# Overview

![](/files/-M2-qdJIfLB6aNqGKv5J)

## [About](https://flow.swiss/about-us)

Flow is an ISO 27001-certified Swiss cloud service provider. The company, which was established in 2009 and is run by its founders, offers premium cloud services with a focus on simplicity. Flow Cloud Platform is based in two state of the art data centers in Switzerland: ZRH1 (Zurich), the most modern DC on Swiss soil; and ALP1 (Luzern), located at the edge of the Swiss Alps.

### [Sign Up](/platform/account/sign-up)

If you haven't already signed up for an account, this is the place to begin.


# Release Notes

Updates and improvements to our cloud platform.

{% hint style="info" %}
You can try the platform for free. [**Start now**](https://my.flow.swiss/#/register).
{% endhint %}

## v4.17.9

<figure><img src="/files/x4uIMpV4rU3GGBPwGoBW" alt=""><figcaption></figcaption></figure>

Release date: May 14, 2025

### New Features

With the release 4.17.9 our focus was on the implementation of the latest [**Apple M4 Pro Mac Minis**](https://flow.swiss/mac-bare-metal) for our Mac Bare Metal service. The iOS and general Apple Ecosystem developer community can now benefit from improved build performance. In addition, the first version of the **SSO implementation** for Google Accounts was also introduced.

#### Mac Bare Metal

* Support and availability for new Apple M4 Pro Mac minis

#### CI Engine

* Many improvements at core level including switch to M4 Pro Mac minis

### Improvements and Fixes

* SSO with Google Accounts
* General platform-related improvements and fixes

## v4.17.4

<figure><img src="/files/6dZJPDjGDjEIfH8xY2tq" alt=""><figcaption></figcaption></figure>

Release date: December 04, 2024

### New Features

With release 4.17.4, our focus was on the latest Kubernetes version v1.30. As a result, our customers can update their Kubernetes clusters to the latest version with just one click. The following Kubernetes topics were also addressed and improved with the same release: cluster certificate expiration, cluster action logic, restart issue upon kernel panic of a node, health check, and how k3s handles CCM and external Load Balancers.

#### Compute

* New images: Flatcar 3975

### Improvements and Fixes

* Kubernetes improvements
* CI Engine improvements
* General platform-related improvements and fixes

## v4.17.0

<figure><img src="/files/OIbVGEQPetNHCVWkZKxb" alt=""><figcaption></figcaption></figure>

Release date: May 29, 2024

### New Features

With the long-awaited release of 4.17, we focused exclusively on developing our new [CI Engine](https://flow.swiss/ci-engine) service. CI Engine is a managed cloud service powered by the latest generation Apple Silicon Mac minis (M2 Pro), supporting ephemeral macOS build agents. It is explicitly designed and built for CI/CD purposes and easily integrates with existing CI pipeline solutions. The first version of CI Engine comes with direct integration into [Buildkite](https://buildkite.com/), a modern continuous integration and continuous delivery platform.

{% hint style="info" %}
CI Engine will initially be available to a limited number of customers. If you are interested, please [get in touch with us](https://flow.swiss/contact/#sales).
{% endhint %}

#### Mac Bare Metal

* Support and availability for new Apple M2 Mac minis (m2.8-24-512)

#### Compute

* New images: Ubuntu 24.04 LTS, Debian 12.5, CentOS 8.4, Alma Linux 9.3, Rocky Linux 9.3, VyOS 1.3.6, FortiGate 7.4.3, Fedora 39, Fedora CoreOS 39, Flatcar 3815

### Improvements and Fixes

* Cloud Console - Core & Infrastructure Upgrades
* General platform-related improvements and fixes

## v4.16.0

<figure><img src="/files/xLgIsfDk25F69aOL3RRP" alt=""><figcaption></figcaption></figure>

Release date: July 04, 2023

### New Features

With release 4.16, our focus was on the [Kubernetes Cluster Autoscaler](https://doc.flow.swiss/products/kubernetes/resources/cluster-autoscaler). The cluster autoscaler automatically resizes the number of nodes based on the demands of your workload. When demand is low, the cluster autoscaler scales back down to the minimum size you designate. This can increase the availability of your workload when you need it while controlling costs. You don't need to add or remove nodes or over-provision your nodes manually.

#### Compute

* New images: Debian 12, Rocky Linux 8.8, FortiGate 7.4.0, Fedora 38, Fedora CoreOS 38, Flatcar 3510, FreeBSD 13.2, OpenBSD 7.3

### Improvements and Fixes

* General platform-related improvements and fixes

## v4.15.0

<figure><img src="/files/UyRmUT7BPDVRdZCUQFML" alt=""><figcaption></figcaption></figure>

Release date: June 08, 2023

### New Features

With release 4.15, our focus was on the integration of [DevPod](https://devpod.sh/). DevPod is a convenient and easy-to-use open-source tool for creating reproducible developer environments. It comes with [native clients](https://devpod.sh/docs/getting-started/install) for macOS, Windows, and Linux. To get started with Flow Provider for DevPod, please follow [this link](https://github.com/flowswiss/devpod-provider-flow#getting-started).

#### General

* Voucher-Code support

### Improvements and Fixes

* General platform-related improvements and fixes

## v4.14.0

<figure><img src="/files/bY8mnjcdXLlA1ZXLqVs9" alt=""><figcaption></figcaption></figure>

Release date: April 27, 2023

### New Features

Like any comprehensive software, our Cloud Console needs regular refactoring under the hood, which has been implemented with this release. So this release contains mainly major core & infrastructure upgrades of the Cloud Console and some new bold new features and integrations.

#### Mac Bare Metal

* Support and availability for new Apple M2 Pro Mac minis

#### Compute & Kubernetes

* VPN as a Service (Support for VMs with Elastic/Public IPs)
* New images: OpenBSD 7.2, VyOS 1.3.2

### Improvements and Fixes

* Wizard improvements & other small UI bugfixes
* General platform-related improvements and fixes

## v4.13.0

<figure><img src="/files/2W27DvgeyoWlDaWIIQsb" alt=""><figcaption></figcaption></figure>

Release date: January 06, 2023

### New Features

#### VPN & Peering as a Service

The two often-requested services are finally ready for production. Establish a [Site-to-Site VPN](/products/compute/networking/vpn-and-peering#vpn-site-to-site) connection between a private network and your on-premise or other public cloud network with the VPN service. Connect two cross-regional or two regional private networks with just a few clicks with the [Peering](/products/compute/networking/vpn-and-peering#peering) service.

#### User Dashboard

The new user dashboard in the control panel stands out for its beautiful aesthetics and elegance. Besides many useful links like our Quickstart guides, Developer Center, and other widgets, the animated upper area with the overview of all our products stands out.

#### Mac Bare Metal

The first beta version of the Mac device "Reset" feature is available to selected customers. The reset function, which resets macOS to the current version, can be executed with one click via the control panel or with an API call.

### Improvements and Fixes

* Small UI bugfixes
* General platform-related improvements and fixes

## v4.12.0

<figure><img src="/files/tq1KKVELcEfvsY1OHtjB" alt=""><figcaption></figcaption></figure>

Release date: October 19, 2022

### New Features

#### CLI 2.0

With the [latest version](https://github.com/flowswiss/cli) of our CLI (command-line interface), all products are now fully integrated. In addition to Compute, Networking, and Load Balancers, as of now, Kubernetes, Mac Bare Metal, and Object Storage can also be managed via the CLI.

#### Terraform Provider

Introducing the [Flow Terraform Provider](https://github.com/flowswiss/terraform-provider-flow). Terraform is an Infrastructure-as-Code tool that lets you provision, and version cloud resources safely and efficiently. It enables automated and repeatable provisioning of Flow cloud resources.

#### Support Plans

With this release, the ability to easily request an update of the current [Support Plan](/platform/pricing/support) via UI has been implemented.

#### Kubernetes

* New Kubernetes version (v1.25.2)
* Change default behavior in CPU Softlockup / Hardlockup handling

### Improvements and Fixes

* Small UI bugfixes
* General platform-related improvements and fixes

## v4.11.0

Release date: August 18, 2022

### New Features

#### Object Storage

* Account Management
* Bucket Management
* Instance Management

#### Compute

* New images: Windows Server 2022, FreeBSD 13

### Improvements and Fixes

* Small UI bugfixes
* General platform-related improvements and fixes

## v4.10.1

![](/files/96Aiog4tK58fdIvuukGI)

Release date: June 22, 2022

### New Features

#### General

* New, simplified Platform Status widget

#### Kubernetes

* Auto-renewal of k3s certificates with user notifications
* New Kubernetes version (v1.24.1)
* Online volume resize
* CSI volume metrics
* Expandable Volumes and Snapshot list with the force delete action
* Search and filter options for Persistent Volumes and Load Balancers
* Increased 'max file' handlers in FlatcarOS

#### Compute

* Online Volume resize
* New images: Ubuntu 22.04, Alma Linux, Rocky Linux

### Improvements and Fixes

* Portal speed optimizations
* Small UI bugfixes
* General platform-related improvements and fixes

## v4.9.0

![](/files/03hejXZgAVAlDIr3syJq)

Release date: March 31, 2022

### New Features

#### Kubernetes

* New Kubernetes version (v1.23.3)
* One-click cluster upgrade (improved)
* Kubernetes management features (improved)

#### Compute

* New images: Flatcar 3033

### Improvements and Fixes

* Portal speed and security optimizations
* Updated Kubernetes naming convention (Control Plane & Worker)
* Core improvement of the Kubernetes service
* Core improvement of the Security Groups functionality
* Improved usability of the 3DSecure form
* General platform related improvements and fixes

## v4.8.1

![](/files/HuXHfKzawmn4YJXAH3Nx)

Release date: December 16, 2021

### New Features

* [App Engine](https://flow.swiss/app-engine) integration (native integration of the Jelastic PaaS solution)
* New images: VzLinux 8, Alma Linux 8, Fedora 34, Fedora Core 34, Debian 11

### Improvements and Fixes

* Core improvement of the snapshot functionality
* Improved usability of the 2FA-code form
* General platform related improvements and fixes

## v4.7.1

![](/files/-MivZlpVnW6uzVpK_FwB)

Release date: September 6, 2021

### New Features

* Cashback (The more you recharge, the more bonus you receive)
* Billing Dashboard
* Usage Dashboard

### Improvements and Fixes

* The billing-engine has been modernized to support the growth of the platform
* General platform related improvements and fixes

## v4.6.0

![](/files/-MbFrH2ieBiAVGJxT69c)

Release date: June 04, 2021

### New Features

#### Mac Bare Metal

* Support and availability for new Apple M1 Mac minis
* Support for FileVault full-disk encryption with M1 Mac minis

#### Kubernetes

* One-click cluster upgrade support to newer versions
* Native support for platform Load Balancers (via CCM)
* Custom cluster configuration (disable traefik, change log file amount and size)
* Updated CCM and CSI for Helm charts support

### Improvements and Fixes

* General platform related improvements
* Improved Mac Bare Metal actions and workflows to support new M1 devices
* Improved Mac Bare Metal Power-Management UI
* Improved Kubernetes cluster creation and deployment of CCM and CSI
* Increased volume size for Kubernetes config drives
* Improved Load Balancer status management
* Upgraded CSI sidecar containers with a memory leak fix
* Fixed issue with PATCH security group rule for Mac Bare Metal
* Fixed issue with crashing sync and status update for Kubernetes
* Fixed issue with mount propagation of root volume mount in Kubernetes
* Fixed issue with Drain-Node actions if k3s is unavailable


# Pricing

{% content-ref url="/pages/fDFqTbrb985YMS8weWi9" %}
[Compute](/platform/pricing/compute)
{% endcontent-ref %}

{% content-ref url="/pages/iuVCSLSDk92KkldkDwi7" %}
[Kubernetes](/platform/pricing/kubernetes)
{% endcontent-ref %}

{% content-ref url="/pages/h92uzqbHH7rYV1Zvc1FW" %}
[App Engine](/platform/pricing/app-engine)
{% endcontent-ref %}

{% content-ref url="/pages/YKrRczB4Jswsku14WflO" %}
[Object Storage](/platform/pricing/object-storage)
{% endcontent-ref %}

{% content-ref url="/pages/fqx0idhxchJa31LZpGbo" %}
[Mac Bare Metal](/platform/pricing/mac-bare-metal)
{% endcontent-ref %}

{% content-ref url="/pages/tt6Lr0Azzb202sGFgHIh" %}
[DevOps Services](/platform/pricing/devops-services)
{% endcontent-ref %}

### Add-ons

{% content-ref url="/pages/vD15Y8OIzhKrcFWf1XJm" %}
[Volumes & Snapshots](/platform/pricing/volumes-and-snapshots)
{% endcontent-ref %}

{% content-ref url="/pages/WnjhraqANX2VaBAmrMp3" %}
[Load Balancers](/platform/pricing/load-balancers)
{% endcontent-ref %}

{% content-ref url="/pages/hQtewpICc9sb7qux3DLr" %}
[Elastic IPs](/platform/pricing/elastic-ips)
{% endcontent-ref %}

{% content-ref url="/pages/dXVPxMYFRmk63tVhF8tr" %}
[VPN & Peering](/platform/pricing/vpn-and-peering)
{% endcontent-ref %}

{% content-ref url="/pages/qzADsly3CKjc4JU4R2J2" %}
[Licenses](/platform/pricing/licenses)
{% endcontent-ref %}

{% content-ref url="/pages/Lg37DCFUoE1WBKC8QJXK" %}
[Support](/platform/pricing/support)
{% endcontent-ref %}


# Compute

### How Compute pricing works

Compute pricing is based on the underlying required and optional Compute-related resources.

{% hint style="info" %}
Starting at CHF 0.04/hr or CHF 29/mo
{% endhint %}

{% hint style="warning" %}
Billing also occurs when the VM instance is in a stopped state.
{% endhint %}

### Required resources

{% tabs %}
{% tab title="Balanced VM flavors" %}
Virtual machine flavors with a healthy balance of vCPU, RAM and Storage.

<table><thead><tr><th width="150">Flavor</th><th width="150">vCPUs</th><th width="150">RAM</th><th width="150">Storage</th><th width="150">Hourly price°</th><th>Monthly price°¹</th></tr></thead><tbody><tr><td>b1.1x1</td><td>1</td><td>1 GB</td><td>10 GB</td><td>CHF 0.0400</td><td>CHF 29</td></tr><tr><td>b1.1x2</td><td>1</td><td>2 GB</td><td>25 GB</td><td>CHF 0.0541</td><td>CHF 39</td></tr><tr><td>b1.2x2</td><td>2</td><td>2 GB</td><td>50 GB</td><td>CHF 0.0890</td><td>CHF 65</td></tr><tr><td>b1.2x4</td><td>2</td><td>4 GB</td><td>100 GB</td><td>CHF 0.1232</td><td>CHF 90</td></tr><tr><td>b1.2x8</td><td>2</td><td>8 GB</td><td>150 GB</td><td>CHF 0.1766</td><td>CHF 129</td></tr><tr><td>b1.4x8</td><td>4</td><td>8 GB</td><td>200 GB</td><td>CHF 0.2464</td><td>CHF 180</td></tr><tr><td>b1.4x16</td><td>4</td><td>16 GB</td><td>300 GB</td><td>CHF 0.3532</td><td>CHF 256</td></tr><tr><td>b1.4x32</td><td>4</td><td>32 GB</td><td>400 GB</td><td>CHF 0.5368</td><td>CHF 392</td></tr><tr><td>b1.8x32</td><td>8</td><td>32 GB</td><td>500 GB</td><td>CHF 0.6764</td><td>CHF 494</td></tr><tr><td>b1.8x64</td><td>8</td><td>64 GB</td><td>600 GB</td><td>CHF 1.0136</td><td>CHF 740</td></tr><tr><td>b1.8x96</td><td>8</td><td>96 GB</td><td>800 GB</td><td>CHF 1.3808</td><td>CHF 1'008</td></tr><tr><td>b1.16x96</td><td>16</td><td>96 GB</td><td>1000 GB</td><td>CHF 1.6600</td><td>CHF 1'212</td></tr><tr><td>b1.16x128</td><td>16</td><td>128 GB</td><td>1500 GB</td><td>CHF 2.1172</td><td>CHF 1'546</td></tr><tr><td>b1.24x128</td><td>24</td><td>128 GB</td><td>2000 GB</td><td>CHF 2.4864</td><td>CHF 1'815</td></tr><tr><td>b1.24x256</td><td>24</td><td>256 GB</td><td>2500 GB</td><td>CHF 3.8652</td><td>CHF 2'822</td></tr><tr><td>b1.32x256</td><td>32</td><td>256 GB</td><td>3000 GB</td><td>CHF 4.2344</td><td>CHF 3'091</td></tr><tr><td>b1.32x512</td><td>32</td><td>512 GB</td><td>4000 GB</td><td>CHF 6.9920</td><td>CHF 5'104</td></tr></tbody></table>
{% endtab %}
{% endtabs %}

### Optional resources

{% content-ref url="/pages/vD15Y8OIzhKrcFWf1XJm" %}
[Volumes & Snapshots](/platform/pricing/volumes-and-snapshots)
{% endcontent-ref %}

{% content-ref url="/pages/WnjhraqANX2VaBAmrMp3" %}
[Load Balancers](/platform/pricing/load-balancers)
{% endcontent-ref %}

{% content-ref url="/pages/hQtewpICc9sb7qux3DLr" %}
[Elastic IPs](/platform/pricing/elastic-ips)
{% endcontent-ref %}

{% content-ref url="/pages/dXVPxMYFRmk63tVhF8tr" %}
[VPN & Peering](/platform/pricing/vpn-and-peering)
{% endcontent-ref %}

{% content-ref url="/pages/qzADsly3CKjc4JU4R2J2" %}
[Licenses](/platform/pricing/licenses)
{% endcontent-ref %}

### Included

{% hint style="success" %}
**Elastic IP Address.** Each VM comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Economy Support** **Plan** according to the best-effort principle. Business and First support plans are available at an additional cost.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Kubernetes

### How Kubernetes pricing works

Kubernetes cluster pricing is based on the underlying required and optional Kubernetes-related resources.

{% hint style="info" %}
Starting at CHF 0.2578/hr or CHF 190/mo
{% endhint %}

{% hint style="warning" %}
Billing also occurs when the Kubernetes cluster is in a stopped state.
{% endhint %}

### Required resources

{% tabs %}
{% tab title="Worker nodes" %}
A cluster requires at least three (3) of the following worker node flavors to operate.

<table><thead><tr><th width="150">Flavor²</th><th width="150">vCPUs</th><th width="150">RAM</th><th>Hourly price°</th><th>Monthly price°¹</th></tr></thead><tbody><tr><td>k1.1x2</td><td>1</td><td>2 GB</td><td>CHF 0.0526</td><td>CHF 39</td></tr><tr><td>k1.2x2</td><td>2</td><td>2 GB</td><td>CHF 0.0800</td><td>CHF 59</td></tr><tr><td>k1.2x4</td><td>2</td><td>4 GB</td><td>CHF 0.0992</td><td>CHF 73</td></tr><tr><td>k1.2x8</td><td>2</td><td>8 GB</td><td>CHF 0.1376</td><td>CHF 101</td></tr><tr><td>k1.4x8</td><td>4</td><td>8 GB</td><td>CHF 0.1924</td><td>CHF 141</td></tr><tr><td>k1.4x16</td><td>4</td><td>16 GB</td><td>CHF 0.2692</td><td>CHF 197</td></tr><tr><td>k1.4x32</td><td>4</td><td>32 GB</td><td>CHF 0.4228</td><td>CHF 309</td></tr><tr><td>k1.8x32</td><td>8</td><td>32 GB</td><td>CHF 0.5324</td><td>CHF 389</td></tr><tr><td>k1.8x64</td><td>8</td><td>64 GB</td><td>CHF 0.8396</td><td>CHF 613</td></tr><tr><td>k1.8x96</td><td>8</td><td>96 GB</td><td>CHF 1.1468</td><td>CHF 838</td></tr><tr><td>k1.16x96</td><td>16</td><td>96 GB</td><td>CHF 1.3660</td><td>CHF 998</td></tr></tbody></table>
{% endtab %}

{% tab title="Control plane" %}
The following fee for the control plane (master node) per cluster applies irrespective of the cluster size.

| Flavor²       | vCPUs | RAM  | Hourly price° | Monthly price°¹ |
| ------------- | ----- | ---- | ------------- | --------------- |
| k1.2x4        | 2     | 4 GB | CHF 0.0992    | CHF 73          |
| {% endtab %}  |       |      |               |                 |
| {% endtabs %} |       |      |               |                 |

### Optional resources

<details>

<summary>Volumes &#x26; Snapshots</summary>

Persistent Volumes (PV) are optional and can be dynamically provisioned from the Kubernetes context. They are scalable and support online expansion without downtime.

