Skip to content
NebulaCtrldocs
Concepts

Glossary

Definitions of the terms NebulaCtrl uses in the console, the API and these docs, each linked to the page that explains it.

The console, the API and these docs use each term below in exactly this sense. Terms are in alphabetical order.

TermDefinitionRead more
ActivationThe moment an environment's stable entry point starts sending traffic to a release, which completes a deployment's move from candidate to live.Deployments
AgentThe process in a cluster that receives desired state from the control plane, reconciles the cluster toward it, and reports nodes, workloads, logs and events back. Its connection is outbound only.How NebulaCtrl works
Agent updateA change of the image a cluster's agent runs, started by you. A new agent that never reports in within a fixed deadline is rolled back to the previous image.Update an agent
ApprovalA sign-off a protected environment requires before a deploy, rollback, promotion or change set takes effect.Change sets and approvals
Audit eventAn immutable record of a state-changing action, who did it and what changed, kept for accountability rather than debugging.Audit log
BlockerThe named reason a deployment is not progressing, such as capacity, image-pull or readiness.Deployment states
BuildOne attempt to produce an image from a service's Git source at one commit, run as a job inside the target cluster.Builds
BuilderHow a Git service's build turns its repository into an image: dockerfile, railpack, or auto to let each build decide.Builds
Canvas metricsThe few numbers a service's card on the canvas shows for its kind, read over the trailing 30 minutes.Logs and metrics
Change setOne person's staged edits to one environment, reviewed as a diff and applied together.Change sets and approvals
Cloudflare connectionAn organization's sealed Cloudflare API token, used to manage a domain's DNS records and issue DNS-01 certificates.Domains
CloudNativePGThe Kubernetes operator that runs every Postgres database service as a replicated cluster with health-checked failover and backups.Databases
ClusterA K3s cluster enrolled with the control plane and running one agent.Connect a cluster
Compose importTurning a repository's Docker Compose file into services, with hostnames and credentials rewritten to references. NebulaCtrl never runs the Compose file itself.Import from Compose
Control planeThe central service that stores the desired state and sends it to the agents. It serves the API and the console.How NebulaCtrl works
Database connectionA service variable named for a database, such as DATABASE_URL_PG_APP, whose value references that database's connection URL.Databases
Database serviceA service created from a database template: PostgreSQL, Valkey, MySQL or MongoDB.Projects and environments
DependencyAn edge from one service to another, which exists exactly when the first references the second or is linked to it. You never draw one by hand.Deployments
Deploy afterA service's explicit list of services and databases its deployments wait for.Deploy order
Deploy freezeA recurring weekly window during which production deployments are refused. Rollbacks stay allowed.Approvals and freezes
DeploymentOne attempt to make a release active in an environment, tracked through a state machine to health.Deployments
Desired stateThe full set of releases, processes and domains the control plane wants running in a cluster, at a given revision.How NebulaCtrl works
DomainA hostname routed to one service and process through a cluster's ingress, or through an edge cluster.Networking
Edge clusterA publicly reachable cluster that serves a domain whose service runs on another cluster of the same organization.Networking
EnvironmentA deployment target within a project, bound to one cluster, with its own namespace, variables and domains.Projects and environments
External resourceA dependency outside the cluster, such as a database or cache, whose connection variables are linked into services.Variables
File mountOne of a service's variables mounted as a read-only file at an absolute path.Release commands and files
Git connectionAn organization's authenticated link to GitHub, Forgejo or GitLab, used to list and clone repositories and receive webhooks.Git providers and registries
Master keyThe key in the control plane's .env file that seals every stored secret.Secrets
MeshThe organization's own WireGuard network that every node of every cluster joins.Networking
Mesh grantAn admin's permission for every workload of one environment to reach one process of a service in another environment.Networking
Mesh peerOne machine admitted to the mesh by one install grant, with an address and key that are never reused.Networking
NodeA single machine inside a cluster.Connect a cluster
NotificationA message to a member about an event they need to see, shown in their inbox and optionally sent to Slack or PagerDuty.Notifications
Object storeAn organization's S3-compatible bucket and credential that volume backups and database dumps are written to.Volumes
OrganizationThe top-level tenant. Every project, cluster, member and API token belongs to one.Projects and environments
PodA running instance of a process, as scheduled by Kubernetes. It appears in the runtime, logs and metrics views.Processes
Preview environmentA short-lived environment cloned from a base environment for one same-repository pull request.Preview environments
ProcessA named way of running a service's image, such as an HTTP process, a worker or a cron job.Processes
ProjectA named grouping of services that ship together. A project holds environments.Projects and environments
Project configA nebula.toml at the root of a project's config repository that declares its services and databases and how they connect.Project config
Project detectionThe read-only probe a build runs over a repository to decide whether Railpack can build it.Build detection
PromotionCreating a release in another environment from an existing release's image.Rollbacks and promotions
Protected environmentAn environment marked as production. Changes to it need an approval.Change sets and approvals
Public gatewayA node with a public IPv4 address that joins a cluster only to be its ingress on ports 80 and 443.Networking
RailpackThe build engine that produces an image from a repository's project files, with no Dockerfile.Build without a Dockerfile
ReaderA replica of a Postgres database that streams from the writer and serves reads only.Databases
Recommended clusterThe connected cluster a new or unbound environment runs on by default.Projects and environments
ReferenceA variable value of the form ${{ SERVICE.KEY }} that resolves, when a release is frozen, to another service's variable.Variable expressions
ReleaseAn immutable image digest plus a frozen configuration revision, numbered per service per environment.Deployments
Release commandA one-off command that runs with the new release's image before any process starts, typically a database migration.Release commands and files
Repository configA nebula.toml in a service's build context that configures the service from Git.Configure from nebula.toml
RestoreExtracting an archive back onto a volume, which always wipes the volume's current contents first.Volumes
RevisionThe increasing version number of an environment's desired state, which the agent uses to ignore stale updates.How NebulaCtrl works
RoleWhat a member or API token may do: owner, admin, deployer or viewer.Projects and environments
RollbackA deployment that makes a previously retired release active again.Rollbacks and promotions
ServiceA deployable unit within a project: an image plus one or more processes, deployed per environment.Projects and environments
SourceHow a service's image comes to exist: image, git, public-git or proxy.Projects and environments
Tailnet deviceThe device the Tailscale operator puts on your tailnet for one tailnet domain.Tailscale
TeamA named group of members that owns projects, set by hand or provisioned through SCIM.Members and teams
TemplateA YAML file describing a set of services, plus the inputs asked at install time.Templates
Trigger-onlyAn image source with a push trigger, so a push creates a release once the matching image appears in the registry.Deploy an image
UpdaterThe host service, nebula-updater, that runs the installer when you update the control plane from the console.Upgrade
VariableA key and value on a project, an environment or a service, optionally sealed as a secret.Variables
VolumePersistent storage attached to a process. A release that touches one needs a downtime acknowledgement.Volumes
Volume backupOne copy of a volume's data in an object store: an archive, or for a database a logical dump.Volumes
WriterThe one primary instance of a Postgres database, through which every write goes.Databases