature depends on the deployed version. The table below outlines the minimum versions required to use a particular feature:

| Feature           | Description                                          | Available From |
| ----------------- | ---------------------------------------------------- | -------------- |
| Volume Expansion  | Resize a volume to increase the available disk space | All Versions   |
| Raw Block Volumes | Use a volume as a block device                       | All Versions   |
| Volume Snapshots  | Create and restore from snapshots                    | 1.1.4          |


# Cluster Autoscaler

## Introduction

Cluster Autoscaler is a component that automatically adjusts the size of a Kubernetes Cluster so that all pods have a place to run and there are no unneeded nodes.

The cluster autoscaler for CloudBit scales worker nodes within any specified CloudBit Kubernetes cluster.

## Installation

As there is no concept of a node group within CloudBit Cloud's Kubernetes offering, the configuration required is quite simple. You need to set:

* Your CloudBit Application Token
* The Kubernetes Cluster's ID (not the name)
* The minimum and maximum number of **worker** nodes you want (the master is excluded)

1. Please adjust the following bold values in the yaml file below:

* Minimum & Maximum of worker nodes (for example minimum 3 and maximal nine): `nodes=3:9:workers`<br>
* Generate an application token in <https://my.cloudbit.ch/#/organization/applications> and convert it to a base64 string and replace the \*\*api-token\*\* value.<br>
* Retrieve the cluster ID from your Kubernetes Cluster, convert it to a base64 string and replace the \*\*cluster-id\*\* value.

```
cluster-autoscaler.yaml
 
---
apiVersion: v1
kind: ServiceAccount
metadata:
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
  name: cluster-autoscaler
  namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: cluster-autoscaler
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
rules:
  - apiGroups: [""]
    resources:
      [
        "pods",
        "services",
        "replicationcontrollers",
        "persistentvolumeclaims",
        "persistentvolumes",
        "nodes",
        "endpoints",
        "namespaces",
        "configmaps",
      ]
    verbs: ["watch", "list", "get", "update", "create", "delete"]
  - apiGroups: [""]
    resources: ["events"]
    verbs: ["watch", "list", "get", "create", "update", "delete", "patch"]
  - apiGroups: ["extensions"]
    resources: ["replicasets", "daemonsets"]
    verbs: ["watch", "list", "get"]
  - apiGroups: ["policy"]
    resources: ["poddisruptionbudgets"]
    verbs: ["watch", "list"]
  - apiGroups: ["apps"]
    resources: ["statefulsets", "replicasets", "daemonsets"]
    verbs: ["watch", "list", "get"]
  - apiGroups: ["storage.k8s.io"]
    resources:
      ["storageclasses", "csinodes", "csistoragecapacities", "csidrivers"]
    verbs: ["watch", "list", "get"]
  - apiGroups: ["batch", "extensions"]
    resources: ["jobs"]
    verbs: ["get", "list", "watch", "patch"]
  - apiGroups: ["coordination.k8s.io"]
    resources: ["leases"]
    verbs: ["get", "create", "update"]
  - apiGroups: [""]
    resources: ["pods/eviction"]
    verbs: ["create"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: cluster-autoscaler
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: cluster-autoscaler
subjects:
  - kind: ServiceAccount
    name: cluster-autoscaler
    namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: cluster-autoscaler
  namespace: kube-system
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
rules:
  - apiGroups: ["coordination.k8s.io"]
    resources: ["leases"]
    verbs: ["create", "get", "update"]
    resourceNames: ["cluster-autoscaler"]
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["create", "list", "watch", "update"]
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: cluster-autoscaler
  namespace: kube-system
  labels:
    app: cluster-autoscaler
spec:
  replicas: 1
  selector:
    matchLabels:
      app: cluster-autoscaler
  template:
    metadata:
      labels:
        app: cluster-autoscaler
      annotations:
        prometheus.io/scrape: "true"
        prometheus.io/port: "8085"
    spec:
      serviceAccountName: cluster-autoscaler
      containers:
        - image: flowswiss/cluster-autoscaler:cloudbit 
          name: cluster-autoscaler
          imagePullPolicy: Always
          resources:
            limits:
              cpu: 100m
              memory: 300Mi
            requests:
              cpu: 100m
              memory: 300Mi
          command:
            - ./cluster-autoscaler
            - --v=4
            - --stderrthreshold=info
            - --cloud-provider=cloudbit
            - --nodes=1:6:workers
            - --skip-nodes-with-local-storage=false
            - --skip-nodes-with-system-pods=false
          env:
            - name: CLOUDBIT_API_TOKEN
              valueFrom:
                secretKeyRef:
                  key: **api-token** #base64_encoded_api_token
                  name: cluster-autoscaler-secrets
            - name: CLOUDBIT_CLUSTER_ID
              valueFrom:
                secretKeyRef:
                  name: cluster-autoscaler-secrets
                  key: **cluster-id** #base64_encoded_cluster_id
            - name: CLOUDBIT_API_URL
              valueFrom:
                secretKeyRef:
                  name: cluster-autoscaler-secrets
                  key: aHR0cHM6Ly9hcGkuY2xvdWRiaXQuY2gv #base64_encoded_api_url
```

