Microsoft Azure
The azure.* family (~60 workflows) covers AKS, ACR, virtual machines, container apps, networking and DNS, Front Door, Key Vault, and blob storage — run against your subscription through a connection you grant.
What the grant is
An Azure connection is a service principal: an app registration in your Entra tenant with role assignments scoped to the subscription or resource groups you choose. Orkestia authenticates as that principal; its authority is the role assignments you made, and removing them (or disabling the app registration) severs access immediately.
Setting it up
- Read the prerequisites of the workflow family you're targeting (
azure.aks.*,azure.acr.*, …) viaget_workflow_prerequisitesor the dashboard connection flow — the guide states the roles and scope required. - In your tenant: create an app registration + client secret (or the credential form the guide specifies), and assign only the listed roles at the narrowest scope that works — a resource group beats the whole subscription.
- Create the org-scoped connection in Orkestia; validation runs a read-only check first.
Contributor on the whole subscription is the Azure equivalent of handing over the keys — the prerequisites guide never asks for more than the family needs.What people run on it
- AKS operations —
azure.aks.*plus the cloud-agnostickubernetes.*family once a cluster credential exists. - Registry + compute —
azure.acr.*,azure.compute.*,azure.containerapps.*. - Edge + secrets —
azure.frontdoor.*,azure.dns.*,azure.keyvault.*. - Runner capacity — runners provisioned on Azure consume this connection.
Browse the full family at reference.orkestia.dev/azure.
Google Cloud (GCP)
Connect a GCP project to your organization and unlock the gcp.* workflow family — Compute, GKE, Cloud Run, Cloud SQL, BigQuery, and billing
Magalu Cloud
Connect Magalu Cloud to your organization and unlock the mgc.* workflow family — compute, Kubernetes, DBaaS, LBaaS, networking, object storage, and registry