[See pricing](/platform/pricing/volumes-and-snapshots)

</details>

<details>

<summary>Load Balancers</summary>

External Load Balancers are optional and can easiely be added in front of the Kubernetes cluster(s).

[See pricing](/platform/pricing/load-balancers)

</details>

### Included

{% hint style="success" %}
**Elastic IP Address.** Each Kubernetes node comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Economy Support** **Plan** according to the best-effort principle. Business and First support plans are available at an additional cost.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.\
² All Kubernetes flavors are deployed with a 60 GB root volume by default.


# App Engine

### How App Engine pricing works

With App Engine you pay only for your resource consumption. The resources are provisioned with granular units called "Cloudlets". This allows to allocate exactly the needed amount of resources.

{% hint style="info" %}
1 Cloudlet = 128MiB of RAM and 400MHz of CPU
{% endhint %}

### RAM & CPU

You have a choice between a dynamic, cost-efficient model (usage-based) and a traditional model with fix pricing (reserved).

{% tabs %}
{% tab title="Dynamic cloudlets" %}
With this model, the price is variable as you pay only for what you really use. For instance, during the day there is high load of your application (you pay more) and at night there is low load (you pay less).

<table><thead><tr><th width="171">Number of cloudlets</th><th width="184.61719833564493" align="right">Hourly price°</th><th width="203" align="right">Monthly price°¹</th><th>Discount</th></tr></thead><tbody><tr><td>01 - 09</td><td align="right">CHF 0.012</td><td align="right">CHF 8.76</td><td>0%</td></tr><tr><td>10 - 24</td><td align="right">CHF 0.0114</td><td align="right">CHF 8.32</td><td>5%</td></tr><tr><td>25 - 49</td><td align="right">CHF 0.0108</td><td align="right">CHF 7.88</td><td>10%</td></tr><tr><td>50 and more</td><td align="right">CHF 0.0102</td><td align="right">CHF 7.44</td><td>15%</td></tr></tbody></table>

The discount level is the total sum of all dynamic cloudlets in use per environment.
{% endtab %}

{% tab title="Reserved cloudlets" %}
With this model, you pay a fixed price. You always pay for the configured (reserved) number of Cloudlets, even if you use fewer resources.

&#x20;

<table><thead><tr><th width="171">Number of cloudlets</th><th width="184.61719833564493" align="right">Hourly price°</th><th width="202" align="right">Monthly price°¹</th><th>Discount</th></tr></thead><tbody><tr><td>01 - 24</td><td align="right">CHF 0.0096</td><td align="right">CHF 7.00</td><td>20%</td></tr><tr><td>25 - 49</td><td align="right">CHF 0.0084</td><td align="right">CHF 6.13</td><td>30%</td></tr><tr><td>50 - 149</td><td align="right">CHF 0.0072</td><td align="right">CHF 5.25</td><td>40%</td></tr><tr><td>150 and more</td><td align="right">CHF 0.006</td><td align="right">CHF 4.38</td><td>50%</td></tr></tbody></table>

The discount level is the total sum of all reserved cloudlets per environment.
{% endtab %}
{% endtabs %}

### Disk

Disk space is charged hourly per GB of disk space used in your environment.

| Disk used | Hourly price° | Monthly price°¹ |
| --------- | ------------: | --------------: |
| 1 GB      |   CHF 0.00035 |        CHF 0.26 |

### Public IPv4

This is about an external, public IPv4 address which is directly accessible from outside of the cluster. Charges accrue hourly for as long as the public IP exists.

| Item          | Hourly price° | Monthly price°¹ |
| ------------- | ------------: | --------------: |
| 1 public IPv4 |      CHF 0.01 |        CHF 7.30 |

### Included

{% hint style="success" %}
**1 TB External Traffic.** Per environment 1 TB of external traffic per month is included. Traffic above the included quota, costs CHF 0.06 per GB per month. Internal traffic is always free.
{% endhint %}

###

### How App Engine billing works

Since App Engine is a third-party solution (Virtuozzo Application Platform) that itself has its own billing engine, the integration in the my.flow\.swiss portal is solved in such a way that the credit from my.flow\.swiss portal is the master and App Engine automatically obtains the credit from there in the background. You can therefore simply **ignore** the negative balance under App Engine dashboard. As long as the balance under my.flow\.swiss portal is positive, nothing can be automatically deactivated or stopped.&#x20;

### How to discover the price

You probably ask yourself: how much does it cost me exactly per month? Well, this is always different as it depends on your application load. Therefore, we recommend anybody:

1. [Start with a free trial](https://my.flow.swiss/#/register)
2. Deploy your application(s)
3. Discover your price

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Object Storage

### How Object Storage pricing works

The price for Object Storage consists of a standard package of 250 GB with a fixed price. Any additional storage beyond this is charged per GB and hour.

{% hint style="info" %}
Starting at CHF 0.0138/hr or CHF 10/mo
{% endhint %}

### Standard Package

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------- | --------------- |
| 250 GB  | CHF 0.0138    | CHF 10          |

### Additional Storage

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------- | --------------- |
| 1 GB    | CHF 0.00005   | CHF 0.04        |

### Included

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Economy Support** **Plan** according to the best-effort principle. Business and First support plans are available at an additional cost.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Mac Bare Metal

Mac as a Service Pricing

### How Mac Bare Metal pricing works

Mac mini and Mac Studio devices are available on-demand with instant activation. Billing is per hour with a 24-hour minimum allocation period to comply with the Apple macOS License Agreement. Billing also takes place when the device is switched off.

{% hint style="info" %}
Starting at CHF 0.27/hr or CHF 199/mo
{% endhint %}

### Pricing plans

#### Intel (Mac minis)

<table><thead><tr><th width="246">Flavor</th><th width="87">Cores</th><th width="86">RAM</th><th width="111">Storage (SSD)</th><th width="97">Hourly price°</th><th>Monthly price°¹</th></tr></thead><tbody><tr><td>macmini.2018.6-16-256</td><td>6</td><td>16 GB</td><td>256 GB</td><td>0.27</td><td>199</td></tr><tr><td>macmini.2018.6-32-512</td><td>6</td><td>32 GB</td><td>512 GB</td><td>0.55</td><td>399</td></tr><tr><td>macmini.2018.6-64-1024</td><td>6</td><td>64 GB</td><td>1024 GB</td><td>0.68</td><td>499</td></tr></tbody></table>

#### Apple Silicon (Mac minis and Mac Studio)

<table><thead><tr><th width="259">Flavor</th><th width="79">Cores</th><th width="82">RAM</th><th width="103">Storage (SSD)</th><th width="104">Hourly price°</th><th>Monthly price°¹</th></tr></thead><tbody><tr><td>macmini.m1.8-16-512</td><td>8</td><td>16 GB</td><td>512 GB</td><td>0.27</td><td>199</td></tr><tr><td>macmini.m2.8-24-512</td><td>8</td><td>24 GB</td><td>512 GB</td><td>0.34</td><td>249</td></tr><tr><td>macmini.m2-pro.12-32-4096</td><td>12</td><td>32 GB</td><td>4096 GB</td><td>0.62</td><td>449</td></tr><tr><td>macmini.m4-pro.12-48-2048</td><td>12</td><td>48 GB</td><td>2048 GB</td><td>0.75</td><td>549</td></tr><tr><td>macmini.m4-pro.14-48-2048</td><td>14</td><td>48 GB</td><td>2048 GB</td><td>0.82</td><td>599</td></tr><tr><td>studio.m4-max.16-128-2048</td><td>16</td><td>128 GB</td><td>2048 GB</td><td>1.34</td><td>979</td></tr></tbody></table>

### Optional resources

{% content-ref url="/pages/hQtewpICc9sb7qux3DLr" %}
[Elastic IPs](/platform/pricing/elastic-ips)
{% endcontent-ref %}

### Included

{% hint style="success" %}
**Elastic IP Address.** Each Mac device comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

{% hint style="success" %}
**Economy Support** **Plan** according to the best-effort principle. Business and First support plans are available at an additional cost.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# CI Engine

### Plans Table

|                                                   | Essential                                   | Professional                                                     |
| ------------------------------------------------- | ------------------------------------------- | ---------------------------------------------------------------- |
| Flavor                                            | gen1-3c.8g\*                                | gen1-6c.16g\*                                                    |
| Specs                                             | 3-Cores CPU, 8GB RAM                        | 6-Cores CPU, 16GB RAM                                            |
| <p>Starting at<br>(includes 1 concurrent job)</p> | <p><br><strong>CHF 149 /mo</strong><br></p> | <p><br><strong>CHF 899 /mo</strong><br></p>                      |
| <p>Each additional<br>concurrent job</p>          | CHF 130 /mo                                 | CHF 350 CHF /mo                                                  |
| Number of jobs                                    | Unlimited                                   | Unlimited                                                        |
| Global Images                                     | 3 Included                                  | Yes                                                              |
| Active Custom Images                              | ---                                         | <p>1 included<br>(Each additional custom image: CHF 100 /mo)</p> |
| Inactive Custom Images                            | ---                                         | <p>3 included<br>(Each additional custom image: CHF 10 /mo</p>   |

*\*gen1 is powered by the Apple Mac mini with a **M4 Pro** chip*&#x20;


# DevOps Services

### Subscriptions

|                             | 8x5 Subscription\*¹ °  | 24x7 Subscription\*¹ ° |
| --------------------------- | ---------------------- | ---------------------- |
| <p></p><p>Control Plane</p> | 640 CHF /mo            | 840 CHF /mo            |
| Worker Node (min. 3)        | 420 CHF /mo (per node) | 520 CHF /mo (per node) |

{% tabs %}
{% tab title="Included (DevOps Cluster Subscription)" %}
Incident Management:

* Identify Cause
* Service / Node Incident Handling
* Pod / Container Incident Handling

Monitoring:

* Cluster Monitoring
* Node Monitoring
* Argo CD Monitoring
* Backup Monitoring

Upgrade Service:

* Kubernetes Upgrade (2x per year)
* Backup Solution Upgrades
* Argo CD Upgrades&#x20;
  {% endtab %}

{% tab title="Excluded (DevOps Consulting) " %}

* General Consulting
* Problem Management
* General planned changes
* Root Cause analysis
* Performance analysis
* Service / Node Changes
* Node / Pod Resize
* PVC Volume Resize
* Restore Management
  {% endtab %}
  {% endtabs %}

### Consulting & Add-ons

<table><thead><tr><th>Item</th><th width="283">Description</th><th>Price</th></tr></thead><tbody><tr><td>DevOps Consulting - 30h Package</td><td>Redeemable within 4 months, Smallest billable unit: 30 minutes (half hour)</td><td>7'200 CHF</td></tr><tr><td>DevOps Consulting - <br>1h Package</td><td>Smallest billable unit: 30 minutes (half hour)</td><td>250 CHF</td></tr><tr><td>Application Monitoring</td><td>Monitoring of customer applications and services</td><td>on request</td></tr><tr><td>Security Monitoring</td><td>Vulnerability Scanning &#x26; Reporting</td><td>on request</td></tr></tbody></table>

### Initial Response Time Objectives

Initial response time means the maximum time to get back to the customer. Initial response time objectives do not apply to any billing, invoice, or sales-related inquiry or cases.

<table><thead><tr><th width="150">Priority</th><th>Business Hours°</th><th>Non-Business Hours°¹</th></tr></thead><tbody><tr><td>Critical</td><td>Within 2 hours</td><td>Within 4 hours</td></tr><tr><td>Normal</td><td>Within 4 hours</td><td>Within 12 hours</td></tr><tr><td>Low</td><td>Within 12 hours</td><td>Within 24 hours</td></tr></tbody></table>

° Business Hours\
Monday till Friday, 08:00 - 18:00 CET/CEST (excl. Saturday, Sunday, and common holidays)\
\
°¹ Non-Business Hours\
Monday till Friday, 18:00 - 08:00 CET/CEST (incl. Saturday, Sunday, and common holidays)<br>

\*¹ Minimum contract term: 12 months


# Volumes & Snapshots

### How Volumes pricing works

The price for Volumes is calculated on the basis of the smallest unit of 1 GB. When creating volumes, the smallest unit is always 10 GB. After that, you can always expand volumes with the smallest unit of 1 GB. Charges accrue hourly for as long as the Volume exists.

### How Snapshots pricing works

Snapshots are always associated with Volumes. As Snapshots are 1:1 block storage level copies of a Volume, the per GB pricing and the method of calculation are exactly the same. Charges accrue hourly for as long as the Snapshot exists.

### Pricing per GB

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------- | --------------- |
| 1 GB    | CHF 0.0003    | CHF 0.22        |

### Pricing examples

| Storage | Hourly price° | Monthly price°¹ |
| ------- | ------------- | --------------- |
| 10 GB   | CHF 0.0030    | CHF 2           |
| 50 GB   | CHF 0.0150    | CHF 11          |
| 100 GB  | CHF 0.0300    | CHF 22          |
| 200 GB  | CHF 0.0600    | CHF 44          |
| 250 GB  | CHF 0.0750    | CHF 55          |
| 500 GB  | CHF 0.1500    | CHF 110         |
| 1000 GB | CHF 0.3000    | CHF 220         |

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Load Balancers

### How Load Balancers pricing works

The Load Balancer service is charged per load balancing service unit. You can run more than one Load Balancer. Charges accrue hourly for as long as the Load Balancer exists.

### Pricing

| Plan     | Hourly price° | Monthly price°¹ |
| -------- | ------------- | --------------- |
| Standard | CHF 0.0068    | CHF 5           |

### Included

{% hint style="success" %}
**Elastic IP Address.** Each Load Balancer comes with a free elastic public IPv4 address.
{% endhint %}

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Elastic IPs

### How Elastic IPs pricing works

It is important to note that each Compute instance, Load Balancer unit, or Kubernetes node comes with a free, public Elastic IPv4 address. Any additional Elastic IP not attached to an instance will be charged accordingly. Charges accrue hourly for as long as the Elastic IP exists.

### Pricing per Elastic IP

| Item          | Hourly price° | Monthly price°¹ |
| ------------- | ------------- | --------------- |
| 1 public IPv4 | CHF 0.01      | CHF 7.30        |

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# VPN & Peering

### How VPN pricing works

The VPN service is charged per Site-to-Site VPN connection. You can run more than one Site-to-Site VPN connection. Charges accrue hourly for as long as the VPN connection exists.

### How Peering pricing works

The Peering service is charged per peering connection (interconnection of two private networks). You can run more than one peering connection. Charges accrue hourly for as long as the VPN connection exists.

### Pricing

| Connection type | Hourly price° | Monthly price°¹ |
| --------------- | ------------- | --------------- |
| VPN             | CHF 0.05      | CHF 40          |
| Peering         | CHF 0.11      | CHF 80          |

### Included

{% hint style="success" %}
**20 TB Outbound Traffic.** Per organization-account 20 TB of outbound traffic per month is included. Inbound and internal traffic is always free.
{% endhint %}

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Licenses

### How License pricing works

Licenses for paid operating systems or third-party software are usually tied to a product. The best example is a Windows-based Compute instance. Charges accrue hourly.

### Pricing

<table><thead><tr><th width="256.88422971741113">Item</th><th>Hourly price°</th><th>Monthly price°¹</th></tr></thead><tbody><tr><td>Microsoft Windows Server (Standard Edition)</td><td>CHF 0.0137</td><td>CHF 10</td></tr></tbody></table>

° Prices are in CHF (Swiss franc) and don't include VAT. 1 CHF is usually [equal](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) to 1 USD.\
¹ Monthly price estimates are based on 730 hours of usage.


# Support

Economy, Business and First Support Plans

### Overview

You can choose an Economy, Business, or First support plan to customize your Flow Cloud support experience for your business needs. The level of support that you select determines the severity that you can assign to support cases and the communication channel.

<table><thead><tr><th width="181.04162394914908"> </th><th width="169.2626977935501">Economy Support</th><th width="195.7142857142857">Business Support</th><th>First Support</th></tr></thead><tbody><tr><td>Description</td><td>Included and good enough for non-critical environments in which traditional severities and response times aren't needed</td><td>Business Support is for environments with business-critical environments</td><td>First Support is designed for clients that operate business-critical 24×7 environments, which require highest priority of cases handling and a dedicated Technical Account Manager</td></tr><tr><td>Availability</td><td>24x7</td><td>24x7</td><td>24x7</td></tr><tr><td>Channel</td><td>Ticketing System<br>-</td><td>Ticketing System<br>-</td><td>Ticketing System<br>Phone</td></tr><tr><td><a href="/pages/G3ZzS485PdZzkOJTddF8#severity-level-definition">Case severity</a></td><td>Not applicable</td><td>Critical, Normal, Low</td><td>Critical, Normal, Low</td></tr><tr><td>Initial response time objectives</td><td>Best effort<br><a href="/pages/G3ZzS485PdZzkOJTddF8#basic-support-plan">Details</a></td><td><p>Starting at &#x3C; 2h</p><p><a href="/pages/G3ZzS485PdZzkOJTddF8#advanced-support-plan">Details</a></p></td><td><p>Starting at &#x3C; 30min</p><p><a href="/pages/G3ZzS485PdZzkOJTddF8#premium-support-plan">Details</a></p></td></tr><tr><td>Pricing</td><td><p><strong>Free of charge</strong></p><p>Included with cloud entitlement</p></td><td><strong>Starting at 500 CHF</strong> per month and based on consumption</td><td><strong>Starting at 5'000 CHF</strong> per month and based on consumption</td></tr></tbody></table>

{% hint style="info" %}
If you want to upgrade your support plan, please [contact our sales](https://flow.swiss/contact/#sales) team.
{% endhint %}


# Billing FAQ

## What's your billing model?

It's a consumption-based billing model. Essentially, it’s a lot like a prepaid mobile phone plan, where payment is made in advance (prepaid principle). You prepay for credits, which are then balanced against the consumption of services. This results in no minimum contract terms or any other liabilities.

## How am I billed?

Billing for **Compute, Kubernetes, App Engine, Object Storage**, and other related services is based on an hourly basis. Our automatic system gathers usage data every hour after which we deduct the usage from your account balance. Monthly prices are displayed for easier comparisons and they are approximations assuming a 30 day month.

Billing for **Mac Bare Metal** devices is based on a daily basis respectively 24 hours. Our automatic system gathers usage data every 24 hours after which we deduct the usage from your account balance. Monthly prices are displayed for easier comparisons and they are approximations assuming a 30 day month.

## Do you charge for stopped virtual machine instances?

Yes. Instances in a stopped state continue to reserve dedicated system resources (CPU, RAM, Storage, IP) and therefore incur charges until you destroy the instance. If you wish to no longer accumulate charges for a virtual machine, please use the delete button in the control panel.

## Do you charge for stopped Mac Bare Metal devices?

Yes. A device in a stopped state continues to reserve the dedicated Mac device and therefore incur charges until you destroy/delete it. If you wish to no longer accumulate charges for a device, please use the delete button in the control panel.

## What payment methods do you accept?

Currently, we accept MasterCard, Visa, and American Express. If you are an Enterprise and Bank Transfer (PO approach) is your only method, please contact us. Bitcoin as a payment method will be supported soon.

## What currency do you charge in?

As a Swiss company, Flow only charges in Swiss franc (CHF). 1 CHF is usually equal to 1 USD. [Here](https://www.google.com/search?q=1+CHF+in+USD\&cad=h) you can check the current and historical exchange rates.

## What is the minimum amount for adding credit to my account?

There’s a minimum amount of 10 CHF you can add. That's about 10 USD.

## What is Auto-recharge and how does it work?

If enabled, Auto-recharge automatically adds credit to your account's balance when it falls below a certain amount. If disabled, the customer is responsible for manually recharging the credit.

## Can I test the service before paying for it?

Yes. We offer all customers 20 CHF worth of free credits that you can use to try the service before making any payments. Certain functionalities are however restricted before the first payment to prevent abusive behaviour.