2. Apply the yaml file with kubectl in your desired Kubernetes Cluster.<br>
3. Follow the official documentation to configure the behavior of the cluster autoscaler: <https://github.com/kubernetes/autoscaler/tree/master/cluster-autoscaler>\ <br>


# Object Storage

CloudBit Object Storage is an S3-compatible object storage service that lets you store and serve large amounts of data. You can create them in a few seconds and use them immediately with no configuration. Data transfer is automatically secured with HTTPS, and the available storage capacity scales seamlessly.

Object Storage are ideal for storing static, unstructured data like audio, video, and images as well as large amounts of text. Use cases like databases, applications written in server-side languages, and mission-critical applications will work best with local storage (volumes).

To **enable** Object Storage, navigate to Object Storage in the menu on the left then the desired location and click the **(+ plus)** button on the right. You will then see the Access Key, Secret Key and the Endpoint Address, required for connecting and using your Object Storage.

Please also follow our guides:

{% content-ref url="/pages/-MG2jV\_zVGwQ78pmBXHU" %}
[How-to](/products/object-storage/how-to)
{% endcontent-ref %}


# Instances

## Quickstart

1. Start by navigating to "Object Storage" > "Overview" in the [Control Panel](https://my.cloudbit.ch).<br>
2. Click the **Activate** button and confirm with **Yes, activate**. Deploying an Object Storage instance takes a few minutes.<br>
3. Once the instance is created, follow the [detailed guides](/products/object-storage/how-to) on how to access it.


# How-to

{% content-ref url="/pages/-MF5W08\_RhwAR2HIAFlv" %}
[Access Storage with AWS S3 SDKs](/products/object-storage/how-to/access-storage-with-aws-s3-sdks)
{% endcontent-ref %}

{% content-ref url="/pages/-MF5aj0qjJaUVSSLCpNs" %}
[Access Storage with Cyberduck](/products/object-storage/how-to/access-storage-with-cyberduck)
{% endcontent-ref %}

{% content-ref url="/pages/-MF5ah9MD1O-qo9vc347" %}
[Access Storage with Mountainduck](/products/object-storage/how-to/access-storage-with-mountainduck)
{% endcontent-ref %}


# Access Storage with AWS S3 SDKs

## Introduction <a href="#introduction" id="introduction"></a>

CloudBit Object Storage is an S3-compatible object storage service that lets you store and serve large amounts of data.

The CloudBit Object Storage API is inter-operable with the AWS S3 API, meaning you can use existing S3 tools and libraries with Spaces. A common use case is managing CloudBit Object Storage programmatically with AWS’ S3 SDKs.

## Install the SDK <a href="#install-the-sdk" id="install-the-sdk"></a>

Install the AWS SDK using the package manager for your language of choice.

