Skip to content
NebulaCtrldocs

Limits

Every hard limit in NebulaCtrl 0.39.0, with its exact value and what is refused or clamped when you reach it. Covers API requests, streams, rate limits, sizes and counts in configuration files, retention periods and timeouts.

A limit is a value the control plane or an agent enforces. This page lists each one, grouped by the area where you meet it. A value marked as a default is not a limit: you can change it, and it is listed so you know what applies when you set nothing.

Where a row names an HTTP status, the API answers with that status and a message naming the field. A 422 means the request is well formed but a value is out of range. A 409 means the request collides with the current state.

API and pagination

Limits on the size of a request and on how much one list call returns.

LimitValueApplies to
List page size, default50 itemsA list request that sets no limit.
List page size, range1 to 200 itemsA limit outside the range answers 422.
Build log page size, default200 linesA build log request that sets no limit.
Build log page size, range1 to 1,000 linesA limit outside the range answers 422.
SCIM list page sizeAt most 200 resourcesA count above 200 is clamped to 200.
Deployments-per-day report window1 to 400 daysA days value outside the range answers 422. The default is 371 days.
Request bodyAt most 1 MiBThe body of an API, SCIM or agent request. A larger body is refused with 413. The agent's log batches have their own limit, listed under Observability and retention.
Staged changes per batchAt most 500 itemsA batch of staged changes with more items, or none, answers 422.
Canvas positions per requestAt most 500 itemsA request that saves more canvas positions answers 422.

Live streams

Limits on the server-sent event streams that feed the console and the log views. The deployment stream, the environment log stream and the build log stream share one set of limits. The organization event stream has its own.

LimitValueApplies to
Open log, build log and deployment streamsAt most 4 per user or API tokenA fifth stream opens, sends one refused: comment and closes.
Log, build log and deployment stream lifetime15 minutesThe server ends the stream. The console reconnects.
Log, build log and deployment stream heartbeatEvery 5 secondsThe server sends a comment frame so that proxies keep the connection open.
Log, build log and deployment stream re-authorizationEvery 30 secondsA revoked session or token, or a lost grant, ends the stream within 30 seconds.
Open organization event streamsAt most 8 per user or API tokenA ninth stream opens, sends one refused: comment and closes.
Organization event stream lifetime30 minutesThe server ends the stream. The console reconnects.
Organization event stream keep-aliveEvery 15 secondsThe server sends a comment frame so that proxies keep the connection open.
Organization event stream re-authorizationEvery 30 secondsA revoked session or token, or a lost grant, ends the stream within 30 seconds.
Console reconnect delay1 second, doubling to at most 30 secondsThe console waits this long before it reopens a stream that dropped.

Rate limits

Limits per client address on unauthenticated endpoints, including the ones that connect a cluster. Each bucket refills continuously. A request over the limit answers 429.

LimitValueApplies to
Sign-in start and callback20 requests at once, then 1 more every 3 secondsOne bucket per client address for both sign-in endpoints.
Agent enrollment and host scripts5 requests per minuteOne shared bucket per client address for agent enrollment and for the install, high-availability, Tailscale and CloudNativePG script requests.
Install progress reports60 requests per minuteOne bucket per client address for the progress reports an installing node posts.
Mesh registration5 requests per minuteOne bucket per client address for a machine that asks to join the WireGuard mesh.
Community template refresh1 refresh every 30 secondsOne bucket for the whole installation. A request while a refresh runs, or within 30 seconds of the last one, answers 429.

Services and processes

Limits that apply when you configure a service in the console or over the API. For the limits of a nebula.toml file, see the next section. For the model behind them, see processes.

LimitValueApplies to
Process port1 to 65,535The port of an http process, or of a worker process that declares one. A value outside the range answers 422.
Replicas0 or more, except a managed Postgres database, which takes 1 to 6A negative value answers 422. For any other service the API sets no upper bound. The console control stops at 50 and nebula.toml stops at 100. A Postgres database has one writer and up to 5 readers, so staging 0 or more than 6 instances answers 422.
Run-as user ID0 or moreA negative value answers 422.
Release command sizeAt most 8 KiB in totalThe combined length of every argument. A longer command answers 422.
Release command timeout1 to 3,600 secondsA value outside the range answers 422. The default is 300 seconds.
Deploy after entriesAt most 20The services and databases one service waits for, as set in the console or API. A longer list answers 422. See deploy order.
Dockerfile build targetAt most 128 charactersThe stage name must start with a letter or digit and use letters, digits, _, . or -. A name outside the shape answers 422.
Retired releases kept per service3Older retired releases are removed from the cluster, so a rollback reaches the 3 newest.

nebula.toml

Limits on a service's nebula.toml file, as written in the guide. A file over any limit is invalid: the build fails and its log lists each problem with the key and line. Counts apply to the merged result after environment overrides.