## Can I get a refund if I don't use the service?

We do not issue refunds for unused services or credits.


# Account


# Sign Up

If you haven't already signed up for an account, this is the place to begin.

## Registration

1. [Sign up](https://my.flow.swiss/#/register) for a free trial account and receive a preloaded balance to test out the functionality.
2. Start working right away by provisioning your cloud environment.
3. If you like the Flow Cloud Platform, you have the option to upgrade your account to a full paid account.

{% hint style="info" %}
Please note that we block all disposable email domains, including free providers like google, yahoo, etc.
{% endhint %}

## Verification

As an additional safeguard of the registration process, we also perform an SMS verification. For this a working mobile number is required.&#x20;


# Closing account

## How can I close my organizations account?

**Option 1 (allow an account to expire)**

It is not necessary to request the closing of the account, as it is **automatically** closed depending on the balance status. To make sure that no additional costs are incurred, it is important to **delete all objects** first (such as VM instances, Mac devices, Elastic IP's, etc). The advantage of this option is that you can reuse any existing (positive) balance at a later date. After several months of general inactivity on the platform, the account is automatically closed.&#x20;

**Option 2 (immediate closing)**

If for some reason you wish to have your account deleted immediately, please contact our support. First of all you have to make sure that all your objects have already been deleted. The remaining balance will also be cleared and cannot be requested again in the future.


# Cashback Program

The more you recharge, the more free credits you receive.

### How it works

Our billing is a true consumption-based model. It works like a prepaid mobile phone plan where payment is made in advance (prepaid principle). You prepay in advance for credits, which are then charged against the consumption of individual services on our platform. This flexible billing model allows us to offer a simple and transparent cashback program for all customers. Compared to many other providers who offer saving plans on individual product objects (which is not so flexible), with our approach, you benefit practically on all products and services the more you pay in advance.

### Cashback overview

<table><thead><tr><th width="197">Recharge amount</th><th width="152">Cashback</th><th>Cashback as free credits (Bonus)</th></tr></thead><tbody><tr><td>CHF 50'000+</td><td>10%</td><td>CHF 5'000+</td></tr><tr><td>CHF 20'000+</td><td>7.5%</td><td>CHF 1'500+</td></tr><tr><td>CHF 10'000+</td><td>5%</td><td>CHF 500+</td></tr><tr><td>CHF 5'000+</td><td>3%</td><td>CHF 150+</td></tr><tr><td>CHF 1'000+</td><td>2%</td><td>CHF 20+</td></tr><tr><td>CHF 500+</td><td>1%</td><td>CHF 5+</td></tr></tbody></table>

### Example

Let's assume you are recharging an amount of CHF 12'000. Since this amount is in the range of 5% cashback, your account balance will be credited with a cash amount of CHF 12'000 and additionally the CHF 600 (5%) as a bonus (free credit). Accordingly, the account balance will have a total amount of CHF 12'600.


# Support


# Case severity and initial response times

How quickly your support cases are addressed depends on the assigned severity. You assign the severity of the issue when you open the case. With your agreement, the support team adjusts the assigned severity if an incorrect severity level is selected. For more information about Support plans and pricing, see [Economy, Business, and First](/platform/pricing/support) Support plans.

The following table lists some common examples of support issues, suggested severity levels, and the initial response time objectives. The initial response time objectives are used to describe our goals only and don't represent a performance guarantee.

### Severity Level Definition

<table><thead><tr><th width="150">Severity</th><th width="150">Priority</th><th width="510.2">Details</th></tr></thead><tbody><tr><td>1</td><td>Critical</td><td>Represents a business-critical incident or scenarios like a complete loss of service or a significant feature that is completely unavailable, and no workaround exists.</td></tr><tr><td>2</td><td>Normal</td><td>Represents a non-business-critical incident and intermittent issues and reduced quality of service. A workaround may be available.</td></tr><tr><td>3</td><td>Low</td><td>Represents general service-related questions, feature requests, and other requests for information.</td></tr></tbody></table>

### Initial Response Time Objectives

Initial response time means the maximum time for a technical support team member to get back to the customer. Initial response time objectives do not apply to any billing, invoice, or sales-related inquiry or cases.

#### Economy Support Plan

<table><thead><tr><th width="150">Priority</th><th>Business Hours°</th><th>Non-Business Hours°¹</th></tr></thead><tbody><tr><td>Standard<br>(Best effort)</td><td>Usually response time<br>within 12 hours</td><td>Usually response time<br>within 48 hours</td></tr></tbody></table>

#### Business Support Plan

<table><thead><tr><th width="150">Priority</th><th>Business Hours°</th><th>Non-Business Hours°¹</th></tr></thead><tbody><tr><td>Critical</td><td>Within 2 hours</td><td>Within 4 hours</td></tr><tr><td>Normal</td><td>Within 4 hours</td><td>Within 12 hours</td></tr><tr><td>Low</td><td>Within 12 hours</td><td>Within 24 hours</td></tr></tbody></table>

#### First Support Plan

<table><thead><tr><th width="150">Priority</th><th>Business Hours°</th><th>Non-Business Hours°¹</th></tr></thead><tbody><tr><td>Critical</td><td>Within 30 minutes</td><td>Within 1 hour</td></tr><tr><td>Normal</td><td>Within 2 hours</td><td>Within 6 hours</td></tr><tr><td>Low</td><td>Within 6 hours</td><td>Within 12 hours</td></tr></tbody></table>

° Business Hours\
Monday till Friday, 08:00 - 18:00 CET/CEST (excl. Saturday, Sunday, and common holidays)\
\
°¹ Non-Business Hours\
Monday till Friday, 18:00 - 08:00 CET/CEST (incl. Saturday, Sunday, and common holidays)


# Service Level Agreement (SLA)

Flow Swiss AG (hereinafter "Flow") assumes responsibility for the availability and proper functionality of the entire Server-, Network- and Storage Infrastructure (hereinafter "Cloud Platform").

### **Hours of Operation and Availability**

{% tabs %}
{% tab title="Platform Availability" %}
{% hint style="info" %}
**99.9%**\
\
Percentage of time in hours, measured in an interval of a calendar semester (6 months), during the Cloud Platform is available. Interruptions due to announced maintenances, massive DDOS-Attacks and higher force are excluded.
{% endhint %}
{% endtab %}

{% tab title="Hours of operation" %}
{% hint style="info" %}
**24x7**

Time period, during Cloud Platform is operating and reachable via internet.
{% endhint %}
{% endtab %}

{% tab title="Proactive Monitoring" %}
{% hint style="info" %}
**24x7**

Flow practices a proactive 24x7 Monitoring of their Cloud Platform. In the event of a malfunction, which was reported by the Monitoring System, Flow immediately and independently will take measures.
{% endhint %}
{% endtab %}
{% endtabs %}

### Support Level - Cloud Platform

{% tabs %}
{% tab title="Basic Support" %}

| Support Channel  | Availability | Response Time |
| ---------------- | ------------ | ------------- |
| Ticketing System | 24x7         | 12 hours      |
| Phone Line       | n/a          | n/a           |

{% hint style="info" %}
Basic Support is included and good enough for non-critical environments in which traditional severities and response times aren't needed.
{% endhint %}
{% endtab %}

{% tab title="Advanced Support" %}

| Support Channel  | Availability | Response Time |
| ---------------- | ------------ | ------------- |
| Ticketing System | 24x7         | 2 hours       |
| Phone Line       | n/a          | n/a           |

{% hint style="info" %}
Advanced Support is for environments with business-critical environments (starting at 500 CHF /mo).
{% endhint %}
{% endtab %}

{% tab title="Premium Support" %}

| Support Channel  | Availability | Response Time |
| ---------------- | ------------ | ------------- |
| Ticketing System | 24x7         | 30 minutes    |
| Phone Line       | 24x7         | 30 minutes    |

{% hint style="info" %}
Premium Support is designed for clients that operate business-critical 24×7 environments, which require highest priority of cases handling and a dedicated Technical Account Manager (starting at 5'000 CHF /mo).
{% endhint %}
{% endtab %}
{% endtabs %}


# Security & Compliance


# Log4j Vulnerability

Flow is working diligently to protect our customers, products, and partner ecosystem from the impact of the Log4j vulnerabilities. We have evaluated the impact of the issues across all our services and completed an assessment of these vulnerabilities.

Flow teams are monitoring the evolving information around these issues, adapting as conditions change and determining the best possible resolution options for our customers. We are continually monitoring the vulnerability information available for all updates.

#### Security Advisories

* [CVE-2021-45105](https://nvd.nist.gov/vuln/detail/CVE-2021-45105)
* [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)

## Assessment

### Compute

* Compute Instances (including Flow Cloud Servers) are not vulnerable to the Log4j security vulnerability. Our team reviewed its tech stack, found three areas of concern, and issued a patch to close the concern.
* Compute Images / Templates ***does not use*** Log4j. However, we recognize that customers may run vulnerable applications. We encourage you to review the applications you run for potential impact information on this vulnerability.

### Mac Bare Metal

* Mac Bare Metal ***does not use*** Log4j. However, we recognize that customers may run vulnerable applications. We encourage you to review the applications you run for potential impact information on this vulnerability.

### Kubernetes

* Kubernetes ***does not use*** Log4j. Therefore, no additional patches or mitigation activity is required at this time.&#x20;

### App Engine

* App Engine ***does not use*** Log4j. However, we recognize that customers may run vulnerable applications. We encourage you to review the applications you run for potential impact information on this vulnerability.
* As an addition from a certified templates perspective, JavaEngine and WildFly templates contain log4j-api but not log4j-core. According to LOG4J2-3201 customers which only depend on log4j-api are not affected by this vulnerability.

### Object Storage

* Spaces ***does not use*** Log4j. Therefore, no additional patches or mitigation activity is required at this time.

### Volumes / Snapshots

* Volumes ***does not use*** Log4j. Therefore, no additional patches or mitigation activity is required at this time.&#x20;

### Networking

* Networking ***does not use*** a vulnerable version of Log4j. Therefore, no additional patches or mitigation activity is required at this time.&#x20;


# Regions

Flow Cloud Platform currently operates in three state-of-the-art data centers in Switzerland: ZRH1, one of the most modern data centers on Swiss soil, ALP1, located on the edge of the Swiss Alps, and ALP2, the CO2-neutral bunker data centre in the heart of Switzerland.

With ISO/IEC 27001 and PCI DSS certifications and FINMA-RS 18/3 compliance, we operate only in trustworthy and premium data centers.

## Overview

<table data-card-size="large" data-column-title-hidden data-view="cards" data-full-width="false"><thead><tr><th></th><th></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><strong>ALP1</strong></td><td>Central Switzerland</td><td></td><td><a href="/pages/sMAlTb6ojNyFIplGlEOg">/pages/sMAlTb6ojNyFIplGlEOg</a></td><td><a href="/files/Ztbk3lgIMhCwPY8VqYEq">/files/Ztbk3lgIMhCwPY8VqYEq</a></td></tr><tr><td><strong>ALP2</strong></td><td>Central Switzerland</td><td></td><td><a href="/pages/73A0TARmQSmVfEq3MmcT">/pages/73A0TARmQSmVfEq3MmcT</a></td><td><a href="/files/m3h2E4QrNw8xOakmvtAJ">/files/m3h2E4QrNw8xOakmvtAJ</a></td></tr><tr><td><strong>ZRH1</strong></td><td>Northern Switzerland</td><td></td><td><a href="/pages/q4WrzWGX5CcdMeF2gDrw">/pages/q4WrzWGX5CcdMeF2gDrw</a></td><td><a href="/files/oH1A1p3wLh7Fg0ulPuWB">/files/oH1A1p3wLh7Fg0ulPuWB</a></td></tr></tbody></table>


# ALP1

### Facts

| Location                | Lucerne (Central Switzerland)                                                 |
| ----------------------- | ----------------------------------------------------------------------------- |
| DC building type        | Standard                                                                      |
| Operator                | CKW Fiber Services AG                                                         |
| Energy source           | [100% Hydropower](https://flow.swiss/company/insights/news/water-power-flow/) |
| CO2-neutral operation   | -                                                                             |
| ISO/IEC 27001 certified | ✅                                                                             |
| FINMA-RS 18/3 compliant | ✅                                                                             |

### Energy suppliers

The data center obtains its energy from its parent company, CKW AG, and is redundantly connected by two lines to the energy grid.

### Emergency power supply

The data center can be operated self-sufficiently for at least 72 hours (at full capacity, without refueling) using their diesel generators and on-site diesel supplies. This easily bridges possible rolling grid outages. In addition, the operator possess reserved external diesel supplies. The data center can be operated as long as necessary by refilling the tanks.


# ALP2

### Facts

| Location                | Lucerne (Central Switzerland)                                                                                     |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------- |
| DC building type        | Bunker                                                                                                            |
| Operator                | ewl Rechenzentrum AG                                                                                              |
| Energy source           | [100% Hydropower](https://flow.swiss/company/insights/news/now-open-alp2-our-safest-and-greenest-hosting-region/) |
| CO2-neutral operation   | ✅                                                                                                                 |
| ISO/IEC 27001 certified | ✅                                                                                                                 |
| FINMA-RS 18/3 compliant | ✅                                                                                                                 |

### Energy suppliers

The data center obtains its energy from its parent company, EWL Energie Wasser Luzern Holding AG, and is redundantly connected by two lines to the energy grid.

### Emergency power supply

The data center can be operated self-sufficiently for at least 72 hours (at full capacity, without refueling) using their diesel generators and on-site diesel supplies. This easily bridges possible rolling grid outages. In addition, the operator possess reserved external diesel supplies. The data center can be operated as long as necessary by refilling the tanks.


# ZRH1

### Facts​

<table data-header-hidden><thead><tr><th width="279"></th><th></th></tr></thead><tbody><tr><td>Location</td><td>Zurich (Northern Switzerland)</td></tr><tr><td>DC building type</td><td>Standard</td></tr><tr><td>Operator</td><td>NTT Global Data Centers Switzerland AG</td></tr><tr><td>Energy source</td><td>approx. 65% renewable energy (hydropower, solar, wind)<br>approx. 35% nuclear and fossil energies</td></tr><tr><td>CO2-neutral operation</td><td>-</td></tr><tr><td>ISO/IEC 27001 certified</td><td>✅</td></tr><tr><td>FINMA-RS 18/3 compliant</td><td>✅</td></tr></tbody></table>

### Energy suppliers

The data center obtains its energy from the electric utility company of the Canton of Zurich (EKZ) and is redundantly connected via two sub-stations on dedicated lines to the energy grid.

### Emergency power supply

The data center can be operated self-sufficiently for at least 72 hours (at full capacity, without refueling) using their diesel generators and on-site diesel supplies. This easily bridges possible rolling grid outages. In addition, the operator possess reserved external diesel supplies. The data center can be operated as long as necessary by refilling the tanks.


# Compute

## Introduction

Our suite of compute products lets you create the infrastructure you want, whether you want to build applications by managing your own infrastructure with instances, implement modern container-based methodology with Kubernetes.

### Plans and Pricing <a href="#plans-and-pricing" id="plans-and-pricing"></a>

We offer different kinds of products; you can view all available plans on the [pricing page](/platform/pricing/compute).

{% hint style="info" %}
&#x20;You are still billed for Instances / Kubernetes clusters that are powered off because the compute resources for the Instance stay reserved on the hypervisor, even when they are not in use. To end billing, destroy the instance or Kubernetes cluster.
{% endhint %}

### Bandwidth

Each organisation includes free outbound data transfer: 20000 TB/month. Outbound data transfer is shared between all services each billing cycle. Additional transfer is billed at CHF 90 / 1TB, but most users don't exceed the amount included with their services.

### Regions

Flow Cloud Platform is based in two state of the art data centers in Switzerland: ZRH1 (Zurich), the most modern DC on Swiss soil; and ALP1 (Luzern), located at the edge of the Swiss Alps. With ISO/IEC 27001 and PCI DSS certifications and FINMA-RS 18/3 compliance, we operate only in trustworthy and premium data centers. Please find more information on our [Infrastructure & Security](https://flow.swiss/infrastructure-security) page.


# Instances

&#x20;Instances are Linux or Windows-based virtual machines (VMs) that run on top of virtualized hardware in different regions.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Instance**.<br>
2. Name your instance. The hostname is also set from the selected name during the initial creation.<br>
3. Choose a data center [Region](/platform/regions).<br>
4. Choose the image distribution and version of your choice. Several Linux, FreeBSD, Windows, Container, and Firewall image distributions are available.<br>
5. Choose the configuration (flavor) for your instance that determines its vCPUs, RAM, Disk, and price.<br>
6. Confirm the network topology. If you have more than one **Private Network**, you can select the one you want. By default, each instance is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the instance to be reachable only internally, uncheck the **IPv4** checkbox. <br>
7. **Linux-based** distributions:\
   Select an existing SSH key or create a new one by clicking the **(+) Plus** button.\
   The use of "User data" aka cloud-init[^2], is optional and only intended for advanced users.\
   \
   **Windows-based** distributions:\
   Specify a password for the Administrator user account.\
   \
   Click on **Finish**. Deploying an instance takes a few minutes.<br>
8. Once the instance is created, follow the [detailed guide](/products/compute/instances/how-to/connect-to-instances) on how to connect to it.

## Images

We offer a wide variety of different distribution images you can use for your Instances. Besides regular server operating systems, we also offer container and firewall distributions, as listed below.

| Distribution     | Available Versions                                              |
| ---------------- | --------------------------------------------------------------- |
| Ubuntu           | 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS                      |
| Debian           | 10, 11                                                          |
| RHEL Derivatives | Alma Linux 8, 8.5, 9                                            |
|                  | Cent OS 7, 8.1, 8.3                                             |
|                  | Rocky Linux 8.5                                                 |
|                  | VzLinux 8                                                       |
| Windows Server   | 2016 Standard, 2019 Standard, 2019 Core Standard, 2022 Standard |
| Fedora           | 31, 32, 34, 35                                                  |
| FreeBSD          | 12.2, 13.1                                                      |

| Container Distribution | Available Versions     |
| ---------------------- | ---------------------- |
| Fedora Core OS         | 31, 34, 35             |
| RancherOS              | 1.5.5                  |
| Flatcar                | 2512, 2765, 3033, 3227 |

| Firewall Distribution . | Available Versions                       |
| ----------------------- | ---------------------------------------- |
| VyOS (Crux)             | 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.3.1 |
| FortiGate               | 6.2.3, 6.4.0, 7.0.0                      |

## Regional Availability

Instances are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* At the moment, IPv6 is not supported.

[^1]: Publicly-accessible static IP address

[^2]: Cloud-init is an industry-standard instance initialization tool that allows you to inject customized configurations at creation time


# How-to


# Connect to instances

{% tabs %}
{% tab title="Connect to Linux (Container) instances" %}

## Connect to Linux (Container) Instances

During the launch an instance, a default user will be created, and this user will have **no** password set. Instead, your SSH key is copied to the VM and you will be able to login to the machine via SSH using the default username. The default username varies between Operating Systems. Here are the usernames for our official distributions:

| Distribution                 | Username |
| ---------------------------- | -------- |
| Ubuntu Linux                 | ubuntu   |
| Debian Linux                 | debian   |
| CentOS Linux                 | centos   |
| Fedora Linux / Fedora CoreOS | fedora   |
| Rancher Linux                | rancher  |
| Flatcar Linux                | core     |
| VyOS                         | vyos     |
| Fortigate                    | admin    |

To connect by using a terminal on Linux, macOS, or Windows Subsystem for Linux:

1. Open your terminal, and enter the command\
   \
   &#x20;`ssh username@185.xx.xx.xx`

   \
   Substitute in your instance's [Elastic IP](#user-content-fn-1)[^1] address after the `@`. The username is mentioned above in the list for your desired distribution.<br>
2. Press `ENTER` and answer `yes` to the prompt that confirms the connection.<br>
3. When you've logged in, your command prompt changes, and you'll see a welcome screen.

