Skip to content

Limits and constraints

Hard limits the public API enforces. Values come from request schemas, the Abidjan catalog, and route query bounds. Commercial quotas that are not in this API are contact your Door account team.

Who can do this: read this page before create and scale. Enforcement is the same for console, API, and Maya.

Names and tags

Pattern (RFC 1123 DNS label), unless noted:

^[a-z0-9]([-a-z0-9]{0,61}[a-z0-9])?$
Field Min Max Notes
Cluster name 1 63 Catalog constraints.cluster_name. Immutable after create. Unique per organization.
Organization slug 1 63 Same pattern on create body organization.
Node pool name 1 63 Unique on the cluster. Default pool name on create is default if you omit it in PublicNodePoolRequest.
Cluster tags[] 1 63 each Max 64 tags. Each entry is a DNS label (not free-form key=value on write — the catalog/create schema is labels only).
Elastic IP name 1 63 Optional. Unique among alive EIPs on the cluster.
Firewall rule name 1 63 Optional. Unique among alive rules on the cluster.
Firewall description — 255 Optional.
Cluster description — 16384 Optional.

Node-pool labels and tags are string-to-string maps. The public schema does not add extra key syntax checks beyond JSON strings.

Worker node names on DELETE …/nodes/{node_name} must match ^[a-z0-9][-a-z0-9.]{0,252}[a-z0-9]$.

Cluster and pool shape

From GET /v1/catalog → constraints.node_pools and the create schema:

Constraint Value
Pools per cluster 1–20 (min_length 1 on create)
Nodes per pool count 0–200. count=0 requires auto_scale=true (otherwise 422). Without autoscaling, count ≥ 1.
Catalog min_nodes_per_pool / max_nodes_per_pool 1 / 200 (catalog card; schema allows 0 with autoscaling)
Autoscaling auto_scale=true requires max_nodes. min_nodes defaults to 1 if omitted. min_nodes ≤ max_nodes. count must lie in [min_nodes, max_nodes]. max_nodes ≥ 1; min_nodes ≥ 0.
Pool size Public machine tier id. Immutable. To change tier, delete the pool and add another (you cannot delete the last pool).
Control plane Not customer-selectable. Door applies the zone's active option.

Idempotency-Key

Header on create, delete, and node-pool PATCH:

^[A-Za-z0-9_\-:.]{8,255}$

Same key + same body → replay (Idempotency-Replay: true). Same key + different body → 409. Optional; if omitted, every call is a new request.

Pagination and long-poll

Parameter Default Bounds
List page 1 ≥ 1
List size 20 1–100
/state since 0 ≥ 0
/state timeout_seconds 25 0–60

Kubeconfig

  • Allowed phases: ControlPlaneReady, Provisioned.
  • 202 retry: honor Retry-After / retry_after_seconds (default 5 seconds).
  • format=plain (default) or format=json.
  • After exposure changes, download again.

Exposure

  • Values: public, private.
  • Create default: catalog defaults.exposure_mode (currently public).
  • PATCH only when phase=Provisioned. Not Provisioned → 400. In-flight other change → 409.
  • Public hostname suffix: clusters.dks.door.africa. Zone must have public exposure enabled (Abidjan: yes).

Network mode and Elastic IPs

  • Create default: catalog defaults.network_mode = intranet.
  • Immutable after create.
  • intranet → Elastic IP exposure=private only.
  • internet → Elastic IP exposure=public only. Public also needs the zone public pool (Abidjan: enabled). Otherwise 503.
  • Mismatch → 409.
  • EIP statuses: Pending, Provisioning, Ready, Failed, Deleting, Deleted.
  • Release only from Ready or Failed.
  • No bind route on the public API. Attach workloads with Service annotation dks.door.africa/elastic-ip (see Elastic IPs).
  • No per-org EIP count in code. Zone pool exhausted → 503.

Firewall rules

  • Ingress only; tcp / udp / icmp.
  • ≤ 16 IPv4 CIDRs per rule.
  • No max rule count in code.
  • Cluster must be Provisioned.
  • No firewall editor in the Door console Networking tab (API or automation only). Maya can list Elastic IPs but cannot allocate, release, or change firewall rules.

Zones and Kubernetes versions

From Abidjan public catalog (GET /v1/catalog?zone=abidjan):

Item Value
Zone id abidjan
Display name Abidjan
Region label Côte d'Ivoire
Kubernetes version v1.32.4 (label 1.32.4, recommended, channel stable)

Unknown zone query → 400.

Create and patch bodies forbid extra fields (422). Do not send control-plane flags, raw size names, CIDR blocks, or operator-only keys. The catalog lists control_plane_options for display. Public create ignores a client-side pick. Door applies the option assigned to your organization; active_control_plane_option_id is the zone default.

The Door console create form includes Where can your applications be reached? (Private (VPN) = intranet, Internet = internet). Same immutability as the API.

Machine tiers (Abidjan)

Use these ids as size:

Id Display vCPU Memory (GiB) Disk (GiB) Recommended
dks.c5.large c5.large 2 4 50 no
dks.m5.large m5.large 2 8 60 no
dks.c5.xlarge c5.xlarge 4 8 80 yes
dks.m5.xlarge m5.xlarge 4 16 120 no
dks.c5.2xlarge c5.2xlarge 8 16 160 no

Root volume size follows the catalog disk for the tier (root_volume_size_gib on the pool response).

Organization quotas

There is no general “N clusters per org” cap in the public API.

What does exist:

  • Prepaid credit → 402 on create and scale (see errors).
  • Door hub on the cluster body: hub_registration.reason / default_environment.reason may be organization quota exceeded, name or address conflict in the Door hub, registration rejected by the Door hub, waiting for Door platform installation, or Door platform installation failed. Contact your account team.
  • Zone pool / capacity → 503 on Elastic IP or create.

Anything else (seat counts, contract caps) → contact your Door account team. Do not assume a number that is not in this table.