Getting started on Cloud
Sign up at app.kubebolt.io, verify your email, and connect your first cluster with the Add Cluster wizard.
This is the path from nothing to a cluster on screen at app.kubebolt.io. Nothing to host — you install one agent in your own cluster and it dials out. What Cloud is and how it differs from self-hosting is KubeBolt Cloud.
1. Create your account
Signing up creates a user and an organization in one step. Two ways in:
- Email and password. You provide your name, email, an organization name, a country, and a password of at least 8 characters. The email doubles as your login. Your organization name must be unique across KubeBolt Cloud — if it is taken, you get told exactly that.
- Google, Microsoft, or GitHub. One click, no password to choose.
2. Verify your email — before the wizard, not after
Connecting a cluster requires a verified email. The endpoint that issues the agent’s ingest token is gated on it. If you skip this step, the Add Cluster wizard stops at the token with “Verify your email before you can add a cluster” and there is nothing to paste. Issuing or rotating a token under Administration → Agents & Ingest → Agent Tokens passes the same gate.
If you signed up with Google, Microsoft or GitHub, your email is already verified — the provider vouched for it, and KubeBolt records that at signup. There is nothing to do; go to step 3.
If you signed up with email and password, KubeBolt sends a confirmation link and shows a banner across the top of the app until you click it:
- The link is valid for 24 hours from signup.
- Resend link in the banner sends a fresh one, throttled to one every five minutes.
- Verifying in another tab clears the banner here — the app re-checks whenever you focus the window.
- If the 24 hours lapse, the app locks behind a full-screen prompt and a resend cannot help (every link expires on the same deadline). Contact support to get the window reopened.
One honest edge: if the banner says “email delivery isn’t configured on this install” you are on a self-hosted deployment whose SMTP is unset, not on Cloud.
3. Connect your first cluster
A brand-new organization lands on a Home with no clusters. Two doors, both valid:
- Home → Connect cluster in the greeting header.
- Fleet → Connect cluster (
/fleet), the same button.
Both open the same menu with two paths: Import kubeconfig, for a cluster this backend can dial directly, and Install agent, for one it cannot. On Cloud the answer is always Install agent — our backend has no route into your network.
The wizard then:
- Issues an ingest token for your organization, scoped server-side. This is the step email verification gates. The token is shown once and you have to tick a box confirming you saved it.
- Prints a
kubectlcommand that creates the namespace and stores the token as a Secret in your cluster, so the token never travels inside the Helm command. - Prints the
helmcommand, with your cluster name, connection mode, RBAC tier and metrics topology already baked in. Run both against the cluster you want to connect.
The full option surface — RBAC modes, metrics sources, mTLS, cost — is Connecting Clusters. Use the wizard’s output rather than writing the command yourself; it carries every choice you made.
4. What “working” looks like
The moment you copy the Helm command, the wizard starts watching for a new cluster and shows it the second the agent registers. It watches for five minutes, then offers to keep waiting — closing the wizard stops the watch, not the connection.
Then, in order:
- The cluster appears in Fleet and in the cluster switcher.
- Home fills in: cluster count, pods, and — once the agent has shipped a few minutes of samples — spend and findings.
- The Overview dashboard renders live resources immediately; historical charts need the agent to accumulate a window first, so a fresh cluster looks thin for the first few minutes. That is normal, not a fault.
If the wizard times out, or the cluster shows up but the dashboards stay empty, go to Troubleshooting.
Next
- Kobi Copilot —
⌘J. On Cloud the AI is managed; there is no key to configure and no enabling step. - Home and Fleet — the two screens you will live in.
- Security and compliance — what lights up once you install a scanner.