{% hint style="info" %}
Windows users can alternatively connect with [PuTTY](https://www.chiark.greenend.org.uk/~sgtatham/putty/).
{% endhint %}
{% endtab %}

{% tab title="Connect to Windows Instances" %}

## Connect to Windows Instances

To access a Windows Instance, use the RDP protocol and an RDP client for your operating system:

* Windows: [How to use Remote Desktop](https://support.microsoft.com/en-us/help/4028379/windows-10-how-to-use-remote-desktop)
* macOS: [Microsoft Remote Desktop](https://apps.apple.com/us/app/microsoft-remote-desktop-10/id1295203466?mt=12)
* Linux: [FreeRDP](http://www.freerdp.com)

Specify the [Elastic IP](#user-content-fn-1)[^1] address in the client and provide the *default username* **Administrator** and the password specified during the deployment (wizard).
{% endtab %}
{% endtabs %}

##

[^1]: Publicly-accessible static IP address


# Destroy Instances

Deleting an instance permanently and irreversibly destroys the instance and its contents. To destroy a Instance from the [control panel](https://my.flow.swiss/#/compute/instances), click on the Instance's name to access its main page and select **Delete** from the action menu (top in the right corner):

<div align="left"><img src="/files/-M3MjHEsUofxra6oFb-k" alt=""></div>


# Volumes

Volumes are virtual disks based on SSD-only, high availability storage devices to serve as your instances system and storage disks. Besides your instance's primary Volume you can add multiple additional Volumes to provide additional data storage for Instances.&#x20;

Volumes function as generic block devices, so you can treat attached volumes like locally connected storage drives. This lets you partition, format, and manage volumes with familiar tools and techniques.

You can move the Volumes between instances and resize them at any time.

## Snapshots

You can take snapshots of Volumes. Volume snapshots save all the contents from the volume, there are 1:1 block storage level copies of a Volume at the moment of creation.

Snapshots can be used to revert an Instance back to an earlier state or to create a new instance based on the snapshot.

## Plans and Pricing

For pricing details please consult our [pricing page](https://flow.swiss/pricing#compute).

## Regional Availability

Volumes are available in all regions. They are region-specific resources and can only be assigned to Instances within the same region.

## Limits

* To increase an attached volume you have to power-off / shutdown your instance.
* Volumes cannot be assigned to more than one instance at a time.


# Keypairs

Using Keypairs (SSH keys) allows you to secure SSH access to instances (VMs). You can generate a key pair on a client from which you will connect to instances via SSH. The private key will be stored on the client, and the public key will need to be uploaded and specified during instance creation. It will be injected into the instance by cloud-init and used for OpenSSH authentication.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Key Pair.**<br>
2. Name your Keypair.<br>
3. Under **Keypair**, paste your public key in the empty field or upload a file by clicking on "or select file". The Keypair should have the following format:\
   \
   `ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQClkRUh/9D7QmZSPvWqJc1NBqs07t77s8lAwrVzsZMgP/vFZJtXQCRJ2NTxQOoJk7q1QEPqJtidIIz/oau2QkvOWvWB/gorbI2iCDDkK1j9XBsnp+DVmu126lAcGUb/V0U/5J3PCHYE2K4gKNoiQShIQbp/7JTsNCxwLaz2oZ5/brG5X+it6triEhRG/lqh6QiVvGWiQPaJTp6mBSQQF6AAaEMXLXeQkBiVW+UrV6bSC+tV5A5aBMwNP8L90TXl/sBoqlpuDMnIXOPwPt8UFSos/AR7hMl1JueRohuG26PNwwZ2NDCH+Uk3ER4hXZmIWEup99QJA3pmFGhJADIFy/Qh`<br>
4. Click on **Next**. In the summary window, click on **Finish** to complete the process. The new Keypair can now be used when creating new instances.

## Adding Keypairs to an existing instance

For security reasons, you can’t add or modify the Keypairs (SSH keys) on your instance using the control panel after you create it, but you have several options to add and modify them via the command line. If you currently have SSH access to the instance, you can upload keys:

* **From your local computer, using `ssh-copy-id`**, which is included in many Linux distribution's OpenSSH packages.<br>
* **From your local computer by piping the contents of the public key** into the `~/.ssh/authorized_keys` file. This is a good choice if you don’t have `ssh-copy-id`.<br>
* **By SSHing to your instance and adding the public key manually**, which is necessary if you do not have password-based SSH access.

## Regional Availability

Keypairs are available in all regions.

## Limitations

Keypairs are only supported for Linux and Unix-based instances.


# Networking


# Private Networks

A Private Network (also known as VPC) is a virtual version of a physical network (Layer 2) implemented inside of our production network using VXLAN encapsulation. Private Networks provide the following:

* Internal connectivity for your Compute Instances, including Kubernetes Clusters.
* Complete isolation of network traffic from other Private Networks.
* Integrated DHCP, IP, and DNS management enable easy network configuration.<br>

## Default Networks

Each region comes with a Private Network by default. The default network is an auto-created Private Network with the following addressing scheme:

* Region ALP1: 172.31.0.0/20
* Region ZRH1: 172.31.16.0/20

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Private Network.**<br>
2. Name your Private Network and compose a description.<br>
3. Under **CIDR**, specify the IP address allocation in CIDR notation for your Private Network (for example, 10.11.12.0/24).<br>
4. Under **Gateway IP**, specify the IP address that serves as an entrance to other networks, such as the internet (for example, 10.11.12.1).<br>
5. Under **Allocation Pool Start**, specify the IP address that will serve as the start of the DHCP allocation pool. (for example, 10.11.12.100).<br>
6. Under **Allocation Pool End**, specify the IP address that will serve as the end of the DHCP allocation pool. (for example, 10.11.12.200).<br>
7. Under **Domain Name Servers**, specify the IP addresses that will serve as the DNS for your Private Network. (for example, 1.1.1.1, 8.8.8.8).<br>
8. Under **Region**, choose a data center [Region](/platform/regions) where your Private Network should be created and click on **Save**. Creating a new Private Network takes a few minutes.

## Pricing

Private Networks are free of charge.

## Regional Availability

Private Networks are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limitations

Only one subnet per Private Network is supported.


# Routers

Routers provide L3 services such as routing and Source Network Address Translation (SNAT) between Virtual Private Cloud (VPC) network and public (WAN) networks, or different Virtual Private Cloud (VPC) networks:

* A Router between Virtual Private Cloud (VPC) network and public network provides access to public networks, such as the Internet, for VMs connected to this virtual network.<br>
* A virtual router between different Virtual Private Cloud (VPC) networks provides communication for VMs connected to these Virtual Private Cloud (VPC) networks.

With virtual routers, you can do the following:

* Create virtual routers
* Change external or internal router interfaces
* Create, edit, and delete static routes
* Change a router name
* Delete a router

## Plans and Pricing

Routers are free.

## Regional Availability

Routers are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limitations

* At the moment only IPv4 is supported.


# Security Groups

Security Groups place a barrier between your servers and other machines on the network to protect them from external attacks. Security Groups are network-based firewalls and stop traffic at the network layer before it reaches the server.

A security group consists a set of network access rules that control incoming and outgoing traffic to instance assigned to this group. With security group rules, you can specify the type and direction of traffic that is allowed access to a virtual interface port. Traffic that does not satisfy any rule is dropped.

For each region, a default security group is automatically created in the control panel. This group allows all traffic on all ports for all protocols. When you attach a network interface to an instance, the interface is associated with the default security group, unless you explicitly select a custom security group.

When you add rules to security groups or remove them, the changes are enforced at runtime.

## Quickstart

{% hint style="info" %}
As standard, each organization's account comes with a default Security Group per data center region. The default group allows all traffic on all ports for all protocols.
{% endhint %}

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Security Group**.<br>
2. Name your Security Group, compose a description and choose a data center [Region](/platform/regions)**.** Click on **Save** to create a new Security Grou&#x70;**.**<br>
3. To edit and manage the newly created Security Group, click on it in the list.<br>
4. Create a new rule by clicking on the **(+) Plus** button under the **Rules** tab.<br>
5. Under **Direction**, specify whether the rule should apply to inbound "Ingress" or outbound "Egress" traffic.<br>
6. Under **Protocol**, choose the protocol. The values Any, TCP, UDP, and ICMP are available for selection. Depending on the choice, you have the possibility to set further parameters. For TCP and UDP, you can specify the "Start port" and "End port", and for ICMP, the "Type" and "Code.<br>
7. Under **Remote**, specify the remote resource to which this rule should be applied. The values Any, Subnet, and Group are available for selection. Depending on the choice, you have the possibility to set further parameters. For the Subnet, you can specify the CIDR notation (for example, 10.11.12.0/24 or /32 for a single address). For Group, you can specify an existing Security Group.<br>
8. Click **Save** to add the rule to the Security Group. To assign the newly created Security Group, including the rules you created, to an instance, navigate to Compute > Instances > Instance > Security Groups.

## Disable Network Security

You have the ability to disable the Security Group feature per network interface of an instance. This feature is mostly required when you use a firewall distribution.

## Plans and Pricing

Security Groups are free.

## Regional Availability

Security Groups are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limitations

* You can manage only IPv4 security group rules.


# Elastic IPs

Elastic IPs (Floating IPs) are publicly-accessible static IP addresses that you can assign to Instances and instantly remap between other Instances in the same region.

You can use elastic IPs to create server infrastructures without single points of failure, but a elastic IP alone does not automatically provide high availability. For a setup to be highly available, you need to implement a failover mechanism to automate the process of detecting failures of the active server and reassigning the elastic IP to a passive server.

## Plans and Pricing

One Elastic IPs is free when assigned to a Instance. For pricing details please consult our [pricing page](https://flow.swiss/pricing#compute).

## Regional Availability

Elastic IPs are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* Elastic IPs cannot be assigned to more than one instances at a time.<br>
* At the moment, we do not support IPv6 elastic IPs. All elastic IPs are IPv4.<br>
* Reverse DNS Records (rDNS) have to be requested via support ticket.


# Load Balancers

Flow Load Balancers are a fully-managed, highly available network load balancing service. Load balancers distribute traffic to groups of Instances or Kubernetes Clusters, which decouples the overall health of a backend service from the health of a single server to ensure that your services stay online.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Load Balancer.**<br>
2. Name your Load Balance&#x72;**.**<br>
3. Choose a data center [Region](/platform/regions).<br>
4. Confirm the network topology. If you have more than one **Private Network**, you can select the one you want. By default, each Load Balancer is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the Load Balancer to be reachable only internally, uncheck the **IPv4** checkbox. Click on **Finish**. Deploying a Load Balancer takes a few minutes.<br>
5. To edit and manage the newly created Load Balancer, click on it in the list.<br>
6. Create a new pool by clicking on the **(+) Plus** button under the **Balancing Pools** tab.<br>
7. Under **Forwarding Rule**, choose the protocol. Enable **Proxy Protocol** only if you want to preserve the client IP for SSL passthrough.<br>
8. Under **Load Balancer Port**, specify the listener port.<br>
9. Under **Balancing Algorithm**, choose the [algorithm](#balancing-algorithms). Enable **Sticky Session** only if you want to enable the Session Persistence feature. Click on **Next** to proceed.<br>
10. Under **Members Port**, specify the backend port. It can be the same port number as in step 7 (listener) or its own port number.<br>
11. Under **Members**, add the Load Balancer members. Click on **Next** to proceed.<br>
12. Under **Protocol**, choose the protocol that the Health Monitor should use to monitor the availability of the pool members. Click on **Finish** to create a new Balancing Pool.

## Protocol Support

A single Load Balancer can be configured to handle multiple protocols and ports. You can control traffic routing with configurable rules that specify the ports and protocols that the load balancer should listen on, as well as the way that it should select and forward requests to the backend servers.

Because Flow Load Balancers are network load balancers, not application load balancers, they do not support directing traffic to specific backends based on URLs, cookies, HTTP headers, etc.

**HTTP**

Standard HTTP balancing directs requests based on standard HTTP mechanisms. The load balancer sets the `X-Forwarded-For`, `X-Forwarded-Proto`, and `X-Forwarded-Port` headers to give the backend servers information about the original request.

If user sessions depend on the client always connecting to the same backend, a cookie can be sent to the client to enable sticky sessions.

**HTTPS AND HTTP**

You can balance secure traffic using either HTTPS or HTTP. Both protocols can be configured with:

* **SSL termination**, which handles the SSL decryption at the load balancer after you add your SSL certificate and private key. <br>
* **SSL passthrough**, which forwards encrypted traffic to your backend Droplets. This is a good for end-to-end encryption and distributing the SSL decryption overhead, but you’ll need to manage the SSL certificates yourself.

**TCP / UDP**

TCP / UDP balancing is available for applications that do not speak HTTP. For example, deploying a load balancer in front of a database cluster like Galera would allow you to spread requests across all available machines.

#### PROXY Protocol <a href="#proxy-protocol" id="proxy-protocol"></a>

[PROXY protocol](https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt) is a way to send client connection information (like origin IP addresses and port numbers) to the final backend server rather than discarding it at the load balancer. This information can be helpful for use cases like analyzing traffic logs or changing application functionality based on geographical IP.

## Balancing Algorithms

* **Least connections**. Requests will be forwarded to the VM with the least number of active connections.<br>
* **Round robin**. All VMs will receive requests in the round-robin manner.<br>
* **Source IP**. Requests from a unique source IP address will be directed to the same VM.

Enable/disable the **Sticky session** option to enable/disable session persistence. The load balancer will generate a cookie that will be inserted into each response. The cookie will be used to send future requests to the same VM.

## Plans and Pricing

For pricing details, please consult the [pricing page](/platform/pricing/load-balancers).

## Regional Availability

Load Balancers are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* At the moment, IPv6 is not supported.

[^1]: Publicly-accessible static IP address


# Balancing Pools

## Manage the Balancing Pools

A load balancer can have one or more balancing pools. The balancing and health monitor properties are defined in the balancing pools. To see a list of balancing pools of a load balancer, click on its name.

To edit the balancing settings (such as the balancing algorithm and session persistence) or health monitor parameters, click the properties icon in the right corner.

You can monitor its performance and health on the Status, see its parameters on the Properties, and manage its members on the Members tab.

## Members

Each balancing pool contains one or more members (instances). The traffic is redirected to these using the configured balancing algorithm. To view the members to a balancing pool, click its name. You have the possibility to add, disable and remove members at runtime.&#x20;

## Health Monitor

A health monitor is a scheduled HTTP, TCP, UDP Connect or ICMP request that you can configure to run on a repeating basis to ensure that a service is healthy. You can manually set the health monitor parameters in the Balancers Detail view.


# Certificates

Some services, like load balancer SSL termination require SSL certificates. To add a new certificate you need to fill in four fields:

* **Name**\
  This is a name you choose to identify the certificate in the interface. It can only contain letters, numbers, periods, and dashes.<br>
* **Certificate**\
  This is the actual SSL public key or certificate file.<br>
* **Private key**\
  This is the secret key associated with the certificate.

{% hint style="info" %}
The **Certificate chain** must already be included in the certificate file. This is the full trust chain between the trusted certificate authority’s certificate and your domain’s certificate.
{% endhint %}

## Plans and Pricing

The storage of Certificates is free.

## Regional Availability

Certificates are available in all regions. They are region-specific resources and can only be assigned to items within the same region.


# VPN & Peering

VPN and Peering are two different managed connectivity services that use the same technology in the background but can be used independently of each other. Both services use the Internet Key Exchange (IKE) and IP Security (IPsec) protocols to establish secure connections and are based on strongSwan's IPsec solution.&#x20;

## VPN (Site-to-Site)

Our managed VPN service allows you to easily establish a Site-to-Site VPN connection between one of your private networks at Flow and your on-premise or other public cloud networks. The traffic that flows between VPN endpoints is encrypted.

## Peering

Our managed Peering service allows you to easily connect two cross-regional or two regional private networks with just a few clicks. Peering allows resources in one private network to communicate with resources in the other private network as if they were on the same network. The traffic that flows between Peering endpoints is encrypted.

## Quickstart

1. Start by navigating to "Compute" > "Networking" > "VPN & Peering" in the [Control Panel](https://my.flow.swiss).<br>
2. Click the **(+) Plus** button in the **VPN & Peering** tab.<br>
3. Choose the Connection Type. If you have selected **Peering**, follow step 4. If you have selected **VPN**, follow steps 5 to 9.<br>
4. Under **Local Private Network**, choose the local private network, and under **Remote Private Network**, the remote private network you would like to peer. Please note that only networks can be selected where the CIDR does not overlap and that both private networks must be connected to a [Router](/products/compute/networking/routers) of a public type.\
   \
   Click on **Finish**. Establishing a new peering connection takes a few minutes.<br>
5. Under **Local Private Network**, choose the local private network. Under **Remote Public IP,** specify the public IP of the remote VPN endpoint. Under **Remote CIDRs**, specify the CIDRs (Subnets) of the remote site.<br>
6. Under **IKE Policy**, specify parameters for the Internet Key Exchange (IKE) policy that will be used to establish a VPN connection. Or keep the default best practices.<br>
7. Under **IPsec Policy**, specify parameters for the IP Security (IPsec) policy that will be used to encrypt the VPN traffic. Or keep the default best practices.<br>
8. Under **VPN Configuration**, specify the matching configuration parameters necessary to connect to the remote VPN endpoint. Please note that the configuration parameters on both VPN endpoints must match for the connection to be established successfully.<br>
9. Name your VPN connection and click on **Finish**. Establishing a new VPN connection takes a few minutes.

## Limitations

Instances (VMs) with an [Elastic IP](#user-content-fn-1)[^1] attached cannot currently be reached via managed VPN or Peering connections. Only instances with a private IP can be addressed via this type of connection. This limitation will be lifted in Q1-2023.

[^1]: Publicly-accessible static IP address


# Kubernetes

Flow Kubernetes is a managed Kubernetes service lets you deploy scalable and secure Kubernetes clusters without the complexities of administrating the control plane. We manage the Kubernetes control plane and the underlying containerized infrastructure. \
\
Clusters are compatible with standard Kubernetes toolchains and integrate natively with our Load Balancers and block storage volumes.

There are no restrictions on the API objects you can create as long as the underlying Kubernetes version supports them. We offer the latest version of Kubernetes as well as earlier patch levels of the latest minor version for special use cases. You can also install popular tools like Helm, metrics-server, and Istio.

## Nodes

Worker and Master nodes are built on instaces, but unlike standalone instances, worker nodes are managed with the Kubernetes command-line client `kubectl` and are not accessible with SSH. On both the control plane and the worker nodes, Flow maintains the system updates, security patches, operating system configuration and installed packages.

Worker nodes are automatically deleted and respawned when needed, and you can manually rebuild worker nodes.

## Persistent Data

You can persist data in Kubernetes clusters to block storage volumes using the Flow CSI plugin, the CSI Plugin is already preinstalled and is used for the default storage class.

You can also persist data to Flow object storage by using the S3 API to interact with the storage from your application.

## Load Balancing

The Flow Kubernetes Cloud Controller supports provisioning [external Load Balancers](/products/kubernetes/resources/external-load-balancers).

## VPC Support

Clusters are added to a VPC network for the datacenter region by default. This keeps traffic between clusters and other applicable resources from being routed outside the datacenter over the public internet.

## Plans and Pricing

The cost of a Kubernetes cluster is based on the cluster’s resources:

* Nodes (Workers and Master / Control plane ) are built on Instances.<br>
* Integration Load Balancers is charged at the same rate as common Load Balancers.<br>
* Integration with block storage volumes is charged at the same rate as volumes.

All charges for Kubernetes clusters appear in the Kubernetes detail view section. For pricing details please consult our [pricing page](https://flow.swiss/pricing#kubernetes).

## Regional Availability

Kubernetes Clusters are available in all regions. They are region-specific resources and can only be assigned within the same region.

## Limits

* At the moment IPv6 is not supported.<br>
* The control plane is not highly available and may be temporarily unavailable during upgrades or maintenance. This does not affect running clusters and does not make the cluster workers or workloads unavailable if external load balancers are used.


# Clusters

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Kubernetes Cluster**.<br>
2. Choose a data center [Region](/platform/regions).<br>
3. Choose the default configuration for your worker nodes, which determines their RAM, vCPUs, and price. If you need more than three worker nodes, click the **(+) Plus** sign on the card.<br>
4. Confirm the network topology. If you have more than one **Private Network**, you can select the one you want. By default, each cluster is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the cluster to be reachable only internally, uncheck the **IPv4** checkbox.<br>
5. Name your cluster and click on **Finish**. Deploying the cluster takes a few minutes.<br>
6. Download the cluster configuration file by clicking the **(**•••**) More** button and then **Download Kube-Config**.<br>
7. Once the cluster is created, use [kubectl](https://kubernetes.io/docs/tasks/tools/), the official Kubernetes command-line tool, to connect and interact with the cluster. If you prefer an intuitive graphical interface, then the free third-party tool [Lens](https://k8slens.dev/desktop.html) is right for you.

