Skip to content

Cloud providers

With a provider credential, Falak creates the machine for you through the provider’s API, passes the install command as cloud-init user data, and waits for the agent to enroll. The rest is identical to a custom server.

Provider API value API endpoint (override)
Hetzner Cloud hetzner https://api.hetzner.cloud/v1 (FALAK_HETZNER_API_URL)
DigitalOcean digitalocean https://api.digitalocean.com/v2 (FALAK_DIGITALOCEAN_API_URL)
Vultr vultr https://api.vultr.com/v2 (FALAK_VULTR_API_URL)
Akamai / Linode linode https://api.linode.com/v4 (FALAK_LINODE_API_URL)
AWS Lightsail aws https://lightsail.{region}.amazonaws.com (FALAK_LIGHTSAIL_API_URL)
Custom custom none: you run the install command
  1. Create an API token (or access key for AWS) with permission to create and delete servers at your provider.
  2. Open Settings → Cloud providers, choose the provider and paste the credential. It is stored encrypted.
  3. Falak loads the provider’s regions, sizes and images (cached for an hour, FALAK_PROVIDERS_CATALOG_TTL).

Managing credentials needs providers.manage (owners and admins).

Settings → Cloud providers: credentials per provider with their status.

In Servers → Create, pick the provider, the credential, the region, the size and the image, then the type and software as usual. Falak creates the machine with the install command as user data. The server stays creating until the agent enrolls, then provisions automatically.

Deleting a server in Falak also destroys the machine at the provider by default (destroy_at_provider, default true in the API). Custom servers are only forgotten: the agent keeps running until you remove it (systemctl disable --now falak-agent).

  • AWS is Lightsail only; EC2 is not supported. Use a custom server for EC2.
  • Deleting an organization revokes its agents but does not destroy provider machines.
  • Provider APIs are covered by unit and feature tests with faked responses, not yet by the end-to-end suite.
  • HTTP calls to providers time out after 30 s (FALAK_PROVIDERS_HTTP_TIMEOUT) and retry rate limits and idempotent failures up to 3 times.