#Providers
Providers are cloud accounts connected to an organization so Central can create a VPS, install OSS on it and connect it, all in one flow.
Backend Phase 5 — Integrations is now drafted (2026-10-03), so providers are specified: cloud provider accounts live in Central at organization level, and the create-server flow installs OSS automatically. V8 requirement The screen spec is on FE: Integrations; this page keeps the V7 / OSS detail behind it. V7 remains the functional reference V7 only; the OSS installer supports being installed for Central OSS API.
#Supported providers (V7)
| Provider | Connect method in V7 | Notes |
|---|---|---|
| DigitalOcean | OAuth (redirect → integrations/cloud-service-providers callback) | Token refresh middleware renewServerProviderToken |
| Linode (Akamai) | OAuth | Root password required at create (11–128 chars, mixed + symbol) |
| Vultr | API key | Name: letters, digits, hyphens, ≤ 63 chars |
| Hetzner | API key | Name: letters, digits, dots, hyphens |
| AWS Lightsail | Access key + secret | Needs availabilityZone |
| EC2, Hostinger | Present in V7's enum, not in the store validation (lightsail,vultr,hetzner) | Hostinger is NOT a provider — answered 2026-10-03 (Q12). V7 has no Hostinger API, connect form or create-server; it only detects a Hostinger IP when someone adds an existing server, and then removes Hostinger's pre-installed Apache/MySQL before installing. That belongs to the Servers phase. EC2 is not mentioned by Phase 5 at all Open question |
Each provider is enabled/disabled by admin config (CloudPlatform … enabled), and V7 rejects a disabled one with "
The demo shows Vultr, DigitalOcean, Linode and Hetzner Cloud, with token connect and a last-4 preview. Demo UI only
#Connect account
- V7 table
cloud_server_providers:organization_id,name(account email or label),provider,access_key,access_secret,refresh_token,expires_at,server_limit. Organization-scoped. V7 only - Duplicate account (same email for OAuth providers) is refused. V7 only V8 has no such rule: accounts are identified by a name the user types, and several accounts per provider are allowed (2026-10-03). V8 requirement
- Tokens are never returned to the browser. Only provider, label and last 4 characters.
- Disconnect: the backend now refuses it while any server in Central was created with that account (2026-10-03), and the warning lists those servers. Our earlier recommendation to refuse rather than silently allow it is therefore confirmed V8 requirement — the frontend disables the button with "Used by N servers" instead of letting the user try.
#Regions and sizes
Moved to the Servers phase on 2026-10-03 — regions and sizes are read when creating a server, not on the Integrations page.
GET …/cloud-server-providers/{id}/regionsand…/sizes(V7, with token refresh). V7 only- Sizes must show price/month from the provider (not Central's price), CPU, RAM, disk, and whether they meet OSS's minimum. The OSS installer itself checks memory and adds swap. OSS API
#Create VPS → install OSS → connect (Servers phase, not Integrations)
| Step | Who | Source |
|---|---|---|
| Inputs | Phase 5 (2026-10-03): provider account, region, size, Ubuntu 22.04 / 24.04 / 26.04, stack (Nginx + PHP / Apache + PHP / Nginx + Node (MERN) / OpenLiteSpeed + PHP), name, optional SSH key, root password for Linode. V7 also asked for database engine, nodejs and yarn — not in Phase 5 | V8 requirement · extras V7 only |
| Limit/credit checks | Email verified, trial server limit, plan, credits ("The … are insufficient. Please add $N") | V7 only |
| Install | `install.sh --stack=lemp | lamp |
| Wait | OSS doesn't call Central back. Central polls GET /api/health | OSS API |
| Link | Server record with the generated token | Missing |
#Bring your own VPS (demo concept)
The demo offers "Install on your VPS": Central connects over SSH with a root password used once, then installs and connects. V7 had a similar "direct installation" (direct-installation/generate-command). Demo UI only V7 only In V8 this could simply be: show a one-line install command containing a one-time CENTRAL_TOKEN, and the user runs it on their server. Open question D-13 — Phase 5 explicitly leaves "connecting an existing / own server" to the Servers phase, so this is still undecided.
#Provider differences that affect the UI
| Area | Difference |
|---|---|
| Auth | V8: a pasted API token for all — one field, except Lightsail's access key + secret key. (V7 used OAuth for DigitalOcean and Linode.) V8 requirement |
| Required extra fields | Linode root password, Lightsail availability zone |
| Naming rules | Different regex per provider |
| Token expiry | V8: no refresh. A rejected token → the account shows "Needs new token" and the user pastes a new one V8 requirement |
| Power / resize | V7 had droplet power and resize endpoints. Out of scope for V8 first release Open question |