[^1]: Publicly-accessible static IP address


# Resources


# Volumes Features (CSI)

The availability of a specific CSI feature depends on the deployed version. The table below outlines the minimum versions required to use a particular feature:

| Feature           | Description                                          | Available From |
| ----------------- | ---------------------------------------------------- | -------------- |
| Volume Expansion  | Resize a volume to increase the available disk space | All Versions   |
| Raw Block Volumes | Use a volume as a block device                       | All Versions   |
| Volume Snapshots  | Create and restore from snapshots                    | 1.1.4          |


# External Load Balancers

## About

Generally, applications running inside a Kubernetes cluster are not available to the outside world. To expose such applications Kubernetes added support for cloud providers to implement external Load Balancers which will be synchronized with the cluster. Our cloud controller manager (CCM) supports these external Load Balancers and you can simply provision an external Load Balancer on our infrastructure by setting the `spec.type` property of your service configuration to `LoadBalancer`.

If you are interested in the general configuration of services and external Load Balancers, please read the official Kubernetes documentation found [here](https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer). A simple TCP Load Balancer configuration might look like this:

```
apiVersion: v1
kind: Service
metadata:
  name: some-application
spec:
  type: LoadBalancer
  selector:
    app: some-application
  ports:
    - protocol: TCP
      port: 80
```

For our managed Kubernetes solution you can choose to disable the external Load Balancer by updating the configuration of your cluster. Setting the Load Balancer type to internal will delete all existing Load Balancers and your services will only be available from the network interfaces of your nodes. If you have a public cluster you can still access your services over the Elastic IP attached to your master node.

## Custom Annotations

Since Kubernetes only supports the minimum requirements for Load Balancers, we have added custom annotations which you can simply apply to your service YAML. The cloud-controller-manager (CCM) will interpret them and apply them to the final Load Balancer configuration. All of these annotations are optional.

```
// example of a Terminated HTTPS Load Balancer
apiVersion: v1
kind: Service
metadata:
  name: some-application
  annotations:
    load-balancer.flow.swiss/entry-protocol: "terminated_https"
    load-balancer.flow.swiss/target-protocol: "http"
    load-balancer.flow.swiss/tls-certificate: "1234"
    load-balancer.flow.swiss/health-check-type: "http"
    load-balancer.flow.swiss/health-check-method: "GET"
    load-balancer.flow.swiss/health-check-path: "/health"
spec:
  type: LoadBalancer
  selector:
    app: some-application
  ports:
- port: 80
```

### General

`load-balancer.flow.swiss/entry-protocol`\
The name of the protocol which should be used between the client and the load balancer (see Supported Protocols below).

`load-balancer.flow.swiss/target-protocol`\
The name of the protocol which should be used between the load balancer and the nodes (see Supported Protocols below).

`load-balancer.flow.swiss/algorithm`\
The algorithm which should be used to distribute traffic to the individual nodes (see Supported Balancing Algorithms below).

`load-balancer.flow.swiss/sticky-session`\
If this is set to "true" the load balancer will try to always direct a client to the same node using cookies when the protocol is HTTP or Terminated HTTPS or the clients' source IP address for every other protocol.

`load-balancer.flow.swiss/tls-certificate`\
The unique identifier of the TLS certificate which should be served by the load balancer. This option may only be set if the entry protocol is Terminated HTTPS. To set this option, you need to create a certificate on myFlow and use the ID to reference it in Kubernetes.

### Networking

`load-balancer.flow.swiss/internal`\
Set this to "true" if you want the load balancer to only be available from inside the network (no external elastic IP will be attached to the load balancer).

`load-balancer.flow.swiss/network`\
The unique identifier of the network in which the load balancer should be spawned. This is required if your nodes have multiple network interfaces or are located in different networks.&#x20;

`load-balancer.flow.swiss/private-ip`\
A static private IP for the load balancer inside the network. The IP must be available otherwise the deployment will fail.

### Health Check

A health check is used by the load balancer to determine whether a node is currently able to handle connections. If a node is marked as unhealthy by the health check it will be excluded from handling connections until the node is healthy again.

`load-balancer.flow.swiss/health-check-type`\
The health check type determines how the load balancer can determine whether a node can currently handle requests (see supported health check types below).

`load-balancer.flow.swiss/health-check-path`\
The HTTP path which should be called. This option may only be set for the HTTP and HTTPS health check types.

`load-balancer.flow.swiss/health-check-method`\
The HTTP method which should be used. This option may only be set for the HTTP and HTTPS health check types.

`load-balancer.flow.swiss/health-check-interval`\
The interval in seconds at which the health check should run. This value must be between 5 and 300 seconds.

`load-balancer.flow.swiss/health-check-timeout`\
The timeout in seconds after which the health check should fail if a node is not responding. This value must be between 5 and 300 seconds.

`load-balancer.flow.swiss/health-check-healthy-threshold`\
The number of successful health checks that are required before a node is considered healthy. This value must be between 1 and 10.

`load-balancer.flow.swiss/health-check-unhealthy-threshold`\
The amount of failed health checks that are required before a node is considered unhealthy. This value must be between 1 and 10.

### Supported Protocols

* HTTP "http"
* HTTPS "https"
* Terminated HTTPS "terminated\_https"
* TCP "tcp"
* UDP "udp"
* PROXY

{% hint style="info" %}
A list of supported load balancer protocols can always be found over the API via the [https://api.flow.swiss/v4/entities/compute/load-balancer-protocols](https://api.flow.swiss/v4/entities/compute/load-balancer-protocols?no_filter=1) endpoint.
{% endhint %}

### PROXY Protocol

The target protocol of PROXY will use the entry protocol as the pool protocol but will wrap that protocol in the proxy protocol. In the case of entry protocol TERMINATED\_HTTPS, a target protocol of PROXY will be HTTP wrapped in the proxy protocol.

### Protocol Combinations

The following protocol combinations are supported:

| Entry Protocol | HTTP | HTTPS | TCP | TERMINATED\_HTTPS | UDP |
| -------------- | ---- | ----- | --- | ----------------- | --- |
| HTTP           |   Y  |   N   |   Y |         Y         |   N |
| HTTPS          |   N  |   Y   |   Y |         N         |   N |
| PROXY          |   Y  |   Y   |   Y |         Y         |   N |
| TCP            |   N  |   Y   |   Y |         N         |   N |
| UDP            |   N  |   N   |   N |         N         |   Y |

“Y” means the combination is valid and “N” means invalid.

### Supported Balancing Algorithms

* Round Robin "round\_robin"
* Least Connections "least\_connections"
* Source IP "source\_ip"

A list of supported load balancer algorithms can always be found over the API via the <https://api.flow.swiss/v4/entities/compute/load-balancer-algorithms> endpoint.

### Supported Health Check Types

* Ping "ping"
* TCP "tcp"
* UDP Connect "upd\_connect"
* HTTP "http"
* HTTPS "https"

A list of supported load balancer health check types can always be found over the API via the <https://api.flow.swiss/v4/entities/compute/load-balancer-health-check-types> endpoint.


# Cluster Autoscaler

## Introduction

Cluster Autoscaler is a component that automatically adjusts the size of a Kubernetes Cluster so that all pods have a place to run and there are no unneeded nodes.

The cluster autoscaler for Flow scales worker nodes within any specified Flow Kubernetes cluster.

## Installation

As there is no concept of a node group within Flow Cloud's Kubernetes offering, the configuration required is quite simple. You need to set:

* Your Flow Application Token
* The Kubernetes Cluster's ID (not the name)
* The minimum and maximum number of **worker** nodes you want (the master is excluded)

1. Please adjust the following bold values in the yaml file below:

* Minimum & Maximum of worker nodes (for example minimum 3 and maximal nine): `nodes=3:9:workers`<br>
* Generate an application token in <https://my.flow.swiss/#/organization/applications> and convert it to a base64 string and replace the \*\*api-token\*\* value.<br>
* Retrieve the cluster ID from your Kubernetes Cluster, convert it to a base64 string and replace the \*\*cluster-id\*\* value.

```
cluster-autoscaler.yaml
 
---
apiVersion: v1
kind: ServiceAccount
metadata:
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
  name: cluster-autoscaler
  namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: cluster-autoscaler
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
rules:
  - apiGroups: [""]
    resources:
      [
        "pods",
        "services",
        "replicationcontrollers",
        "persistentvolumeclaims",
        "persistentvolumes",
        "nodes",
        "endpoints",
        "namespaces",
        "configmaps",
      ]
    verbs: ["watch", "list", "get", "update", "create", "delete"]
  - apiGroups: [""]
    resources: ["events"]
    verbs: ["watch", "list", "get", "create", "update", "delete", "patch"]
  - apiGroups: ["extensions"]
    resources: ["replicasets", "daemonsets"]
    verbs: ["watch", "list", "get"]
  - apiGroups: ["policy"]
    resources: ["poddisruptionbudgets"]
    verbs: ["watch", "list"]
  - apiGroups: ["apps"]
    resources: ["statefulsets", "replicasets", "daemonsets"]
    verbs: ["watch", "list", "get"]
  - apiGroups: ["storage.k8s.io"]
    resources:
      ["storageclasses", "csinodes", "csistoragecapacities", "csidrivers"]
    verbs: ["watch", "list", "get"]
  - apiGroups: ["batch", "extensions"]
    resources: ["jobs"]
    verbs: ["get", "list", "watch", "patch"]
  - apiGroups: ["coordination.k8s.io"]
    resources: ["leases"]
    verbs: ["get", "create", "update"]
  - apiGroups: [""]
    resources: ["pods/eviction"]
    verbs: ["create"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: cluster-autoscaler
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: cluster-autoscaler
subjects:
  - kind: ServiceAccount
    name: cluster-autoscaler
    namespace: kube-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: cluster-autoscaler
  namespace: kube-system
  labels:
    k8s-addon: cluster-autoscaler.addons.k8s.io
    k8s-app: cluster-autoscaler
rules:
  - apiGroups: ["coordination.k8s.io"]
    resources: ["leases"]
    verbs: ["create", "get", "update"]
    resourceNames: ["cluster-autoscaler"]
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["create", "list", "watch", "update"]
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: cluster-autoscaler
  namespace: kube-system
  labels:
    app: cluster-autoscaler
spec:
  replicas: 1
  selector:
    matchLabels:
      app: cluster-autoscaler
  template:
    metadata:
      labels:
        app: cluster-autoscaler
      annotations:
        prometheus.io/scrape: "true"
        prometheus.io/port: "8085"
    spec:
      serviceAccountName: cluster-autoscaler
      containers:
        - image: flowswiss/cluster-autoscaler:v0.0.4 
          name: cluster-autoscaler
          imagePullPolicy: Always
          resources:
            limits:
              cpu: 100m
              memory: 300Mi
            requests:
              cpu: 100m
              memory: 300Mi
          command:
            - ./cluster-autoscaler
            - --v=4
            - --stderrthreshold=info
            - --cloud-provider=flow
            - --nodes=1:6:workers
            - --skip-nodes-with-local-storage=false
            - --skip-nodes-with-system-pods=false
          env:
            - name: FLOW_API_TOKEN
              valueFrom:
                secretKeyRef:
                  key: **api-token** #base64_encoded_api_token
                  name: cluster-autoscaler-secrets
            - name: FLOW_CLUSTER_ID
              valueFrom:
                secretKeyRef:
                  name: cluster-autoscaler-secrets
                  key: **cluster-id** #base64_encoded_cluster_id
            - name: FLOW_API_URL
              valueFrom:
                secretKeyRef:
                  name: cluster-autoscaler-secrets
                  key: aHR0cHM6Ly9hcGkuZmxvdy5zd2lzcy8= #base64_encoded_api_url
```

2. Apply the yaml file with kubectl in your desired Kubernetes Cluster.<br>
3. Follow the official documentation to configure the behavior of the cluster autoscaler: <https://github.com/kubernetes/autoscaler/tree/master/cluster-autoscaler>\ <br>


# Traefik upgrade and tests

Upgrading older versions of k3s to a new one and having the old Traefik v1 seems to be a common issue that k3s users are facing. There are a several of issues which happen when upgrading without changing API resources (ingress):

* [Failed to list \*v1beta1.Ingress: the server could not find the requested resource (get ingresses.extensions)](https://github.com/k3s-io/k3s/issues/4967)
* [Issue #4967 · k3s-io/k3s · GitHub](https://github.com/k3s-io/k3s/issues/4967)

The common solution which people recommend is simply upgrade Traefik. There are plenty of guides even official ones from Traefik. We recommend the following workflow with Helm:

#### Upgrade Traefik with Helm

*Setup:* From Kubernetes v1.20.x to v1.24.X with Traefik helm chart 1.8.1

1. Uninstall current Traefik version v1.8x.x `helm uninstall traefik -n kube-system`
2. Make sure Helm has everything it needs to install Traefik v2 `helm repo add traefik https://helm.traefik.io/traefik` `helm repo update`
3. Install new Traefik v2 ([GitHub - traefik/traefik-helm-chart: Traefik v2 helm chart](https://github.com/traefik/traefik-helm-chart)) `helm install traefik traefik/traefik`
4. Migrate your configurations and ingress definitions to the new Traefik v2 by using the official guides and tools:
   * [Traefik V2 Migration Documentation - Traefik](https://doc.traefik.io/traefik/migration/v1-to-v2/#some-tips-you-should-know)
   * [GitHub - traefik/traefik-migration-tool: A migration tool from Traefik v1 to Traefik v2.](https://github.com/traefik/traefik-migration-tool)


# Update custom resource definitions (CRDs) for VolumeSnapshots

The CRDs for the VolumeSnapshots are still in v1beta1 and the cluster has been updated to min Kubernetes v1.23.3. v1beta1 support will be removed in a future release. It is recommended for users to switch to v1 as soon as possible after upgrading the cluster:

1. Check and delete all old VolumeSnapshots
2. Apply new CRDs `kubectl apply -f https://raw.githubusercontent.com/flowswiss/csi-driver/master/deployments/kubernetes/latest/crds.yaml`
3. Check if new CRDs are applied `kubectl get crds`


# Object Storage

## Introduction

Flow Object Storage is an [S3-compatible](/products/object-storage/ressources/supported-amazon-s3-features) object storage service that lets you store and serve large amounts of data. You can create them in a few seconds and use them immediately with no configuration. Data transfer is automatically secured with HTTPS, and the available storage capacity scales seamlessly.

Object Storage is ideal for storing static, unstructured data like audio, video, and images as well as large amounts of text. Use cases like databases, applications written in server-side languages, and mission-critical applications will work best with local storage (volumes).


# Instances

## Quickstart

1. Start by navigating to "Object Storage" > "Overview" in the [Control Panel](https://my.flow.swiss).<br>
2. Choose a data center [Region](/platform/regions).<br>
3. Click the **Activate** button and confirm with **Yes, activate**. Deploying an Object Storage instance takes a few minutes.<br>
4. Once the instance is created, follow the [detailed guides](/products/object-storage/how-to) on how to access it.


# How-to


# Access Storage with AWS S3 SDKs

## Introduction

Flow Object Storage is an S3-compatible object storage service that lets you store and serve large amounts of data.&#x20;

The Flow Object Storage API is inter-operable with the AWS S3 API, meaning you can use existing S3 tools and libraries with Spaces. A common use case is managing Flow Object Storage programmatically with AWS’ S3 SDKs.

## Install the SDK

Install the AWS SDK using the package manager for your language of choice.

{% tabs %}
{% tab title="Java Script" %}

```
npm install aws-sdk
```

{% endtab %}

{% tab title="Go" %}

```
go get -u github.com/aws/aws-sdk-go
```

{% endtab %}

{% tab title="PHP" %}

```
php composer.phar require aws/aws-sdk-php
```

{% endtab %}

{% tab title="Python" %}

```
pip install boto3
```

{% endtab %}

{% tab title="Ruby" %}

```
gem install aws-sdk-s3
```

{% endtab %}
{% endtabs %}

## Obtain Access & Secret Keys

You are able to retrieve the access & secret keys in our customer portal:\
<https://my.flow.swiss/#/object-storage>

The examples below rely on environment variables to access these keys. Export `ACCESS_KEY` and `SECRET_KEY` to your environment (e.g. `export ACCESS_KEY=DSJE2334JAS`) to make them available to your code.

## SDKs

After you set up and configure an SDK, you can follow the examples below to see how to perform common Flow Object Storage operations in JavaScript, Go, PHP, Python and Ruby.

{% tabs %}
{% tab title="Java Script" %}

```
const AWS = require('aws-sdk');
const fs = require('fs'); // Needed for example below

const spacesEndpoint = new AWS.Endpoint('<S3-ENDPOINT>');
const s3 = new AWS.S3({
    endpoint: spacesEndpoint,
    accessKeyId: process.env.ACCESS_KEY,
    secretAccessKey: process.env.SECRET_KEY
});
```

{% endtab %}

{% tab title="Go" %}

```
package main

import (
    "os"
    // Additional imports needed for examples below
    "fmt"
    "io"
    "strings"
    "time"

    "github.com/aws/aws-sdk-go/aws"
    "github.com/aws/aws-sdk-go/aws/credentials"
    "github.com/aws/aws-sdk-go/aws/session"
    "github.com/aws/aws-sdk-go/service/s3"
)

func main() {
    key := os.Getenv("ACCESS_KEY")
    secret := os.Getenv("SECRET_KEY")

    s3Config := &aws.Config{
        Credentials: credentials.NewStaticCredentials(key, secret, ""),
        Endpoint:    aws.String("https://<ENDPOINT>"),
        Region:      aws.String("us-east-1"),
    }

    newSession := session.New(s3Config)
    s3Client := s3.New(newSession)

    // ...
```

{% endtab %}

{% tab title="PHP" %}
{% hint style="info" %}
This SDK requires the `region` to be `us-east-1`, an AWS region name, to successfully create a new Bucket. The Flow Object Storage datacenter region is based on the \
\<ENDPOINT> value.
{% endhint %}

```
<?php

// Included aws/aws-sdk-php via Composer's autoloader
require 'vendor/autoload.php';
use Aws\S3\S3Client;

$client = new Aws\S3\S3Client([
        'version' => 'latest',
        'region'  => 'us-east-1',
        'endpoint' => 'https://<ENDPOINT>',
        'credentials' => [
                'key'    => getenv('ACCESS_KEY'),
                'secret' => getenv('SECRET_KEY'),
            ],
]);
```

{% endtab %}

{% tab title="Python 3" %}

```
import os
import boto3

session = boto3.session.Session()
client = session.client('s3',
                        region_name='nyc3',
                        endpoint_url='https://<ENDPOINT>',
                        aws_access_key_id=os.getenv('ACCESS_KEY'),
                        aws_secret_access_key=os.getenv('SECRET_KEY'))
```

{% endtab %}

{% tab title="Ruby" %}

```
require 'aws-sdk-s3'

client = Aws::S3::Client.new(
  access_key_id: ENV['ACCESS_KEY'],
  secret_access_key: ENV['SECRET_KEY'],
  endpoint: 'https://<ENDPOINT>',
  region: 'us-east-1'
)
```

{% endtab %}
{% endtabs %}

{% hint style="info" %}
Please replace the \<ENDPOINT> place holder with the correct endpoint:\
\
**Location ALP1:** os.alp1.flow\.swiss\
**Location ZRH1:** os.zrh1.flow\.swiss
{% endhint %}


# Access Storage with Cyberduck

To access Flow Object Storage with Cyberduck, please follow these steps:

1. Download (<https://cyberduck.io>) and install Cyberduck<br>
2. Open CyberDuck and click **Open Connection**.<br>
3. Specify your the credentials which are provided in our customer portal (<https://my.flow.swiss/#/object-storage>):<br>
   * **Server:** Insert the DNS name of the S3 endpoint:\
     \
     Location ALP1: **os.alp1.flow\.swiss**\
     Location ZRH1: **os.zrh1.flow\.swiss**<br>
   * **Access Key ID:** Insert the displayed **Access Key** from our portal.
   * **Secret Access Key ID:** Insert the displayed **Secret Key** from our portal.<br>
4. Press the connect button