{% tabs %}
{% tab title="Java Script" %}

```
npm install aws-sdk
```

{% endtab %}

{% tab title="Go" %}

```
go get -u github.com/aws/aws-sdk-go
```

{% endtab %}

{% tab title="PHP" %}

```
php composer.phar require aws/aws-sdk-php
```

{% endtab %}

{% tab title="Python" %}

```
pip install boto3
```

{% endtab %}

{% tab title="Ruby" %}

```
gem install aws-sdk-s3
```

{% endtab %}
{% endtabs %}

## Obtain Access & Secret Keys <a href="#obtain-access-and-secret-keys" id="obtain-access-and-secret-keys"></a>

You are able to retrieve the access & secret keys in our customer portal:

<https://my.cloudbit.ch/#/object-storage/BIT1/details>

The examples below rely on environment variables to access these keys. Export `ACCESS_KEY` and `SECRET_KEY` to your environment (e.g. `export ACCESS_KEY=DSJE2334JAS`) to make them available to your code.

## SDKs <a href="#sdks" id="sdks"></a>

After you set up and configure an SDK, you can follow the examples below to see how to perform common CloudBit Object Storage operations in JavaScript, Go, PHP, Python and Ruby.

{% tabs %}
{% tab title="Java Script" %}

```
const AWS = require('aws-sdk');
const fs = require('fs'); // Needed for example below

const spacesEndpoint = new AWS.Endpoint('<S3-ENDPOINT>');
const s3 = new AWS.S3({
    endpoint: spacesEndpoint,
    accessKeyId: process.env.ACCESS_KEY,
    secretAccessKey: process.env.SECRET_KEY
});
```

{% endtab %}

{% tab title="Go" %}

```
package main

import (
    "os"
    // Additional imports needed for examples below
    "fmt"
    "io"
    "strings"
    "time"

    "github.com/aws/aws-sdk-go/aws"
    "github.com/aws/aws-sdk-go/aws/credentials"
    "github.com/aws/aws-sdk-go/aws/session"
    "github.com/aws/aws-sdk-go/service/s3"
)

func main() {
    key := os.Getenv("ACCESS_KEY")
    secret := os.Getenv("SECRET_KEY")

    s3Config := &aws.Config{
        Credentials: credentials.NewStaticCredentials(key, secret, ""),
        Endpoint:    aws.String("https://<ENDPOINT>"),
        Region:      aws.String("us-east-1"),
    }

    newSession := session.New(s3Config)
    s3Client := s3.New(newSession)

    // ...
```

{% endtab %}

{% tab title="PHP" %}
{% hint style="info" %}
This SDK requires the `region` to be `us-east-1`, an AWS region name, to successfully create a new Bucket. The CloudBit Object Storage datacenter region is based on the \
\<ENDPOINT> value.
{% endhint %}

```
<?php

// Included aws/aws-sdk-php via Composer's autoloader
require 'vendor/autoload.php';
use Aws\S3\S3Client;

$client = new Aws\S3\S3Client([
        'version' => 'latest',
        'region'  => 'us-east-1',
        'endpoint' => 'https://<ENDPOINT>',
        'credentials' => [
                'key'    => getenv('ACCESS_KEY'),
                'secret' => getenv('SECRET_KEY'),
            ],
]);
```

{% endtab %}

{% tab title="Python" %}

```
import os
import boto3

session = boto3.session.Session()
client = session.client('s3',
                        region_name='nyc3',
                        endpoint_url='https://<ENDPOINT>',
                        aws_access_key_id=os.getenv('ACCESS_KEY'),
                        aws_secret_access_key=os.getenv('SECRET_KEY'))
```

{% endtab %}

{% tab title="Ruby" %}

```
require 'aws-sdk-s3'

client = Aws::S3::Client.new(
  access_key_id: ENV['ACCESS_KEY'],
  secret_access_key: ENV['SECRET_KEY'],
  endpoint: 'https://<ENDPOINT>',
  region: 'us-east-1'
)
```

{% endtab %}
{% endtabs %}

{% hint style="info" %}
Please replace the \<ENDPOINT> place holder with the correct endpoint:\
\
**Location BIT1:** os.bit1.cloudbit.ch
{% endhint %}


# Access Storage with Cyberduck

Mountain Duck enables you to mount and access CloudBit Object Storage as a regular disk drive. To access CloudBit Object Storage with Cyberduck, please follow these steps:

