# Cloud providers

> Let Falak create servers on Hetzner Cloud, DigitalOcean, Vultr, Akamai/Linode or AWS Lightsail — add a credential, create a server, and what deletion does.

Source: https://falak.sh/docs/servers/cloud-providers/

With a provider credential, Falak creates the machine for you through the provider's API, passes the install command as cloud-init user data, and waits for the agent to enroll. The rest is identical to a [custom server](/docs/servers/connect-custom-server/).

## Supported providers

| Provider | API value | API endpoint (override) |
|---|---|---|
| Hetzner Cloud | `hetzner` | `https://api.hetzner.cloud/v1` (`FALAK_HETZNER_API_URL`) |
| DigitalOcean | `digitalocean` | `https://api.digitalocean.com/v2` (`FALAK_DIGITALOCEAN_API_URL`) |
| Vultr | `vultr` | `https://api.vultr.com/v2` (`FALAK_VULTR_API_URL`) |
| Akamai / Linode | `linode` | `https://api.linode.com/v4` (`FALAK_LINODE_API_URL`) |
| AWS Lightsail | `aws` | `https://lightsail.{region}.amazonaws.com` (`FALAK_LIGHTSAIL_API_URL`) |
| Custom | `custom` | none: you run the install command |

## Add a credential

1. Create an API token (or access key for AWS) with permission to create and delete servers at your provider.
2. Open **Settings → Cloud providers**, choose the provider and paste the credential. It is stored encrypted.
3. Falak loads the provider's regions, sizes and images (cached for an hour, `FALAK_PROVIDERS_CATALOG_TTL`).

Managing credentials needs `providers.manage` (owners and admins).

![Settings → Cloud providers: credentials per provider with their status.](./_images/settings-cloud-providers.png)

## Create a server

In **Servers → Create**, pick the provider, the credential, the region, the size and the image, then the type and software as usual. Falak creates the machine with the install command as user data. The server stays `creating` until the agent enrolls, then provisions automatically.

## Delete a server

Deleting a server in Falak also destroys the machine at the provider by default (`destroy_at_provider`, default `true` in the API). Custom servers are only forgotten: the agent keeps running until you remove it (`systemctl disable --now falak-agent`).

## Limits

- **AWS is Lightsail only**; EC2 is not supported. Use a custom server for EC2.
- Deleting an organization revokes its agents but does **not** destroy provider machines.
- Provider APIs are covered by unit and feature tests with faked responses, not yet by the end-to-end suite.
- HTTP calls to providers time out after 30 s (`FALAK_PROVIDERS_HTTP_TIMEOUT`) and retry rate limits and idempotent failures up to 3 times.

## Next steps