*Example for ALP1:*

![](/files/-M76uy5eYRcqWRKixbJo)


# Access Storage with Mountainduck

Mountain Duck enables you to mount and access Flow Object Storage as a regular disk drive. To access Flow Object Storage with Cyberduck, please follow these steps:

1. Download (<https://mountainduck.io>) and install Cyberduck<br>
2. Start Mountain Duck and click **Open Connection**.<br>
3. Specify your the credentials which are provided in our customer portal (<https://my.flow.swiss/#/object-storage>):<br>
   * **Server:** Insert the DNS name of the S3 endpoint:\
     \
     Location ALP1: **os.alp1.flow\.swiss**\
     Location ZRH1: **os.zrh1.flow\.swiss**<br>
   * **Access Key ID:** Insert the displayed **Access Key** from our portal.
   * **Secret Access Key ID:** Insert the displayed **Secret Key** from our portal.<br>
4. Press the connect button

*Example for ALP1:*

![](/files/-M76y_PQyuT50MNxtoKT)


# Ressources


# Supported Amazon S3 features

Besides basic Amazon S3 operations like GET, PUT, COPY, DELETE, the Flow Object Storage implementation of the Amazon S3 protocol supports the following features:

* Multipart upload
* Access control lists (ACLs)
* Versioning
* Signed URLs
* Object locking
* Geo-replication
* Server access logging
* Object storage classes
* Cross-region replication (CRR)
* Bucket policies
* Object expiration
* Cross-origin resource sharing (CORS)

## Supported authentication schemes

The following authentication schemes are supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* [Signature Version 2](https://docs.aws.amazon.com/general/latest/gr/signature-version-2.html)
* [Signature Version 4](https://docs.aws.amazon.com/general/latest/gr/signature-version-4.html)

The following authentication methods are supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* [Using the authorization header](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-auth-using-authorization-header.html)
  * [Transferring payload in a single chunk](https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-header-based-auth.html)
* [Using query parameters](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-query-string-auth.html)
* [Browser-based uploads using POST](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-UsingHTTPPOST.html)

The following authentication method is not supported:

* [Transferring payload in multiple chunks](https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-streaming.html)

## Supported Amazon request headers

The following Amazon S3 REST request headers are currently supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* Authorization
* Content-Length
* Content-Type
* Content-MD5
* Date
* Host
* x-amz-content-sha256
* x-amz-date
* x-amz-security-token
* x-amz-object-lock-retain-until-date
* x-amz-object-lock-mode
* x-amz-object-lock-legal-hold
* x-amz-bypass-governance-retention
* x-amz-bucket-object-lock-enabled
* x-amz-geo-endpoint
* x-amz-geo-access-key
* x-amz-geo-access-secret

## Supported Amazon response headers

The following Amazon S3 REST response headers are currently supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* Content-Length
* Content-Type
* Connection
* Date
* ETag
* x-amz-delete-marker
* x-amz-request-id
* x-amz-version-id
* x-amz-object-lock-retain-until-date
* x-amz-object-lock-mode
* x-amz-object-lock-legal-hold
* x-amz-geo-endpoint
* x-amz-geo-access-key
* x-amz-geo-access-secret

The following Amazon S3 REST response headers are not used:

* Server
* x-amz-id-2

## Supported Amazon error response headers

The following Amazon S3 REST error response headers are currently supported by the Flow Object Storage implementation of the Amazon S3 protocol:

* Code
* Error
* Message

The following Amazon S3 REST error response headers are not supported:

* RequestId (not used)
* Resource

## Supported Amazon S3 object expiration actions

The Flow Object Storage implementation of the Amazon S3 object lifecycle only supports object expiration by prefix. Deleting objects by tag is not available. The rule definition for object expiration is similar to that for bucket policies.

The following S3 object expiration actions are currently supported:

* Expiration. Deletes objects by age or by date. In case of versioning, inserts a delete marker, which becomes the latest version of an object. Delete markers are not removed.
* NonCurrentVersionExpiration. Deletes an object version after it has become non-current for the specified number of days.
* AbortIncompleteMultipartUpload. Aborts a multipart upload that has not completed during the specified number of days.
* ExpiredObjectDeleteMarker. Deletes a delete marker as soon as there are no other versions of an object.

##

<br>


# Replication Management

This section describes how to manage S3 cross-region replication (CRR) that enables copy objects asynchronously across buckets stored in different regions and public cloud providers using the Amazon S3-compatible CRR API.

{% content-ref url="/pages/KgrG6OcafgoPJznpaope" %}
[GET service replication](/products/object-storage/ressources/replication-management/get-service-replication)
{% endcontent-ref %}

{% content-ref url="/pages/cHMdyBkfZb95EcVvBpWw" %}
[PUT service replication](/products/object-storage/ressources/replication-management/put-service-replication)
{% endcontent-ref %}

{% content-ref url="/pages/EYsgh5hAtJOEEYiR41Hz" %}
[DELETE service replication](/products/object-storage/ressources/replication-management/delete-service-replication)
{% endcontent-ref %}


# GET service replication

Lists information about replication configuration for the specified bucket.

### Requests <a href="#kanchor121" id="kanchor121"></a>

#### Syntax <a href="#kanchor122" id="kanchor122"></a>

```
GET /?replication HTTP/1.1
Host: <bucket>.<host>
Date: <date>
Authorization: <authorization_string>
```

#### Parameters <a href="#kanchor123" id="kanchor123"></a>

| Parameter | Description                                                        | Required |
| --------- | ------------------------------------------------------------------ | -------- |
| `bucket`  | <p>Bucket name.</p><p>Type: string.</p><p>Default value: none.</p> | Yes      |

#### Headers <a href="#kanchor124" id="kanchor124"></a>

This implementation uses only common request headers.

### Responses <a href="#kanchor125" id="kanchor125"></a>

#### Headers <a href="#kanchor126" id="kanchor126"></a>

| Header                    | Description                                                             |
| ------------------------- | ----------------------------------------------------------------------- |
| `x-amz-geo-endpoint`      | Endpoint of the remote region where to replicate objects to.            |
| `x-amz-geo-access-key`    | Access key of a user of the remote region used to replicate objects.    |
| `x-amz-geo-access-secret` | Access secret of a user of the remote region used to replicate objects. |

#### Body <a href="#kanchor127" id="kanchor127"></a>

An XML replication configuration in the following format:

```
<?xml version="1.0" encoding="UTF-8"?>
<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
   <Role>arn:aws:iam::<user_id>:role/s3-replication-role</Role>
   <Rule>
      <Status>Enabled|Disabled</Status>
      <Priority>1</Priority>
      <DeleteMarkerReplication>
         <Status>Enabled|Disabled</Status>
      </DeleteMarkerReplication>
      <Filter>
         <Prefix />
      </Filter>
      <Destination>
         <Bucket>arn:aws:s3:::<destination_bucket></Bucket>
      </Destination>
   </Rule>
</ReplicationConfiguration>
```

#### Examples <a href="#kanchor128" id="kanchor128"></a>

Sample request

Returns replication configuration of the bucket `test`.

```
GET /?replication HTTP/1.1
Host: os.zrh1.flow.swiss
Date: Tu, 18 Jan 2021 14:08:55 GMT
Authorization: <authorization_string>
```

Sample response

```
HTTP/1.1 200 OK
Transfer-encoding : chunked
Server : nginx/1.8.1
Connection: closed
x-amz-request-id : 80000000000000030005c8caec96d65b
Date : Thu, 07 Apr 2016 14:08:56 GMT
Content-type : application/xml
<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
   <Role>arn:aws:iam::850b4943d62191a5:role/s3-replication-role</Role>
   <Rule>
      <Status>Enabled</Status>
      <Priority>1</Priority>
      <DeleteMarkerReplication>
         <Status>Disabled</Status>
      </DeleteMarkerReplication>
      <Filter>
         <Prefix />
      </Filter>
      <Destination>
         <Bucket>arn:aws:s3:::AWSDOC-EXAMPLE-BUCKET2</Bucket>
      </Destination>
   </Rule>
</ReplicationConfiguration>
```


# PUT service replication

Sets replication configuration for the specified bucket.

### Requests <a href="#kanchor110" id="kanchor110"></a>

#### Syntax <a href="#kanchor111" id="kanchor111"></a>

```
PUT /?replication HTTP/1.1
Host: <bucket>.<host>
Date: <date>
Authorization: <authorization_string>
```

#### Parameters <a href="#kanchor112" id="kanchor112"></a>

<table><thead><tr><th>Parameter</th><th width="382.66666666666663">Description</th></tr></thead><tbody><tr><td><code>bucket</code></td><td><p>Bucket name.</p><p>Type: string.</p></td></tr><tr><td><code>user_id</code></td><td><p>ID of the user that is used to replicate objects on your behalf.</p><p>Type: string.</p><p><br>The ID can always be taken from the Access Key by dropping the last 4 digits.</p></td></tr><tr><td><code>destination_bucket</code></td><td><p>The name of the bucket where you want to store the results.</p><p>Type: string.</p></td></tr><tr><td>&#x3C;authorization_string></td><td>&#x3C;authorization_string>: To get the authorization string in the request, you will need to use the AWS Signature Version 4 signing process. This process involves creating a signature using your AWS access key and secret key, along with information from the request, such as the date, the host, and the specific API endpoint you are trying to access. You can find more information on how to create this signature and add it to your request in the AWS documentation: <a href="https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html">https://docs.aws.amazon.com/AmazonS3/latest/API/sig-v4-authenticating-requests.html</a><br><a href="https://datafetcher.com/aws-signature-version-4-calculator">https://datafetcher.com/aws-signature-version-4-calculator</a></td></tr></tbody></table>

#### Body <a href="#kanchor113" id="kanchor113"></a>

An XML replication configuration in the following format:

```
<?xml version="1.0" encoding="UTF-8"?>
<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
   <Role>arn:aws:iam::<user_id>:role/s3-replication-role</Role>
   <Rule>
      <Status>Enabled|Disabled</Status>
      <Priority>1</Priority>
      <DeleteMarkerReplication>
         <Status>Enabled|Disabled</Status>
      </DeleteMarkerReplication>
      <Filter>
         <Prefix />
      </Filter>
      <Destination>
         <Bucket>arn:aws:s3:::<destination_bucket></Bucket>
      </Destination>
   </Rule>
</ReplicationConfiguration>
```

#### Headers <a href="#kanchor114" id="kanchor114"></a>

| Header                    | Description                                                                                                                       |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| `x-amz-geo-endpoint`      | <p>Endpoint of the remote region where to replicate objects to.<br><br>ZRH1: os.zrh1.flow\.swiss<br>ALP1: os.alp1.flow\.swiss</p> |
| `x-amz-geo-access-key`    | Access key of a user of the remote region used to replicate objects.                                                              |
| `x-amz-geo-access-secret` | Access secret of a user of the remote region used to replicate objects.                                                           |

### Responses <a href="#kanchor115" id="kanchor115"></a>

#### Headers <a href="#kanchor116" id="kanchor116"></a>

This implementation uses only common response headers.

#### Body <a href="#kanchor117" id="kanchor117"></a>

Empty.

#### Example <a href="#kanchor118" id="kanchor118"></a>

Sets replication configuration for the bucket. `test`.

```
PUT/?replication HTTP/1.1 
Host: test.os.zrh1.flow.swiss 
Date: Tu, 13 Jan 2023 14:08:55 GMT 
Authorization: <authorization_string> 
x-amz-geo-endpoint: os.alp1.flow.swiss
x-amz-geo-access-key: <access_key> 
x-amz-geo-access-secret: <access-secret>

<ReplicationConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/"> 
   <Role>arn:aws:iam::<user_id>:role/s3-replication-role</Role> 
   <Rule> 
      <Status>Enabled</Status> 
      <Priority>1</Priority> 
      <DeleteMarkerReplication> 
         <Status>Disabled</Status> 
      </DeleteMarkerReplication> 
      <Filter> 
         <Prefix /> 
      </Filter> 
      <Destination> 
         <Bucket>arn:aws:s3:::os.alp1.flow.swiss</Bucket> 
      </Destination> 
   </Rule> 
</ReplicationConfiguration>
```

**Sample response**

```
HTTP/1.1 200 OK
Transfer-encoding : chunked
Server : nginx/1.8.1
Connection: closed
x-amz-request-id : 80000000000000030005c8caec96d65b
Date : Tu, 21 Jan 2021 14:08:56 GMT
```

\
&#x20;


# DELETE service replication

Deletes replication configuration for the specified bucket.

### Requests <a href="#kanchor57" id="kanchor57"></a>

#### Syntax <a href="#kanchor58" id="kanchor58"></a>

```
DELETE /?replication HTTP/1.1
Host: <bucket>.<host>
Date: <date>
Authorization: <authorization_string>
```

#### Parameters <a href="#kanchor59" id="kanchor59"></a>

| Parameter | Description                             |
| --------- | --------------------------------------- |
| `bucket`  | <p>Bucket name.</p><p>Type: string.</p> |

#### Headers <a href="#kanchor60" id="kanchor60"></a>

This implementation uses only common request headers.

### Responses <a href="#kanchor61" id="kanchor61"></a>

#### Headers <a href="#kanchor62" id="kanchor62"></a>

This implementation uses only common response headers.

#### Body <a href="#kanchor63" id="kanchor63"></a>

Empty.

#### Examples <a href="#kanchor64" id="kanchor64"></a>

Sample request

Deletes replication configuration of the bucket `test`.

```
DELETE/?replication HTTP/1.1
Host: test.os.zrh1.flow.swiss
Date: Tu, 18 Jan 2021 14:08:55 GMT
Authorization: <authorization_string>
```

Sample response

```
HTTP/1.1 200 OK
Transfer-encoding : chunked
Server : nginx/1.8.1
Connection: closed
x-amz-request-id : 80000000000000030005c8caec96d65b
Date : Tu, 21 Jan 2021 14:08:56 GMT
```


# App Engine

Platform-as-a-Service

## Introduction

[Flow App Engine](https://flow.swiss/app-engine) is a comprehensive Platform as a Service (PaaS) that supports Docker, Node.js, PHP, Go, Ruby, Python, .NET, and Java apps. It is based on the [Virtuozzo Application Platform](https://www.virtuozzo.com/application-platform-docs/), previously known as Jelastic. With the intuitive control panel and powerful API, it's simple to deploy, manage, and scale web apps.

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>Quickstart</strong></mark></td><td></td><td>Just the essentials to go from zero to working in minutes.</td><td><a href="/pages/KPkMs8aNZZ3s7em8jvdx#quickstart">/pages/KPkMs8aNZZ3s7em8jvdx#quickstart</a></td></tr><tr><td><mark style="color:blue;"><strong>Pricing</strong></mark></td><td></td><td>Get all the details about App Engine product pricing</td><td><a href="/pages/h92uzqbHH7rYV1Zvc1FW">/pages/h92uzqbHH7rYV1Zvc1FW</a></td></tr></tbody></table>


# Accounts

## Quickstart

1. Start by navigating to "App Engine" > "Overview" in the [Control Panel](https://my.flow.swiss).<br>
2. Click the **Activate Account** button and confirm with **Yes, activate**. Deploying an App Engine account takes a few minutes.<br>
3. Click the **(+) Plus** button in the "Environments" tab. This action opens the App Engine UI where you can perform all further steps.<br>
4. From this point, reference is made to the Virtuozzo Application Platform documentation, such as [how to deploy an application](https://www.virtuozzo.com/application-platform-docs/getting-started/#deploy-application) and much [more](https://www.virtuozzo.com/application-platform-docs/).


# Mac Bare Metal

Mac-as-a-Service

[Flow Mac Bare Metal](https://flow.swiss/mac-bare-metal) is an enterprise-class Mac cloud platform. With the easy-to-use control panel, it is possible to deploy, manage, and scale dedicated, bare-metal Apple Mac devices. It is a fully automated bare-metal Mac cloud platform with API support. It comes standard with advanced networking features such as private network, firewall, and VPN at no additional cost. And last but not least, every Mac comes with Lights Out Management (LOM) functionality for easy remote management.

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><a href="/pages/-MM-eTVTR-1DSBDaRLuo#quickstart"><mark style="color:blue;"><strong>Quickstart</strong></mark></a></td><td></td><td>Just the essentials to go from zero to working in minutes.</td></tr><tr><td><a href="/pages/-M27lQADnAFJ1lVrV_dM"><mark style="color:blue;"><strong>How-tos</strong></mark></a></td><td></td><td>How to accomplish specific tasks in detail.</td></tr><tr><td><a href="/pages/fqx0idhxchJa31LZpGbo"><mark style="color:blue;"><strong>Pricing</strong></mark></a></td><td></td><td>Get all the details about Mac Bare Metal product pricing.</td></tr></tbody></table>


# Devices

Mac Bare Metal devices are genuine, dedicated Apple Mac devices that are delivered with the latest stable macOS version. They can be provisioned on-demand in a few steps.

## Quickstart

1. Start by clicking the **Wizard** button in the [Control Panel](https://my.flow.swiss). Click **Create Device** in the Mac Bare Metal ta&#x62;**.**<br>
2. Name your device.<br>
3. Choose the configuration (flavor) for your device that determines its Apple Mac platform (Intel or Apple Silicon), Processor cores, Memory, Storage, and price.<br>
4. Confirm the network topology. By default, each device is assigned an [Elastic IP](#user-content-fn-1)[^1] address and is reachable via the Internet. If you wish for the device to be reachable only internally, uncheck the **IPv4** checkbox.<br>
5. Specify a password for the default user who has root privileges. The default user is named "Flow". Click **Finish**. Deploying a device takes a few seconds.<br>
6. Once the device is created, follow the detailed guides on how to connect to the device via [Remote Desktop](/products/mac-bare-metal/how-to/connect-via-remote-desktop) or [SSH](/products/mac-bare-metal/how-to/connect-via-ssh).

## Important to know

* Billing of Mac devices also takes place when the **device is turned off**. A device in a stopped state continues to reserve the dedicated Mac device, and therefore charges incur until you delete it.<br>
* For security reasons, only two TCP ports are open from the outside. These are ports 5900 (VNC) and 22 (SSH). The port settings can be restricted or extended in the Control Panel via Mac Bare Metal > Networking > Security Groups > Default.

## **Security recommendations**

A device with an Elastic IP address is directly reachable from the Internet. We strongly recommend the following measures:<br>

* **Restrict the open ports to known source IP addresses.** In **Mac Bare Metal > Networking > Security Groups > Default**, limit ports 5900 (VNC) and 22 (SSH) to the IP addresses or ranges you actually connect from, for example your office or VPN exit IP. Leaving VNC open to the entire Internet is the single largest risk factor for a hosted Mac.
* **If you have no fixed source IP address**, do not open port 5900 to the Internet. Instead, connect through a VPN or a jump host, or use a remote desktop tool that does not require an inbound port, such as AnyDesk.
* **Keep macOS up to date.** Install security updates promptly and enable automatic updates. Screen Sharing in particular has been affected by a critical authentication bypass (CVE-2026-65400), fixed in macOS 14.8.9, 15.7.9 and 26.6.1. Devices that are exposed to the Internet and not up to date can be compromised without any credentials.
* **Use strong credentials.** Choose a strong password for the default user "Flow", and prefer SSH key authentication over password authentication for port 22.
* **Disable services you do not need.** If you only work via SSH, turn off Screen Sharing under **System Settings > General > Sharing** and remove port 5900 from the security group.

[^1]: Publicly-accessible static IP address


# How-to


# Connect via Remote Desktop

### <img src="/files/vYpz7DF9eGZP1HKs2CrN" alt="" data-size="line"> AnyDesk (recommended)

For the best remote desktop experience to a cloud-hosted Mac device, we recommend the third-party tool [AnyDesk](https://anydesk.com/), which is optimized for performance and includes client software for all major operating systems and platforms, like Windows, Linux, FreeBSD, ChromeOS, macOS, iOS, Android. With AnyDesk, you can easily connect from any other operating system.