1. Download ([https://mountainduck.io](https://mountainduck.io/)) and install Cyberduck.<br>
2. Start Mountain Duck and click **Open Connection**.<br>
3. Specify your the credentials which are provided in our customer portal (<https://my.cloudbit.ch/#/object-storage/BIT1/details>):<br>
   * **Server:** Insert the DNS name of the S3 endpoint: \
     \
     Location BIT1: **os.bit1.cloudbit.ch**<br>
   * **Access Key ID:** Insert the displayed **Access Key** from our portal.
   * **Secret Access Key ID:** Insert the displayed **Secret Key** from our portal.<br>
4. Press the connect button

*Example:*

![](/files/-MG3SzfsSoUZ60fkySRY)


# Access Storage with Mountainduck

Mountain Duck enables you to mount and access CloudBit Object Storage as a regular disk drive. To access CloudBit Object Storage with Cyberduck, please follow these steps:

1. Download ([https://mountainduck.io](https://mountainduck.io/)) and install Cyberduck<br>
2. Start Mountain Duck and click **Open Connection**.<br>
3. Specify your the credentials which are provided in our customer portal (<https://my.cloudbit.ch/#/object-storage/BIT1/details>):<br>
   * **Server:** Insert the DNS name of the S3 endpoint: <br>

     Location BIT1: **os.bit1.cloudbit.ch**<br>
   * **Access Key ID:** Insert the displayed **Access Key** from our portal.
   * **Secret Access Key ID:** Insert the displayed **Secret Key** from our portal.<br>
4. Press the connect button

*Example:*

![](/files/-MG3WS7cPvnvtxykRbce)


# Ressources


# Supported Amazon S3 features

Besides basic Amazon S3 operations like GET, PUT, COPY, DELETE, the Flow Object Storage implementation of the Amazon S3 protocol supports the following features:

* Multipart upload
* Access control lists (ACLs)
* Versioning
* Signed URLs
* Object locking
* Geo-replication
* Server access logging
* Object storage classes
* Cross-region replication (CRR)
* Bucket policies
* Object expiration
* Cross-origin resource sharing (CORS)

## Supported authentication schemes

The following authentication schemes are supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* [Signature Version 2](https://docs.aws.amazon.com/general/latest/gr/signature-version-2.html)
* [Signature Version 4](https://docs.aws.amazon.com/general/latest/gr/signature-version-4.html)

The following authentication methods are supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* [Using the authorization header](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-auth-using-authorization-header.html)
  * [Transferring payload in a single chunk](https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-header-based-auth.html)
* [Using query parameters](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-query-string-auth.html)
* [Browser-based uploads using POST](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-UsingHTTPPOST.html)

The following authentication method is not supported:

* [Transferring payload in multiple chunks](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-streaming.html)

## Supported Amazon request headers

The following Amazon S3 REST request headers are currently supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* Authorization
* Content-Length
* Content-Type
* Content-MD5
* Date
* Host
* x-amz-content-sha256
* x-amz-date
* x-amz-security-token
* x-amz-object-lock-retain-until-date
* x-amz-object-lock-mode
* x-amz-object-lock-legal-hold
* x-amz-bypass-governance-retention
* x-amz-bucket-object-lock-enabled
* x-amz-geo-endpoint
* x-amz-geo-access-key
* x-amz-geo-access-secret

## Supported Amazon response headers

The following Amazon S3 REST response headers are currently supported by the CloudBit Object Storage implementation of the Amazon S3 protocol:

* Content-Length
* Content-Type
* Connection
* Date
* ETag
* x-amz-delete-marker
* x-amz-request-id
* x-amz-version-id
* x-amz-object-lock-retain-until-date
* x-amz-object-lock-mode
* x-amz-object-lock-legal-hold
* x-amz-geo-endpoint
* x-amz-geo-access-key
* x-amz-geo-access-secret

The following Amazon S3 REST response headers are not used:

* Server
* x-amz-id-2

## Supported Amazon error response headers

The following Amazon S3 REST error response headers are currently supported by the CloudBit Object Storage implementation of the Amazon S3 protocol:

* Code
* Error
* Message

The following Amazon S3 REST error response headers are not supported:

* RequestId (not used)
* Resource

## Supported Amazon S3 object expiration actions

The CloudBit Object Storage implementation of the Amazon S3 object lifecycle only supports object expiration by prefix. Deleting objects by tag is not available. The rule definition for object expiration is similar to that for bucket policies.

