Quickstart
Zero to first server in under ten lines — publicly-trusted endpoints, an API key, then the same create via curl, the CLI, and Terraform, side by side.
REST ≡ CLI ≡ provider ≡ MCP. IG1 is agentic-first: every operation is on the wire API, and the CLI, the Terraform/OpenTofu provider, and the MCP tool surface are generated from — and gated against — the same served OpenAPI contract. The guides below take you from zero to operating a project on each surface; the live references render each service's spec exactly as it serves it right now.
Zero to first server in under ten lines — publicly-trusted endpoints, an API key, then the same create via curl, the CLI, and Terraform, side by side.
What is drop-in, what is familiar, what is different by design and why, what does not exist yet — the fidelity table, the three-line S3 recipe, the m/r flavor-ratio inversion warning, and a week-1 runbook that ends each day in a verifiable state.
The two models end-to-end: OIDC/PKCE for humans (browser + device flow, refresh) and phase-26 scoped API keys for machines — tiers 0/1/2, server-side project scoping, rotation, the verbatim 403 contract.
One admin call provisions a customer end to end — a real Keystone project with the quota template, a Zitadel machine user, and its first scoped credential, atomic with rollback. The isolation model, the customer's first steps, the rotation rule.
The model a new user needs on day one: default-deny security groups (and the aws-like cutover template), floating IPs — public by default since 2026-08-26, so your instances can answer from the internet — the one-call L4 load-balancer composite with default-on health monitors and an internet-facing toggle, the .75 north-south edge (a hostname with TLS, zero IPv4) — and, since the flip, publicly resolving DNS: bring your domain, check the delegation, get a real certificate.
VM autoscaling groups with drain-first scale-in, cooldowns and manual-beats-alarm; Kubernetes worker autoscaling via annotations (manual scale refused while it owns the count); transitions-only alarms whose insufficient_data state is honest; and per-instance metrics.
One static binary for humans AND agents: install, contexts, the four login flows, every command group with examples, and the output contract — -o, --query, --watch, --dry-run, exit codes.
terraform-provider-ig1 (OpenTofu-compatible): provider config, the v1 resource inventory with runnable examples, import syntax, and the sensitive-state contract for credential, webhook and Barbican secrets.
The agent tool surface: 148 scoped, tiered, audited tools over streamable HTTP with per-caller Bearer passthrough — plus the quickstart (ig1 mcp config, ig1 agent init) and the in-repo skill.
Service minor-per-wave, OpenAPI as the contract, the SDK regen rule, the deprecation policy — and the parity gate (OpenAPI ≡ CLI ≡ MCP ≡ provider) that CI enforces, including the docs-don't-rot smoke.
The unified API gateway (phase 16). Proxies OpenStack — servers, volumes, networks, floating IPs, images, DNS, load balancers — and Kubernetes/KaaS cluster operations, plus scoped credentials, object storage, databases, alarms, per-instance metrics, the audit read, edge exposures and status, with per-caller tenant resolution. Fleet monitoring (/v1/monitoring/fleet and /v1/monitoring/alarms) is platform-admin only — your view of platform health is /v1/status.
The cluster factory (phase 22). Tenant-cluster lifecycle orchestration — Kamaji hosted control planes + CAPO worker provisioning, bootstrap and reconcile loops — plus day-2: scale, upgrade, deletion protection, worker autoscaling, and VM autoscaling groups.
The internal event bus (phase 23). Validated lifecycle event envelopes with ring-buffer polling reads, plus customer webhooks (W7) — producers and consumers are the in-cluster services; no north-south ingress by design.
Usage → rating → invoices (phase 21). Per-project Nova/Cinder/Neutron usage collection, in-service per-second rating, cost breakdown and budgets (W7), Stripe draft invoices, and the signature-verified Stripe webhook receiver.
The AI-agent tool surface (phase 27) speaks the Model Context Protocol over streamable HTTP — a tool manifest, not a REST API — so it publishes no /openapi.json to aggregate. Its guide and machine-readable server card live on this hub.
How spec fetching works. Each reference page loads its spec through
this service's same-origin proxy (/specs/<service>.json), which nginx resolves
per-request against the service's live, auth-exempt /openapi.json on its
in-cluster ClusterIP. The specs are fetched at request time — editing or
redeploying a service is immediately reflected here. The direct auth-exempt
ingress URLs (api,
factory,
billing)
also stay reachable; the proxy exists because the events bus deliberately has
no ingress, and the services' CORS allow-lists cover only the portal origins.
The Redoc runtime itself is vendored into this image (v2.5.3) — no runtime CDN.
The examples on the guide pages are validated against the source tree by
services/docs/tests/docs.smoke.js — the docs-don't-rot gate.