{% tabs %}
{% tab title="Step 01" %}

* Use the web console in the Control Panel to log in to your cloud-hosted Mac device. Please note that the default keyboard input source is set to U.S. English.
* In the menu bar, click the Kandji logo, hover over Self Service, and choose Open. Alternatively, you can find the Self Service App in the Applications folder.<br>

  <figure><img src="/files/8ZVM7KdyYZJF8ahBzlNE" alt=""><figcaption></figcaption></figure>
* Within Self Service, find the AnyDesk App and click on Install. As soon as the installation is completed, that button will change to Open.
* Open AnyDesk and complete the App setup. Finally, it is recommended to set a password for unattended access.
  {% endtab %}

{% tab title="Step 02" %}
On your local computer, download + install the appropriate AnyDesk client by using the following link: <https://anydesk.com/en/downloads>

For example, if you connect from a Windows PC, use the AnyDesk Windows client.
{% endtab %}

{% tab title="Step 03" %}
To establish the connection, use the AnyDesk Remote Desk ID of your cloud-hosted Mac device and enter it in AnyDesk on your local computer.
{% endtab %}
{% endtabs %}

### <img src="/files/gVHSxkOsjm33Ak8WeKFF" alt="" data-size="line"> macOS Screen Sharing

If you have a Mac and want to connect from it, it's even easier. You can use the macOS built-in "Screen Sharing" application and use the following information to connect to your Mac device on our platform. Please note that the default keyboard input source is set to U.S. English.

| Subject       | Content                        | Comment                                  |
| ------------- | ------------------------------ | ---------------------------------------- |
| Hostname / IP | 185.223...                     | *Public, Elastic-IP*                     |
| User          | Flow                           |                                          |
| Password      | \*\*\*\*\*\*\*\*\*\*\*\*\*\*\* | *macOS password set during the creation* |

###

### Microsoft Remote Desktop

Unfortunately, the macOS **does not support** the Microsoft Remote Desktop Protocol (RDP), so we recommend all Windows users to use AnyDesk (see above).


# Connect via SSH

To connect via SSH (Secure Shell), you can use any SSH client. Please note that SSH is **enabled by default** on all newly created Mac devices. You can use the following information to connect to your Mac device on our platform using the Terminal software (if it’s a Mac) or any other SSH client of your choice.

The general format of the ssh command is:

```
ssh username@IPAddress
```

For example, if your username is Flow (default) and your public, Elastic-IP address is 10.1.2.3, enter the following:

```
ssh flow@10.1.2.3
```

Enter your macOS password, then press Return.


# Change Display Resolution

By default, the display resolution is set to 720p (1280×720). There is an option to increase the resolution to 1080p (1920x1080). Currently, these are the only two resolutions we can offer. We are working on improvements in this matter.

1. Log in to your Mac device and open System Preferences
2. Go to Displays > Display > Resolution and click on Scaled
3. Switch between 720p or 1080p


# Connect local USB devices

In situations where you need to connect a local USB device (such as an iPhone) to your cloud-based Mac, we recommend the third-party software [USB Network Gate](https://www.eltima.com/products/usb-over-ethernet/) from Electronic Team, Inc.

With USB Network Gate you get to efficiently share multiple USB devices over Ethernet and connect to them on remote machines as if the devices were physically plugged into the computers regardless of the location or distance between them.

* The USB Network Gate Software can be tested for [14 days free of charge](https://www.eltima.com/products/usb-over-ethernet/)
* Available for the platforms: Mac, Windows, Linux, and Android
* [Documentation](https://electronicassist.freshdesk.com/support/solutions/44000587699)

### Installation and configuration

Install the software on your local machine first. When the installation has completed open USB Network Gate. In the top right corner you should be on the local tab where all USB devices connected to your machine will be displayed. Then Click on the Symbol right of the connect button of the device you want to share.

![](/files/k8ZDhRSQJL7Kk401iKdN)

In the newly opened window, choose "Connect to remote client", add the public Address of your Mac Bare Metal unit, a free Port (17831 as an example) and we recommend adding "Encryption" and "Compression". Then add a password if you chose an encrypted connection. Finish by clicking on "Share".

![](/files/wB9RBIaVKbhHK4MV4mow)

The configuration on the server side is now finished.

![](/files/TFwH7qlknN0xlatrJ8aF)

Now the appropriate Ports have to be opened. For this log in to my.flow\.swiss, go to "Mac Bare Metal", "Networking" and then "Security Groups". You can now edit the default security group or create a new one. Under rules click the (+) symbol and add ports:

* TCP 17831 (or whatever Port you chose)
* TCP 5473
* UDP 5474, 5475

![](/files/RVZiQF9orIxi63zL2RCk)

If you edited the default group it should look like this:

![](/files/MnPNtuqjRDopzwsPB68q)

Now change to your Mac Bare Metal unit and install the USB Network Gate. After the installation open the application. Choose the "Remote" register in the top right. In the top bar click on "Device", then "Add device".

![](/files/Y7D0YPjx05AiReUam9HE)

In the new window choose "Allow callback connection", enter the port number 17831 (or whatever you chose) and click on "Add".

![](/files/Rqfwg9YxMDKltQqfy3k2)

You should now see an entry under "Callback connections" with an unknown device. Click on connect on the right and enter the specified password when asked.

![](/files/utfffgbVP98gf80Wx6UL)

Your local USB device should now connect to your Mac Bare Metal unit.

![](/files/tO4Z7lg5Kvz2zOaLApaY)


# Resources


# Deprovisioning

## How does deprovisioning work?

As soon as a customer deletes a Mac device from his account, it is automatically moved into the so-called "Decomission" pool and then completely deleted via the MDM server using an [Erase](https://developer.apple.com/documentation/devicemanagement/erase_a_device) command. With this action (only possible via MDM) everything is completely deleted. Even the disk partition scheme and all including volumes are securely erased. Afterward, a fresh macOS installation is automatically initiated and then moved to the general "Available" pool. This cycle ensures that no residual information and data remains from the previous customer.


# CI Engine

Managed macOS CI Platform

[Flow CI Engine](https://flow.swiss/ci-engine) is a managed cloud service using the latest Apple Silicon Mac devices. Perfect for Continuous Integration and Continuous Delivery (CI/CD), it seamlessly integrates with CI pipeline solutions. Ideal for developer teams and CI/CD providers seeking a scalable, fast, secure, and managed macOS cloud platform compliant with Apple’s Software License Agreement.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/41ue78VpOZdn4ygASwAx"><mark style="color:blue;"><strong>Quickstart</strong></mark></a></td><td></td><td>Just the essentials to go from zero to working in minutes.</td><td></td></tr><tr><td><a href="/pages/qEFa6RW2zMxy1nmIoQC3"><mark style="color:blue;"><strong>How-tos</strong></mark></a></td><td></td><td>How to accomplish specific tasks in detail.</td><td></td></tr><tr><td><a href="/pages/3pG2YImswIGdQ9Hu1lC2"><mark style="color:blue;"><strong>Pricing</strong></mark></a></td><td></td><td>Get all the details about CI Engine product pricing.</td><td></td></tr></tbody></table>


# Subscriptions

In order to start using CI-Engine you will need to setup an Essential or Professional subscription. Within this subscription you will be able to setup the Integration with your CI-provider.

### Quickstart

1. Start by navigating to CI-Engine > [Subscriptions](https://my.flow.swiss/#/ci-engine/subscriptions).
2. Select the plan for your subscription which best suits your needs.
3. Name your subscription.
4. After the subscription has been created, you can adjust its [concurrency](/products/ci-engine/resources/runners-and-concurrency#changing-concurrency-limit) to your needs.
5. Once you are ready, proceed by creating an Integration with your CI-provider.
   1. [How-to: Setup a Buildkite Integration](/products/ci-engine/how-to/setup-buildkite-integration)
   2. [How-to: Setup a GitHub Actions Integration](/products/ci-engine/how-to/setup-github-actions-integration)

You are ready to build! Simply trigger the pipeline at your CI-provider and check the state of your runners on the detail page of your subscription.


# How-to


# Setup GitHub Actions Integration

To integrate GitHub Actions with your CI-Engine subscription, follow the steps below:

1. Navigate to CI-Engine > [Integrations](https://my.flow.swiss/#/ci-engine/integrations).
2. Click on the **(+) Plus** sign.
3. Choose the subscription for which you create the integration.
4. Choose **GitHub Actions** as the CI-provider.
5. Choose a global or custom image for your runners to use.
   1. You can always [change the image of the integration](/products/ci-engine/how-to/change-image-of-integration) later.
6. Configure the runners to connect to your repository.
   1. Setup a [**PAT** at GitHub](#personal-access-token-configuration).
   2. Provide the **full repository name** which you’re creating the integration for and you have given the PAT access to. Make sure the repository name is formatted as follows: `<repository-owner>/<repository-name>`.
   3. Define a **runner timeout**, after which a runner without an active build job will be terminated.
7. Give your integration a name.
8. Configure a [**webhook at GitHub**](#webhook-configuration).
9. [Update the **runs-on** label](#workflow-configuration) in your GitHub Actions Workflow YAML to the string displayed in the wizard, which has the form `flow-runner-<random string>.`

Once you finished the steps above you are ready to build! Simply trigger the Workflow you just updated to run on CI-Engine and check the state of your runners on the detail page of your subscription.

#### Personal Access Token Configuration

For the runners to authenticate themselves, a [fine-grained Personal Access Token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens#creating-a-fine-grained-personal-access-token) needs to be provided. Create a new fine-grained PAT in your GitHub Developer settings and make sure to configure the token as follows:

1. Set the “Expiration” to **No expiration**
2. Under “Repository Access” select **Only selected repositories** and add the Repository which you’re creating the integration for.
3. Under “Permissions" add the repository permissions **Administration** and **Actions** and change "Access" to **Read and Write**. Note: This access will also enforce **Read** access for **Metadata**.

#### Webhook Configuration

To spawn the runners on demand you need to setup Webhooks in your GitHub pipeline:

1. In your GitHub repository, go to **Settings > Webhooks** and click on the **Add Webhook**-Button
2. Configure the **Payload URL** and the **Secret** that are provided in the Wizard-Step. Alternatively you can find this information on the details page of your integration by clicking on **(**•••**) More** button and **View Webhook Config**.
3. Under **Which events would you like to trigger this webhook?** select **Let me select individual events** and enable **Workflow jobs**. This event webhook is **required** for the runners to spawn correctly.

#### Workflow Configuration

In order for GitHub to know which runner can pick up a job you need to specify [runs-on](https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idruns-on) label in your GitHub Actions Workflow. This string needs to be set to the **Runner Label** provided in the Wizard-Step. Alternatively you can find this information on the details page of your integration. Make sure that all jobs have only this Runner Label configured on the [runs-on](https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idruns-on) label or else it cannot be guaranteed that the job gets correctly picked up by the runner.


# Setup Buildkite Integration

To integrate Buildkite with your CI-Engine subscription, follow the steps below:

1. Navigate to CI-Engine > [Integrations](https://my.flow.swiss/#/ci-engine/integrations).
2. Click on the **(+) Plus** sign.
3. Choose the **subscription** for which you create the integration.
4. Choose **Buildkite** as the CI-provider of the integration.
5. Choose a global or custom image for your runners to use.
   1. You can always [change the image of the integration](/products/ci-engine/how-to/change-image-of-integration) later.
6. Configure the runners to connect to your repository.
   1. Setup an [**Agent Token** at Buildkite](#agent-token-configuration)
   2. Define a runner timeout, after which a runner without an active build job will be terminated.
7. Give your integration a name.
8. Configure a [**webhook** at Buildkite](#webhook-configuration)
9. Add the displayed public [SSH key to your repository](#ssh-configuration).

Once you finished the steps above you are ready to build! Simply trigger the Workflow you just updated to run on CI-Engine and check the state of your runners on the detail page of your subscription.

#### Agent Token Configuration

The [agent token](https://buildkite.com/docs/agent/v3/tokens#create-a-token-using-the-buildkite-interface) is used to authenticate and connect the agent on each new runner to your pipeline. We support both clustered and unclustered tokens. However we strongly suggest the usage of a clustered agent token as this is the new default for Buildkite agent tokens. You can find out more about unclustered Buildkite agent tokens [here](https://buildkite.com/docs/agent/v3/unclustered-tokens).

#### Webhook Configuration

To spawn the runners on demand you need to setup Webhooks in your Buildkite pipeline:

1. In your Buildkite dashboard, go to **Settings > Notification Services** and click on the **Add**-Button for webhooks.
2. Configure the **Webhook URL** and the **Token** that are provided in the Wizard-Step. Alternatively you can find this information on the details page of your integration by clicking on **(**•••**) More** button and **View Webhook Config**.
3. Configure the **Webhook Notifications** by selecting the Events **job.scheduled** and **job.finished**. These Events are **required** for the runners to spawn correctly.

#### SSH Configuration

To give the runner access to clone your repository during the jobs you need to add the SSH public key that is provided on this step to your git provider. Most providers support a **deploy key** that can be used for this purpose. For more instructions you can follow the official documentation of your provider:

* [GitLab](https://docs.gitlab.com/ee/user/project/deploy_keys/#create-a-project-deploy-key)
* [GitHub](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/managing-deploy-keys#set-up-deploy-keys)
* [BitBucket](https://confluence.atlassian.com/bitbucketserver/ssh-access-keys-for-system-use-776639781.html#SSHaccesskeysforsystemuse-AddanSSHaccesskeytoeitheraprojectorrepository)


# Customise Image

If our global images don’t meet your requirements, you can customise them, creating a custom image specific to your needs.

Note: This feature is only available to Professional subscriptions. If you are currently on an Essential subscription please upgrade to Professional first. To do this, navigate to the details page of your subscription, click on the dot-menu and on “Upgrade Subscription”.

To customise a global image follow the instructions below:

1. Navigate to the details page of your Professional subscription.
2. Open the tab **Custom Images**.
3. Click on the **(+) Plus** sign on the right side, which will open the wizard.
4. Choose the global image you wish to customise.
5. Enter a **name** and a **description** for the custom image.
6. Click on **Create**.
   1. We will get the image ready, this will take a few minutes. You can see it’s status in the **Custom Images** tab. Once it is in the status **Customising** it is ready for you to make your changes.
7. [Connect to the runner](/products/ci-engine/how-to/enable-debug-mode#connect-to-runner) of your custom image.
8. Make your changes to the image. Please have a look at [important information](/products/ci-engine/resources/custom-images#important-information) on custom images.
9. Disconnect from the runner.
10. Navigate to the details page of your Professional subscription.
11. Open the tab **Custom Images**.
12. On the image you just finished customising, click on the **(**•••**) More** button.
13. Click **Finalize**, which will save the changes made to the image and make it ready for use.

Once the custom image is **Available** it can be chosen while creating a new integration or you can change the image of an existing integration.


# Enable Debug Mode

### Debug Mode

Runners can be started in debug mode, in which case we will keep them running for 12 hours. During this time you can connect to the runner via SSH or VNC.

#### Integration Debug Mode

Debug mode can be enabled for a whole integration. Then every runner of that integration will be started in debug mode. To enable debug mode for the whole integration:

1. Navigate to the details page of your integration.
2. Click on **(**•••**)** **More** and **Change Settings**.
3. Toggle the **Debug mode** setting.

To disable debug mode simply follow the steps above again and toggle the **Debug mode** setting off.

#### Runner Debug Mode

Debug mode can be enabled for a single runner. To enable debug mode for a runner:

1. Navigate to the details page of your subscription.
2. Select the tab of **Active Runners**.
3. Click on the **(**•••**)** **More** of the runner you would like to debug and then on **Enable Debug Mode**.

To disable debug mode simply click on **(**•••**)** **More** of the runner currently in debug mode and then **Disable Debug Mode**.

### Connect to Runner

To connect to the runner via VNC or SSH follow these steps in the wizard:

1. Navigate to the details page of your subscription.
2. Open the **Active Runners** tab.
3. On the runner you wish to connect to, click on **(**•••**)** **More**.
4. Click either on **Connect with VNC** or **Connect with SSH**.
5. Open Cloudflare Tunnel
   1. Either run the cloudflare daemon in docker or locally by copying the command displayed in the wizard.
6. Connecting via VNC
   1. Connect to your runner with your preferred VNC application using the address and credentials provided in the wizard.
7. Alternatively to step 6: Connecting via SSH
   1. Download the SSH private key to authenticate yourself with the runner. Copy the SSH command from the wizard and adjust the path to your private key file that you saved before.


# Change Image of Integration

In order to change the image runners use within your Integration follow the steps below:

1. Navigate to the details page of your integration.
2. Click on the **(**•••**)** **More** button on the right.
3. Click on **Change Image**.
4. Select the new image for the integration.
5. Click on **Save**.

Note: It may take a few minutes for the changes to take effect. Runners your pipeline requests will remain scheduled while we get the new image ready.


# Resources


# Runners & Concurrency

### Runners

Once you have setup an integration with your CI-provider, your build-jobs will be processed by our runners as soon as the configured pipeline is triggered.

#### Active Runners

Runners which are currently scheduled to start, starting or running can be seen in the tab “Active Runners” on the subscription- or integration details.

#### Runner History

Past runners can be found in the “Runner History” tab on the details page of your integration.

#### Debug mode

You have the option to connect to your runner while it has the status “Starting” or “Running” for debugging purposes. For detailed instructions see [How-to: Enable Debug Mode](/products/ci-engine/how-to/enable-debug-mode).

#### Automatic Timeout

* Runners in debug mode will be timed out after 12 hours.
* Runners customizing an Image will be timed out after 12 hours.

### Concurrency

The concurrency limit is the amount of runners which can run in parallel. A subscription has a concurrency limit of one by default.

Be advised that the minimum commitment time for reducing the concurrency limit is 730 hours (\~1 month). You can only reduce your concurrency limit once the commitment time has passed.

#### Changing Concurrency Limit

1. Navigate to the details page of your subscription.
2. Click on the dot-menu of the subscription.
3. Click on “Change limits” in the action menu.
4. Set your “New Concurrency Limit”.


# Vanilla Images


# macOS 15.2 - Vanilla

A plain macOS Sequoia Image with no pre-installed software for you to customise.


# Golden Images


# macOS 15.2 - Golden

A macOS Sequoia Image with pre-installed build-tools, ready for you to use.