The following S3 object expiration actions are currently supported:

* Expiration. Deletes objects by age or by date. In case of versioning, inserts a delete marker, which becomes the latest version of an object. Delete markers are not removed.
* NonCurrentVersionExpiration. Deletes an object version after it has become non-current for the specified number of days.
* AbortIncompleteMultipartUpload. Aborts a multipart upload that has not completed during the specified number of days.
* ExpiredObjectDeleteMarker. Deletes a delete marker as soon as there are no other versions of an object.


# Replication Management

This section describes how to manage S3 cross-region replication (CRR) that enables copy objects asynchronously across buckets stored in different regions and public cloud providers using the Amazon S3-compatible CRR API.

{% content-ref url="/pages/KU19ZOSk6AUGTeoYGdZH" %}
[GET service replication](/products/object-storage/ressources/replication-management/get-service-replication)
{% endcontent-ref %}

{% content-ref url="/pages/IDBONAk6jOaCPwo2Rmeb" %}
[PUT service replication](/products/object-storage/ressources/replication-management/put-service-replication)
{% endcontent-ref %}

{% content-ref url="/pages/kjXLWHWyNx2ePwiL3xNO" %}
[DELETE service replication](/products/object-storage/ressources/replication-management/delete-service-replication)
{% endcontent-ref %}


# GET service replication

Lists information about replication configuration for the specified bucket.

### Requests <a href="#kanchor121" id="kanchor121"></a>

#### Syntax <a href="#kanchor122" id="kanchor122"></a>

```
GET /?replication HTTP/1.1
Host: <bucket>.<host>
Date: <date>
Authorization: <authorization_string>
```

#### Parameters <a href="#kanchor123" id="kanchor123"></a>

| Parameter | Description                                                        | Required |
| --------- | ------------------------------------------------------------------ | -------- |
| `bucket`  | <p>Bucket name.</p><p>Type: string.</p><p>Default value: none.</p> | Yes      |

#### Headers <a href="#kanchor124" id="kanchor124"></a>

This implementation uses only common request headers.

### Responses <a href="#kanchor125" id="kanchor125"></a>

#### Headers <a href="#kanchor126" id="kanchor126"></a>

| Header                    | Description                                                             |
| ------------------------- | ----------------------------------------------------------------------- |
| `x-amz-geo-endpoint`      | Endpoint of the remote region where to replicate objects to.            |
| `x-amz-geo-access-key`    | Access key of a user of the remote region used to replicate objects.    |
| `x-amz-geo-access-secret` | Access secret of a user of the remote region used to replicate objects. |

#### Body <a href="#kanchor127" id="kanchor127"></a>

An XML replication configuration in the following format:

```
<?xml version="1.0" encoding="UTF-8"?>
<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
   <Role>arn:aws:iam::<user_id>:role/s3-replication-role</Role>
   <Rule>
      <Status>Enabled|Disabled</Status>
      <Priority>1</Priority>
      <DeleteMarkerReplication>
         <Status>Enabled|Disabled</Status>
      </DeleteMarkerReplication>
      <Filter>
         <Prefix />
      </Filter>
      <Destination>
         <Bucket>arn:aws:s3:::<destination_bucket></Bucket>
      </Destination>
   </Rule>
</ReplicationConfiguration>
```

#### Examples <a href="#kanchor128" id="kanchor128"></a>

Sample request

Returns replication configuration of the bucket `test`.

```
GET /?replication HTTP/1.1
Host: os.bit1.cloudbit.ch
Date: Tu, 18 Jan 2021 14:08:55 GMT
Authorization: <authorization_string>
```

