Limits and constraints¶
Hard limits the public API enforces. Values come from request schemas, the Abidjan catalog, and route query bounds. Commercial quotas that are not in this API are contact your Door account team.
Who can do this: read this page before create and scale. Enforcement is the same for console, API, and Maya.
Names and tags¶
Pattern (RFC 1123 DNS label), unless noted:
| Field | Min | Max | Notes |
|---|---|---|---|
Cluster name | 1 | 63 | Catalog constraints.cluster_name. Immutable after create. Unique per organization. |
| Organization slug | 1 | 63 | Same pattern on create body organization. |
Node pool name | 1 | 63 | Unique on the cluster. Default pool name on create is default if you omit it in PublicNodePoolRequest. |
Cluster tags[] | 1 | 63 each | Max 64 tags. Each entry is a DNS label (not free-form key=value on write — the catalog/create schema is labels only). |
Elastic IP name | 1 | 63 | Optional. Unique among alive EIPs on the cluster. |
Firewall rule name | 1 | 63 | Optional. Unique among alive rules on the cluster. |
Firewall description | — | 255 | Optional. |
Cluster description | — | 16384 | Optional. |
Node-pool labels and tags are string-to-string maps. The public schema does not add extra key syntax checks beyond JSON strings.
Worker node names on DELETE …/nodes/{node_name} must match ^[a-z0-9][-a-z0-9.]{0,252}[a-z0-9]$.
Cluster and pool shape¶
From GET /v1/catalog → constraints.node_pools and the create schema:
| Constraint | Value |
|---|---|
| Pools per cluster | 1–20 (min_length 1 on create) |
Nodes per pool count | 0–200. count=0 requires auto_scale=true (otherwise 422). Without autoscaling, count ≥ 1. |
Catalog min_nodes_per_pool / max_nodes_per_pool | 1 / 200 (catalog card; schema allows 0 with autoscaling) |
| Autoscaling | auto_scale=true requires max_nodes. min_nodes defaults to 1 if omitted. min_nodes ≤ max_nodes. count must lie in [min_nodes, max_nodes]. max_nodes ≥ 1; min_nodes ≥ 0. |
Pool size | Public machine tier id. Immutable. To change tier, delete the pool and add another (you cannot delete the last pool). |
| Control plane | Not customer-selectable. Door applies the zone's active option. |
Idempotency-Key¶
Header on create, delete, and node-pool PATCH:
Same key + same body → replay (Idempotency-Replay: true). Same key + different body → 409. Optional; if omitted, every call is a new request.
Pagination and long-poll¶
| Parameter | Default | Bounds |
|---|---|---|
List page | 1 | ≥ 1 |
List size | 20 | 1–100 |
/state since | 0 | ≥ 0 |
/state timeout_seconds | 25 | 0–60 |
Kubeconfig¶
- Allowed phases:
ControlPlaneReady,Provisioned. 202retry: honorRetry-After/retry_after_seconds(default 5 seconds).format=plain(default) orformat=json.- After exposure changes, download again.
Exposure¶
- Values:
public,private. - Create default: catalog
defaults.exposure_mode(currentlypublic). - PATCH only when
phase=Provisioned. NotProvisioned→400. In-flight other change →409. - Public hostname suffix:
clusters.dks.door.africa. Zone must have public exposure enabled (Abidjan: yes).
Network mode and Elastic IPs¶
- Create default: catalog
defaults.network_mode=intranet. - Immutable after create.
intranet→ Elastic IPexposure=privateonly.internet→ Elastic IPexposure=publiconly. Public also needs the zone public pool (Abidjan: enabled). Otherwise503.- Mismatch →
409. - EIP statuses:
Pending,Provisioning,Ready,Failed,Deleting,Deleted. - Release only from
ReadyorFailed. - No bind route on the public API. Attach workloads with Service annotation
dks.door.africa/elastic-ip(see Elastic IPs). - No per-org EIP count in code. Zone pool exhausted →
503.
Firewall rules¶
- Ingress only;
tcp/udp/icmp. - ≤ 16 IPv4 CIDRs per rule.
- No max rule count in code.
- Cluster must be
Provisioned. - No firewall editor in the Door console Networking tab (API or automation only). Maya can list Elastic IPs but cannot allocate, release, or change firewall rules.
Zones and Kubernetes versions¶
From Abidjan public catalog (GET /v1/catalog?zone=abidjan):
| Item | Value |
|---|---|
| Zone id | abidjan |
| Display name | Abidjan |
| Region label | Côte d'Ivoire |
| Kubernetes version | v1.32.4 (label 1.32.4, recommended, channel stable) |
Unknown zone query → 400.
Create and patch bodies forbid extra fields (422). Do not send control-plane flags, raw size names, CIDR blocks, or operator-only keys. The catalog lists control_plane_options for display. Public create ignores a client-side pick. Door applies the option assigned to your organization; active_control_plane_option_id is the zone default.
The Door console create form includes Where can your applications be reached? (Private (VPN) = intranet, Internet = internet). Same immutability as the API.
Machine tiers (Abidjan)¶
Use these ids as size:
| Id | Display | vCPU | Memory (GiB) | Disk (GiB) | Recommended |
|---|---|---|---|---|---|
dks.c5.large | c5.large | 2 | 4 | 50 | no |
dks.m5.large | m5.large | 2 | 8 | 60 | no |
dks.c5.xlarge | c5.xlarge | 4 | 8 | 80 | yes |
dks.m5.xlarge | m5.xlarge | 4 | 16 | 120 | no |
dks.c5.2xlarge | c5.2xlarge | 8 | 16 | 160 | no |
Root volume size follows the catalog disk for the tier (root_volume_size_gib on the pool response).
Organization quotas¶
There is no general “N clusters per org” cap in the public API.
What does exist:
- Prepaid credit →
402on create and scale (see errors). - Door hub on the cluster body:
hub_registration.reason/default_environment.reasonmay beorganization quota exceeded,name or address conflict in the Door hub,registration rejected by the Door hub,waiting for Door platform installation, orDoor platform installation failed. Contact your account team. - Zone pool / capacity →
503on Elastic IP or create.
Anything else (seat counts, contract caps) → contact your Door account team. Do not assume a number that is not in this table.