## macOS Version

* OS Version: macOS 15.2 (24C101)
* Kernel Version: Darwin 24.2.0

## Language and Runtime

* .NET Core SDK: 8.0.101, 8.0.204, 8.0.303, 8.0.405, 9.0.102
* Bash 3.2.57(1)-release
* Clang/LLVM 15.0.0
* Clang/LLVM (Homebrew) 18.1.8 - available on `$(brew --prefix llvm@18)/bin/clang`
* GCC 12 (Homebrew GCC 12.4.0) - available by `gcc-12` alias
* GCC 13 (Homebrew GCC 13.3.0) - available by `gcc-13` alias
* GCC 14 (Homebrew GCC 14.2.0\_1) - available by `gcc-14` alias
* GNU Fortran 12 (Homebrew GCC 12.4.0) - available by `gfortran-12` alias
* GNU Fortran 13 (Homebrew GCC 13.3.0) - available by `gfortran-13` alias
* GNU Fortran 14 (Homebrew GCC 14.2.0\_1) - available by `gfortran-14` alias
* Kotlin 2.1.0-release-394
* Node.js 22.13.0
* Perl 5.40.1
* Python3 3.13.1
* Ruby 3.3.7

## Package Management

* Bundler 2.6.3
* Carthage 0.40.0
* CocoaPods 1.16.2
* Homebrew 4.4.16
* NPM 10.9.2
* Pip3 24.3.1 (python 3.13)
* Pipx 1.7.1
* RubyGems 3.6.3
* Yarn 1.22.22

## Project Management

* Apache Ant 1.10.15
* Apache Maven 3.9.9
* Gradle 8.12

## Utilities

* 7-Zip 17.05
* aria2 1.37.0
* azcopy 10.27.1
* bazel 8.0.1
* bazelisk 1.25.0
* bsdtar 3.5.3 - available by 'tar' alias
* Curl 8.7.1
* Git 2.48.1
* Git LFS 3.6.1
* GitHub CLI 2.65.0
* GNU Tar 1.35 - available by 'gtar' alias
* GNU Wget 1.25.0
* gpg (GnuPG) 2.4.7
* jq 1.7.1
* OpenSSL 1.1.1w 11 Sep 2023
* Packer 1.11.2
* pkgconf 2.3.0
* Unxip 3.1
* yq 4.45.1
* zstd 1.5.6

## Tools

* AWS CLI 2.23.2
* AWS SAM CLI 1.132.0
* AWS Session Manager CLI 1.2.694.0
* Azure CLI 2.68.0
* Azure CLI (azure-devops) 1.0.1
* Bicep CLI 0.32.4
* Cmake 3.31.4
* CodeQL Action Bundle 2.20.1
* Fastlane 2.226.0
* SwiftFormat 0.55.4
* Xcbeautify 2.17.0
* Xcode Command Line Tools 16.2.0.0.1.1733547573
* Xcodes 1.6.0

## Linters

* SwiftLint 0.58.2

## Browsers

* Safari 18.2 (20620.1.16.11.8)
* SafariDriver 18.2 (20620.1.16.11.8)
* Google Chrome 132.0.6834.84
* Google Chrome for Testing 132.0.6834.83
* ChromeDriver 132.0.6834.83
* Selenium server 4.27.0

### **Environment variables**

| Name            | Value                                   |
| --------------- | --------------------------------------- |
| CHROMEWEBDRIVER | /usr/local/share/chromedriver-mac-arm64 |
| EDGEWEBDRIVER   |                                         |
| GECKOWEBDRIVER  |                                         |

## Java

| Version               | Environment Variable  |
| --------------------- | --------------------- |
| 11.0.25+9             | JAVA\_HOME\_11\_arm64 |
| 17.0.13+11            | JAVA\_HOME\_17\_arm64 |
| 21.0.5+11.0 (default) | JAVA\_HOME\_21\_arm64 |

## Cached Tools

### **Ruby**

* 3.1.6
* 3.2.6
* 3.3.7
* 3.4.1

### **Python**

* 3.11.9
* 3.12.8
* 3.13.1

### **Node.js**

* 18.20.5
* 20.18.1
* 22.13.0

### **Go**

* 1.21.13
* 1.22.10
* 1.23.4

## Rust Tools

* Cargo 1.84.0
* Rust 1.84.0
* Rustdoc 1.84.0
* Rustup 1.27.1

### **Packages**

* Clippy 0.1.84
* Rustfmt 1.8.0-stable

## PowerShell Tools

* PowerShell 7.4.6

### **PowerShell Modules**

* Az: 12.4.0
* Pester: 5.7.1
* PSScriptAnalyzer: 1.23.0

## Xcode

| Version        | Build    | Path                          | Symlinks                                                                                           |
| -------------- | -------- | ----------------------------- | -------------------------------------------------------------------------------------------------- |
| 16.2           | 16C5032a | /Applications/Xcode\_16.2.app | /Applications/Xcode\_16.2.0.app                                                                    |
| 16.1           | 16B40    | /Applications/Xcode\_16.1.app | /Applications/Xcode\_16.1.0.app                                                                    |
| 16.0 (default) | 16A242d  | /Applications/Xcode\_16.app   | <p>/Applications/Xcode\_16.0.0.app<br>/Applications/Xcode\_16.0.app<br>/Applications/Xcode.app</p> |
| 15.4           | 15F31d   | /Applications/Xcode\_15.4.app | /Applications/Xcode\_15.4.0.app                                                                    |

### **Installed SDKs**

| SDK                      | SDK Name             | Xcode Version |
| ------------------------ | -------------------- | ------------- |
| macOS 14.5               | macosx14.5           | 15.4          |
| macOS 15.0               | macosx15.0           | 16.0          |
| macOS 15.1               | macosx15.1           | 16.1          |
| macOS 15.2               | macosx15.2           | 16.2          |
| iOS 17.5                 | iphoneos17.5         | 15.4          |
| iOS 18.0                 | iphoneos18.0         | 16.0          |
| iOS 18.1                 | iphoneos18.1         | 16.1          |
| iOS 18.2                 | iphoneos18.2         | 16.2          |
| Simulator - iOS 17.5     | iphonesimulator17.5  | 15.4          |
| Simulator - iOS 18.0     | iphonesimulator18.0  | 16.0          |
| Simulator - iOS 18.1     | iphonesimulator18.1  | 16.1          |
| Simulator - iOS 18.2     | iphonesimulator18.2  | 16.2          |
| tvOS 17.5                | appletvos17.5        | 15.4          |
| tvOS 18.0                | appletvos18.0        | 16.0          |
| tvOS 18.1                | appletvos18.1        | 16.1          |
| tvOS 18.2                | appletvos18.2        | 16.2          |
| Simulator - tvOS 17.5    | appletvsimulator17.5 | 15.4          |
| Simulator - tvOS 18.0    | appletvsimulator18.0 | 16.0          |
| Simulator - tvOS 18.1    | appletvsimulator18.1 | 16.1          |
| Simulator - tvOS 18.2    | appletvsimulator18.2 | 16.2          |
| watchOS 10.5             | watchos10.5          | 15.4          |
| watchOS 11.0             | watchos11.0          | 16.0          |
| watchOS 11.1             | watchos11.1          | 16.1          |
| watchOS 11.2             | watchos11.2          | 16.2          |
| Simulator - watchOS 10.5 | watchsimulator10.5   | 15.4          |
| Simulator - watchOS 11.0 | watchsimulator11.0   | 16.0          |
| Simulator - watchOS 11.1 | watchsimulator11.1   | 16.1          |
| Simulator - watchOS 11.2 | watchsimulator11.2   | 16.2          |
| Simulator - visionOS 1.2 | xrsimulator1.2       | 15.4          |
| visionOS 1.2             | xros1.2              | 15.4          |
| visionOS 2.0             | xros2.0              | 16.0          |
| Simulator - visionOS 2.0 | xrsimulator2.0       | 16.0          |
| visionOS 2.1             | xros2.1              | 16.1          |
| Simulator - visionOS 2.1 | xrsimulator2.1       | 16.1          |
| Simulator - visionOS 2.2 | xrsimulator2.2       | 16.2          |
| visionOS 2.2             | xros2.2              | 16.2          |
| Simulator - visionOS 2.2 | xrsimulator2.2       | 16.2          |
| DriverKit 23.5           | driverkit23.5        | 15.4          |
| DriverKit 24.0           | driverkit24.0        | 16.0          |
| DriverKit 24.1           | driverkit24.1        | 16.1          |
| DriverKit 24.2           | driverkit24.2        | 16.2          |

### **Installed Simulators**

| OS           | Simulators                                                                                                                                                                                                                                                                                                                                                                    |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| iOS 17.5     | <p>iPhone 15<br>iPhone 15 Plus<br>iPhone 15 Pro<br>iPhone 15 Pro Max<br>iPhone SE (3rd generation)<br>iPad (10th generation)<br>iPad Air 11-inch (M2)<br>iPad Air 13-inch (M2)<br>iPad mini (6th generation)<br>iPad Pro 11-inch (M4)<br>iPad Pro 13-inch (M4)</p>                                                                                                            |
| iOS 18.0     | <p>iPhone 16<br>iPhone 16 Plus<br>iPhone 16 Pro<br>iPhone 16 Pro Max<br>iPhone SE (3rd generation)<br>iPad (10th generation)<br>iPad Air 11-inch (M2)<br>iPad Air 13-inch (M2)<br>iPad mini (6th generation)<br>iPad Pro 11-inch (M4)<br>iPad Pro 13-inch (M4)</p>                                                                                                            |
| iOS 18.1     | <p>iPhone 16<br>iPhone 16 Plus<br>iPhone 16 Pro<br>iPhone 16 Pro Max<br>iPhone SE (3rd generation)<br>iPad (10th generation)<br>iPad Air 11-inch (M2)<br>iPad Air 13-inch (M2)<br>iPad mini (A17 Pro)<br>iPad Pro 11-inch (M4)<br>iPad Pro 13-inch (M4)</p>                                                                                                                   |
| iOS 18.2     | <p>iPhone 16<br>iPhone 16 Plus<br>iPhone 16 Pro<br>iPhone 16 Pro Max<br>iPhone SE (3rd generation)<br>iPad (10th generation)<br>iPad Air 11-inch (M2)<br>iPad Air 13-inch (M2)<br>iPad mini (A17 Pro)<br>iPad Pro 11-inch (M4)<br>iPad Pro 13-inch (M4)</p>                                                                                                                   |
| tvOS 17.5    | <p>Apple TV<br>Apple TV 4K (3rd generation)<br>Apple TV 4K (3rd generation) (at 1080p)</p>                                                                                                                                                                                                                                                                                    |
| tvOS 18.0    | <p>Apple TV<br>Apple TV 4K (3rd generation)<br>Apple TV 4K (3rd generation) (at 1080p)</p>                                                                                                                                                                                                                                                                                    |
| tvOS 18.1    | <p>Apple TV<br>Apple TV 4K (3rd generation)<br>Apple TV 4K (3rd generation) (at 1080p)</p>                                                                                                                                                                                                                                                                                    |
| tvOS 18.2    | <p>Apple TV<br>Apple TV 4K (3rd generation)<br>Apple TV 4K (3rd generation) (at 1080p)</p>                                                                                                                                                                                                                                                                                    |
| watchOS 10.5 | <p>Apple Watch SE (40mm) (2nd generation)<br>Apple Watch SE (44mm) (2nd generation)<br>Apple Watch Series 5 (40mm)<br>Apple Watch Series 5 (44mm)<br>Apple Watch Series 6 (40mm)<br>Apple Watch Series 6 (44mm)<br>Apple Watch Series 7 (41mm)<br>Apple Watch Series 7 (45mm)<br>Apple Watch Series 9 (41mm)<br>Apple Watch Series 9 (45mm)<br>Apple Watch Ultra 2 (49mm)</p> |
| watchOS 11.0 | <p>Apple Watch SE (40mm) (2nd generation)<br>Apple Watch SE (44mm) (2nd generation)<br>Apple Watch Series 10 (42mm)<br>Apple Watch Series 10 (46mm)<br>Apple Watch Ultra 2 (49mm)</p>                                                                                                                                                                                         |
| watchOS 11.1 | <p>Apple Watch SE (40mm) (2nd generation)<br>Apple Watch SE (44mm) (2nd generation)<br>Apple Watch Series 10 (42mm)<br>Apple Watch Series 10 (46mm)<br>Apple Watch Ultra 2 (49mm)</p>                                                                                                                                                                                         |
| watchOS 11.2 | <p>Apple Watch SE (40mm) (2nd generation)<br>Apple Watch SE (44mm) (2nd generation)<br>Apple Watch Series 10 (42mm)<br>Apple Watch Series 10 (46mm)<br>Apple Watch Ultra 2 (49mm)</p>                                                                                                                                                                                         |
| visionOS 1.2 | Apple Vision Pro                                                                                                                                                                                                                                                                                                                                                              |
| visionOS 2.0 | Apple Vision Pro                                                                                                                                                                                                                                                                                                                                                              |
| visionOS 2.1 | Apple Vision Pro                                                                                                                                                                                                                                                                                                                                                              |
| visionOS 2.2 | Apple Vision Pro                                                                                                                                                                                                                                                                                                                                                              |

## Android

| Package Name               | Version                                                                                                                                                                                                                                          |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Android Command Line Tools | 16.0                                                                                                                                                                                                                                             |
| Android Emulator           | 35.3.11                                                                                                                                                                                                                                          |
| Android SDK Build-tools    | 35.0.0 35.0.1                                                                                                                                                                                                                                    |
| Android SDK Platforms      | <p>android-35-ext14 (rev 1)<br>android-35 (rev 2)<br>android-34-ext8 (rev 1)<br>android-34-ext12 (rev 1)<br>android-34-ext11 (rev 1)<br>android-34-ext10 (rev 1)<br>android-34 (rev 3)<br>android-33-ext5 (rev 1)<br>android-33-ext4 (rev 1)</p> |
| Android SDK Platform-Tools | 35.0.2                                                                                                                                                                                                                                           |
| Android Support Repository | 47.0.0                                                                                                                                                                                                                                           |
| CMake                      | 3.31.0                                                                                                                                                                                                                                           |
| Google Play services       | 49                                                                                                                                                                                                                                               |
| Google Repository          | 58                                                                                                                                                                                                                                               |
| NDK                        | <p>26.3.11579264<br>27.2.12479018 (default)</p>                                                                                                                                                                                                  |

### **Environment variables**

| Name                       | Value                                               |
| -------------------------- | --------------------------------------------------- |
| ANDROID\_HOME              | /Users/runner/Library/Android/sdk                   |
| ANDROID\_NDK               | /Users/runner/Library/Android/sdk/ndk/27.2.12479018 |
| ANDROID\_NDK\_HOME         | /Users/runner/Library/Android/sdk/ndk/27.2.12479018 |
| ANDROID\_NDK\_LATEST\_HOME | /Users/runner/Library/Android/sdk/ndk/27.2.12479018 |
| ANDROID\_NDK\_ROOT         | /Users/runner/Library/Android/sdk/ndk/27.2.12479018 |
| ANDROID\_SDK\_ROOT         | /Users/runner/Library/Android/sdk                   |


# Custom Images

### Custom Images

If a build-tool from the [Golden Image](/products/ci-engine/resources/golden-images#macos-15-golden) should be missing or you have specific requirements for the Image your runners are using, you can customise any of our Global Images in your Professional subscription.

For detailed instructions see: [How-to: Customise Image](/products/ci-engine/how-to/customise-image).

Once your Custom Image is available you can setup a new integration using it or change the image of an existing integration.

#### Important Information

* The Custom Image will be bound to your subscription and cannot be transferred or re-used between other subscriptions.
* One custom image is included in every Professional subscription, for details refer to our [pricing page](/platform/pricing).
* Customising an Image will occupy a single [concurrency](/products/ci-engine/resources/runners-and-concurrency#concurrency) of your subscription, until you finalised the image.
* Do not pre-install any other agents of your CI-provider as they might conflict with our runners.
* Do not update the macOS of the Image as it might become incompatible with CI-Engine.
  * If you have a specific need for an updated macOS version please contact our [support](https://flow.swiss/contact/#support).


# Overview

Flow provides several command-line interfaces (CLIs) and application programming interfaces (APIs) for managing your resources. This section provides the reference materials for these offerings.

<table data-card-size="large" data-column-title-hidden data-view="cards"><thead><tr><th></th><th data-hidden></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td><strong>API</strong></td><td></td><td></td><td><a href="/pages/-MA-feawvLbOvuuXGDN2">/pages/-MA-feawvLbOvuuXGDN2</a></td><td><a href="/files/QwuEALplvvrPILiVgYQJ">/files/QwuEALplvvrPILiVgYQJ</a></td></tr><tr><td><strong>CLI</strong></td><td></td><td></td><td><a href="/pages/-MA-g2xLuB_P0YEopJ1e">/pages/-MA-g2xLuB_P0YEopJ1e</a></td><td><a href="/files/SppXclR5sDR0SaiXJyrL">/files/SppXclR5sDR0SaiXJyrL</a></td></tr><tr><td><strong>Terraform Provider</strong></td><td></td><td></td><td><a href="/pages/j1Kjksz9EoVixMbPfEQK">/pages/j1Kjksz9EoVixMbPfEQK</a></td><td><a href="/files/JVHcmScWkgkgY9UmRgC0">/files/JVHcmScWkgkgY9UmRgC0</a></td></tr></tbody></table>


# API

The Flow API allows you to manage resources within the Flow cloud in a simple, programmatic way using conventional HTTP requests. The endpoints are intuitive and powerful, allowing you to easily make calls to retrieve information or to execute actions.

All of the functionality that you are familiar with in the Flow control panel is also available through the API, allowing you to script the complex actions that your situation requires. Our API has predictable resource-oriented URLs, accepts and returns JSON-encoded content and uses standard HTTP response codes.

### Documentation

The latest API documentation is available here:[ https://my.flow.swiss/#/doc/](https://my.flow.swiss/#/doc/)

### Authentication

Most of our requests are protected tough a user role management system and therefore require identification of the current user. This authentication system works by requesting an authentication token using username and password and sending the generated token with each request in the X-Auth-Token header.

To generate such a token you have to make the following request:

```
POST https://api.flow.swiss/v3/auth
{
	"username": "…",
	"password": "…"
}
```

```
{
	"token": "…",
	"id": 1,
	"username": "my@flow.swiss"
}
```

Please find here more details about the authentication endpoints and models:\
<https://my.flow.swiss/#/doc/authentication>


# Product Entities

### Mac Bare Metal

| ID | Product                |
| -- | ---------------------- |
| 11 | macmini.2018.6-16-256  |
| 12 | macmini.2018.6-32-512  |
| 13 | macmini.2018.6-64-1024 |
| 14 | macmini.m1.8-16-512    |
| 23 | Bare Metal Elastic IP  |

### Object Storage

| ID | Product        |
| -- | -------------- |
| 20 | Object Storage |

### Compute

| ID | Product    |
| -- | ---------- |
| 40 | b1.1x1     |
| 24 | b1.1x2     |
| 25 | b1.2x2     |
| 26 | b1.2x4     |
| 27 | b1.2x8     |
| 28 | b1.4x8     |
| 29 | b1.4x16    |
| 30 | b1.4x32    |
| 31 | b1.8x32    |
| 32 | b1.8x64    |
| 33 | b1.8x96    |
| 34 | b1.16x96   |
| 35 | b1.16x128  |
| 36 | b1.24x128  |
| 37 | b1.24x256  |
| 38 | b1.32x256  |
| 39 | b1.32x512  |
| 8  | Elastic IP |

### Kubernetes

| ID  | Product  |
| --- | -------- |
| 44  | k1.1x2   |
| 45  | k1.2x2   |
| 46  | k1.2x4   |
| 47  | k1.2x8   |
| 48  | k1.4x8   |
| 49  | k1.4x16  |
| 50  | k1.4x32  |
| 51  | k1.8x32  |
| 52  | k1.8x64  |
| 53  | k1.8x96  |
| 54  | k1.16x96 |
| 130 | k2.1x2   |
| 131 | k2.2x2   |
| 132 | k2.2x4   |
| 133 | k2.2x8   |
| 134 | k2.4x8   |
| 135 | k2.4x16  |
| 136 | k2.4x32  |
| 137 | k2.8x32  |
| 138 | k2.8x64  |
| 139 | k2.8x96  |
| 140 | k2.16x96 |


# Location Entities

### Location

| ID | Location |
| -- | -------- |
| 1  | ALP1     |
| 2  | ZRH1     |

{% hint style="info" %}
Mac Bare Metal is currently not available in ALP1
{% endhint %}


# CLI

Flow CLI allows you to interact with the Flow API via the command line. It supports most functionality found in the control panel. You can create, configure, and destroy Flow resources like Instances, Security Groups, Networks and more. We will add Mac Bare Metal and Object Storage support soon.

### Installation

The CLI is written in Go and the source code is public available: <https://github.com/flowswiss/cli>\
If you have GoLang installed, you can download and install the CLI with

```
go get github.com/flowswiss/cli/cmd/flow
```

otherwise, you will need to download the [Go](https://golang.org) executable for your system.

### Usage

After downloading you first of all need to authenticate the cli with your username and password. **Warning**: those credentials will be stored in `$HOME/.flow/credentials.json`

```
flow auth login --username 'USERNAME' --password 'PASSWORD'
```

alternatively you can also pass `--username USERNAME` and `--password PASSWORD` to every other command or set the environment variables `FLOW_USERNAME` and `FLOW_PASSWORD` to avoid the credentials getting stored in your home directory.

Once you have successfully logged in into your account, you can start manipulating things in your organization. As a first step it would be a good idea to upload your personal ssh key onto our platform. You will need this for every linux virtual machine you deploy.

```
flow compute key-pair create \
    --name 'My first key pair' \
    --public-key ~/.ssh/id_rsa.pub
```

Just to test things out, you can try creating an ubuntu virtual machine using the previously uploaded key pair:

```
flow compute server create \
    --name 'My first virtual machine' \
    --location 'ALP1' \
    --image 'ubuntu-20.04' \
    --product 'b1.1x1' \
    --key-pair 'My first key pair'
```

Further usage manuals can be found in the application itself using the `-h` or `--help` flags or in our usage documentation found [here](https://github.com/flowswiss/cli/blob/master/docs/usage.md).


# Terraform

Terraform is an Infrastructure-as-Code tool that lets you provision, and version cloud resources safely and efficiently. It enables automated and repeatable provisioning of Flow cloud resources.

<https://github.com/flowswiss/terraform-provider-flow>