Sample response

```
HTTP/1.1 200 OK
Transfer-encoding : chunked
Server : nginx/1.8.1
Connection: closed
x-amz-request-id : 80000000000000030005c8caec96d65b
Date : Thu, 07 Apr 2016 14:08:56 GMT
Content-type : application/xml
<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
   <Role>arn:aws:iam::850b4943d62191a5:role/s3-replication-role</Role>
   <Rule>
      <Status>Enabled</Status>
      <Priority>1</Priority>
      <DeleteMarkerReplication>
         <Status>Disabled</Status>
      </DeleteMarkerReplication>
      <Filter>
         <Prefix />
      </Filter>
      <Destination>
         <Bucket>arn:aws:s3:::AWSDOC-EXAMPLE-BUCKET2</Bucket>
      </Destination>
   </Rule>
</ReplicationConfiguration>
```


# PUT service replication

Sets replication configuration for the specified bucket.

### Requests <a href="#kanchor110" id="kanchor110"></a>

#### Syntax <a href="#kanchor111" id="kanchor111"></a>

```
PUT /?replication HTTP/1.1
Host: <bucket>.<host>
Date: <date>
Authorization: <authorization_string>
```

#### Parameters <a href="#kanchor112" id="kanchor112"></a>

<table><thead><tr><th>Parameter</th><th width="382.66666666666663">Description</th></tr></thead><tbody><tr><td><code>bucket</code></td><td><p>Bucket name.</p><p>Type: string.</p></td></tr><tr><td><code>user_id</code></td><td><p>ID of the user that is used to replicate objects on your behalf.</p><p>Type: string.</p><p><br>The ID can always be taken from the Access Key by dropping the last 4 digits.</p></td></tr><tr><td><code>destination_bucket</code></td><td><p>The name of the bucket where you want to store the results.</p><p>Type: string.</p></td></tr><tr><td>&#x3C;authorization_string></td><td>&#x3C;authorization_string>: To get the authorization string in the request, you will need to use the AWS Signature Version 4 signing process. This process involves creating a signature using your AWS access key and secret key, along with information from the request, such as the date, the host, and the specific API endpoint you are trying to access. You can find more information on how to create this signature and add it to your request in the AWS documentation: <a href="https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html">https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html</a><br><a href="https://datafetcher.com/aws-signature-version-4-calculator">https://datafetcher.com/aws-signature-version-4-calculator</a></td></tr></tbody></table>

#### Body <a href="#kanchor113" id="kanchor113"></a>

An XML replication configuration in the following format:

```
<?xml version="1.0" encoding="UTF-8"?>
<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
   <Role>arn:aws:iam::<user_id>:role/s3-replication-role</Role>
   <Rule>
      <Status>Enabled|Disabled</Status>
      <Priority>1</Priority>
      <DeleteMarkerReplication>
         <Status>Enabled|Disabled</Status>
      </DeleteMarkerReplication>
      <Filter>
         <Prefix />
      </Filter>
      <Destination>
         <Bucket>arn:aws:s3:::<destination_bucket></Bucket>
      </Destination>
   </Rule>
</ReplicationConfiguration>
```

#### Headers <a href="#kanchor114" id="kanchor114"></a>

| Header                    | Description                                                                                                                                                                                                                                        |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `x-amz-geo-endpoint`      | <p>Endpoint of the remote region where to replicate objects to.<br><br>BIT1: os.bit1.cloudbit.ch<br>ZRH1 ([www.flow.swiss](http://www.flow.swiss)): os.zrh1.flow\.swiss<br>ALP1 ([www.flow.swiss](http://www.flow.swiss)): os.alp1.flow\.swiss</p> |
| `x-amz-geo-access-key`    | Access key of a user of the remote region used to replicate objects.                                                                                                                                                                               |
| `x-amz-geo-access-secret` | Access secret of a user of the remote region used to replicate objects.                                                                                                                                                                            |

### Responses <a href="#kanchor115" id="kanchor115"></a>

#### Headers <a href="#kanchor116" id="kanchor116"></a>

This implementation uses only common response headers.

#### Body <a href="#kanchor117" id="kanchor117"></a>

Empty.

