Door Kubernetes Service (DKS)¶
DKS gives your organization a managed Kubernetes cluster. You choose the zone, the Kubernetes version, the worker size, and how the API is reached. Door runs the control plane. You run your workloads with kubectl.
You can manage a cluster entirely yourself, from create through delete, in three places:
- the Door console
- the customer API at
https://dks-api.apps.door.cloud(/v1/public/clustersand/v1/catalog) - Maya, the assistant in the console
Start here¶
- Console — sign in at https://door.cloud, select the organization, open Clusters, then follow Getting started (one cluster in about 15 minutes).
- API —
https://dks-api.apps.door.cloudwithAuthorization: Bearer $DOOR_TOKEN. Customer routes are/v1/catalogand/v1/public/clusters. Every endpoint, field, and status code is in the API reference. - Maya — open the assistant in the console and ask, for example, “List clusters in this organization.” See Maya AI assistant.

Screenshot from the demo organization (clusters cp-canary and cp-canary-in). Examples in this guide use organization acme and cluster payments-prod.
A member of the organization can read. A super_admin can create, change, and delete. See Authentication and organizations.
Guides¶
| Guide | What you will do |
|---|---|
| What DKS is | Concepts, lifecycle, what you manage and what Door manages |
| Getting started | Create a cluster, download access, run kubectl, delete it |
| Authentication and organizations | Tokens, organization selection, member vs super_admin |
| Catalog, zones, versions, and machine tiers | What you can create in a zone |
| Cluster lifecycle | Create, read, follow progress, update, delete |
| Node pools and nodes | Add, scale, and remove workers |
| Kubeconfig and kubectl | door CLI (recommended) and static kubeconfig |
| API server exposure | Private (VPN) or public API hostname |
| Elastic IPs | Stable addresses for your applications |
| Firewall rules | Open ports on workers |
| Door console | Every page and tab, with screenshots |
| Maya AI assistant | Ask Maya, approve changes, follow progress |
| Errors and troubleshooting | Status codes and what to do |
| Limits and constraints | Names, counts, and quotas |
| API reference | Every customer endpoint and field |
Glossary¶
| Term | Meaning |
|---|---|
| Organization | The Door tenant that owns your clusters. Example: acme. |
| Zone | Where the cluster runs. Today: abidjan (Abidjan, Côte d'Ivoire). |
| Cluster | One managed Kubernetes cluster. Name example: payments-prod. |
| Node pool | A group of workers that share one machine tier and a desired count. |
| Node | One worker. The name matches kubectl get nodes. |
| Machine tier | A public size id such as dks.c5.xlarge (vCPU, memory, disk). |
| Exposure | How you reach the Kubernetes API: private (your network or VPN) or public (an HTTPS hostname under clusters.dks.door.africa). |
| Network mode | How application addresses are routed: intranet (VPN) or internet. Set at create, then immutable. |
| Elastic IP | A stable address you allocate for an application on a ready cluster. |
| Firewall rule | An ingress rule on workers: protocol, ports, source networks. |
| Phase | Requested, Provisioning, ControlPlaneReady, NodesReady, Provisioned, Failed, Deleting, Deleted. The console shows Ready for Provisioned. |
| door CLI | doorctl. Recommended way to run kubectl: short-lived credentials that rotate. |
| Maya | The Door assistant. It asks you to confirm before it changes a cluster. |