#### Example <a href="#kanchor118" id="kanchor118"></a>

Sets replication configuration for the bucket. `test`.

```
PUT/?replication HTTP/1.1 
Host: test.os.bit1.cloudbit.ch 
Date: Tu, 13 Jan 2023 14:08:55 GMT 
Authorization: <authorization_string> 
x-amz-geo-endpoint: os.alp1.flow.swiss
x-amz-geo-access-key: <access_key> 
x-amz-geo-access-secret: <access-secret>

<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/"> 
   <Role>arn:aws:iam::<user_id>:role/s3-replication-role</Role> 
   <Rule> 
      <Status>Enabled</Status> 
      <Priority>1</Priority> 
      <DeleteMarkerReplication> 
         <Status>Disabled</Status> 
      </DeleteMarkerReplication> 
      <Filter> 
         <Prefix /> 
      </Filter> 
      <Destination> 
         <Bucket>arn:aws:s3:::os.alp1.flow.swiss</Bucket> 
      </Destination> 
   </Rule> 
</ReplicationConfiguration>
```

**Sample response**

```
HTTP/1.1 200 OK
Transfer-encoding : chunked
Server : nginx/1.8.1
Connection: closed
x-amz-request-id : 80000000000000030005c8caec96d65b
Date : Tu, 21 Jan 2021 14:08:56 GMT
```

\
&#x20;


# DELETE service replication

Deletes replication configuration for the specified bucket.

### Requests <a href="#kanchor57" id="kanchor57"></a>

#### Syntax <a href="#kanchor58" id="kanchor58"></a>

```
DELETE /?replication HTTP/1.1
Host: <bucket>.<host>
Date: <date>
Authorization: <authorization_string>
```

#### Parameters <a href="#kanchor59" id="kanchor59"></a>

| Parameter | Description                             |
| --------- | --------------------------------------- |
| `bucket`  | <p>Bucket name.</p><p>Type: string.</p> |

#### Headers <a href="#kanchor60" id="kanchor60"></a>

This implementation uses only common request headers.

### Responses <a href="#kanchor61" id="kanchor61"></a>

#### Headers <a href="#kanchor62" id="kanchor62"></a>

This implementation uses only common response headers.

#### Body <a href="#kanchor63" id="kanchor63"></a>

Empty.

#### Examples <a href="#kanchor64" id="kanchor64"></a>

Sample request

Deletes replication configuration of the bucket `test`.

```
DELETE/?replication HTTP/1.1
Host: test.os.bit1.cloudbit.ch
Date: Tu, 18 Jan 2021 14:08:55 GMT
Authorization: <authorization_string>
```

Sample response

```
HTTP/1.1 200 OK
Transfer-encoding : chunked
Server : nginx/1.8.1
Connection: closed
x-amz-request-id : 80000000000000030005c8caec96d65b
Date : Tu, 21 Jan 2021 14:08:56 GMT
```


# Overview

CloudBit provides several command-line interfaces (CLIs) and application programming interfaces (APIs) for managing your resources. This section provides the reference materials for these offerings.

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th data-hidden></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><strong>API</strong></td><td></td><td></td><td><a href="/pages/-MF5vQrrsvKGKQEwibHq">/pages/-MF5vQrrsvKGKQEwibHq</a></td><td><a href="/files/vXxxViYVGj7qB3xmbjD8">/files/vXxxViYVGj7qB3xmbjD8</a></td></tr><tr><td><strong>CLI</strong></td><td></td><td></td><td><a href="/pages/-MYACL3XMZvpZuCw4uIq">/pages/-MYACL3XMZvpZuCw4uIq</a></td><td><a href="/files/PwQZTHpBDlGiVdu7zrKl">/files/PwQZTHpBDlGiVdu7zrKl</a></td></tr><tr><td><strong>Terraform Provider</strong></td><td></td><td></td><td><a href="/pages/qWJyvppZW9qniWt0Yh53">/pages/qWJyvppZW9qniWt0Yh53</a></td><td><a href="/files/CT2Z70udBdVOiksyP6fC">/files/CT2Z70udBdVOiksyP6fC</a></td></tr></tbody></table>


# API

The CloudBit API allows you to manage resources within the CloudBit cloud in a simple, programmatic way using conventional HTTP requests. The endpoints are intuitive and powerful, allowing you to easily make calls to retrieve information or to execute actions.

All of the functionality that you are familiar with in the CloudBit control panel is also available through the API, allowing you to script the complex actions that your situation requires. Our API has predictable resource-oriented URLs, accepts and returns JSON-encoded content and uses standard HTTP response codes.

### Documentation <a href="#documentation" id="documentation"></a>

The latest API documentation is available here: <https://my.cloudbit.ch/#/doc/general>

### Authentication

Most of our requests are protected tough a user role management system and therefore require identification of the current user. This authentication system works by requesting an authentication token using a username and password and sending the generated token with each request in the X-Auth-Token header.

To generate such a token you have to make the following request:

```
POST https://api.cloudbit.ch/v3/auth
{
	"username": "…",
	"password": "…"
}
```

```
{
	"token": "…",
	"id": 1,
	"username": "my@cloudbit.ch"
}
```

Please find here more details about the authentication endpoints and models:\
<https://my.cloudbit.ch/#/doc/authentication>


# Product Entities

### Object Storage <a href="#object-storage" id="object-storage"></a>

| ID | Product        |
| -- | -------------- |
| 20 | Object Storage |

### Compute <a href="#compute" id="compute"></a>

| ID | Product    |
| -- | ---------- |
| 40 | b1.1x1     |
| 24 | b1.1x2     |
| 25 | b1.2x2     |
| 26 | b1.2x4     |
| 27 | b1.2x8     |
| 28 | b1.4x8     |
| 29 | b1.4x16    |
| 30 | b1.4x32    |
| 31 | b1.8x32    |
| 32 | b1.8x64    |
| 33 | b1.8x96    |
| 34 | b1.16x96   |
| 35 | b1.16x128  |
| 36 | b1.24x128  |
| 37 | b1.24x256  |
| 38 | b1.32x256  |
| 39 | b1.32x512  |
| 8  | Elastic IP |


# Location Entities

### Location <a href="#location" id="location"></a>

| ID | Location |
| -- | -------- |
| 1  | BIT1     |


# CLI

CloudBit CLI allows you to interact with the CloudBit API via the command line. It supports most functionality found in the control panel. You can create, configure, and destroy Flow resources like Instances, Security Groups, Networks and more. We will add Object Storage support soon.

### Installation

The CLI is written in Go and the source code is public available: <https://github.com/flowswiss/cli>\
If you have GoLang installed, you can download and install the CLI with

```
go get github.com/flowswiss/cli/cmd/flow
```

otherwise, you will need to download the [Go](https://golang.org) executable for your system.

### Usage

After downloading you first of all need to authenticate the cli with your username and password. **Warning**: those credentials will be stored in `$HOME/.flow/credentials.json`

```
flow auth login --username 'USERNAME' --password 'PASSWORD'
```

alternatively you can also pass `--username USERNAME` and `--password PASSWORD` to every other command or set the environment variables `FLOW_USERNAME` and `FLOW_PASSWORD` to avoid the credentials getting stored in your home directory.

Once you have successfully logged in into your account, you can start manipulating things in your organization. As a first step it would be a good idea to upload your personal ssh key onto our platform. You will need this for every linux virtual machine you deploy.

```
flow compute key-pair create \
    --name 'My first key pair' \
    --public-key ~/.ssh/id_rsa.pub
```

Just to test things out, you can try creating an ubuntu virtual machine using the previously uploaded key pair:

```
flow compute server create \
    --name 'My first virtual machine' \
    --location 'ALP1' \
    --image 'ubuntu-20.04' \
    --product 'b1.1x1' \
    --key-pair 'My first key pair'
```

Further usage manuals can be found in the application itself using the `-h` or `--help` flags or in our usage documentation found [here](https://github.com/flowswiss/cli/blob/master/docs/usage.md).


# Terraform

Terraform is an Infrastructure-as-Code tool that lets you provision, and version cloud resources safely and efficiently. It enables automated and repeatable provisioning of CloudBit resources.

<https://github.com/cloudbit-ch/terraform-provider-cloudbit>