LimitValueApplies to
File sizeAt most 64 KiBThe whole file. It is checked before it is parsed.
ProcessesAt most 20Entries in [processes].
Process name1 to 30 charactersLowercase letters, digits and -, starting with a letter: ^[a-z][a-z0-9-]{0,29}$.
MountsAt most 10Entries in [[mounts]].
Mount name1 to 30 charactersThe same pattern as a process name.
Mount sizeGreater than 0, at most 1 TiBThe initial size of a mount.
Environment variablesAt most 100Keys in env.
Environment variable keyUppercase letters, digits and _^[A-Z_][A-Z0-9_]*$. A key outside the shape is refused.
Build argumentsAt most 50Keys in [build] args.
String lengthAt most 4 KiBEach string value and each cmd or entrypoint word, counted in bytes. release_command is not held to this limit word by word; only its 8 KiB total applies.
Release command sizeAt most 8 KiB in totalThe combined length of every word of release_command.
Release command timeout10 seconds to 1 hourrelease_command_timeout. The default is 300 seconds when a command is set and no timeout.
Deploy after entriesAt most 20Slugs in [deploy] depends_on.
Port1 to 65,535A process port and a metrics port.
Replicas0 to 100A process replicas.
Run-as user ID0 to 2,147,483,647A process run_as_user.
Stabilization time0 to 600 secondsA process stabilization_seconds.
Drain time0 to 600 secondsA process drain_seconds.

Project config

Limits on a project config: the nebula.toml at the root of a project's config repository. Each service block in it is also a service file, so the service file limits above apply to it. A value over a limit is reported as a problem that names the setting.

LimitValueApplies to
File sizeAt most 256 KiBThe whole file. It is checked before it is parsed.
Services and databasesAt most 20 in totalEntries in [services] and [databases] together.
Service or database slug1 to 40 charactersLowercase letters and digits in single-hyphen-separated segments, starting with a letter. inputs is reserved.
Connection variables per serviceAt most 100Keys in a service's connection table.
Secrets per serviceAt most 100Keys in a service's secrets table.
Deploy after entriesAt most 20Slugs in a service's depends_on.
Postgres readers0 to 5readers in a Postgres database block.
Database initial sizeGreater than 0, at most 1 TiBsize in a database block.

Templates

Limits on a template file. A malformed template answers 422 and lists every problem it has. Previewing a template returns the problems in the response body instead.

LimitValueApplies to
File sizeAt most 256 KiBA template saved, previewed, or fetched from a URL.
Name1 to 60 charactersThe template's name.
Slug1 to 40 charactersLowercase letters, digits and -, starting with a letter.
Description1 to 280 charactersThe template's description.
TagsAt most 8Entries in tags.
Tag length1 to 24 charactersLowercase letters, digits and -, starting with a letter or digit.
ReadmeAt most 16 KiBThe template's readme.
InputsAt most 20Entries in inputs.
Input key1 to 64 charactersAn uppercase letter, then uppercase letters, digits and _.
Input label1 to 60 charactersAn input's label.
Input descriptionAt most 280 charactersAn input's description.
Services1 to 20Entries in services.
Service name1 to 30 charactersLowercase letters and digits in single-hyphen-separated segments, starting with a letter.
Processes per serviceAt most 10Entries in a service's processes.
Process name1 to 30 charactersLowercase letters, digits and -, starting with a letter.
Volumes per processAt most 5Entries in a process's volumes.
Volume name1 to 30 charactersLowercase letters, digits and -, starting with a letter.
Volume sizeAt most 1 TiBA volume's size.
Variables per serviceAt most 100Entries in a service's variables.
Port1 to 65,535A process port.
URL fetch time10 secondsFetching a template from a URL. A slower response is refused.
URL redirectsAt most 4Fetching a template from a URL. A fifth redirect is refused, and so is a redirect to a URL that is not https.
Community catalog refresh, automaticEvery hourThe control plane reloads the public community templates.
Community catalog downloadAt most 8 MiBThe compressed download of one refresh. A larger download is refused.
Community catalog download time30 secondsOne refresh download.
Community template fileAt most 256 KiBEach template file in the community catalog.

Compose import

Limits on an import from a Compose file. An import over a hard limit is refused with 422. Where a row says the extra items are skipped, the import goes on and lists a note.

LimitValueApplies to
Compose file sizeAt most 256 KiBA larger file is refused with 422.
Compose files foundAt most 20Files listed when the import searches the repository. The search covers the scan root and its immediate subfolders. Further files are not listed.
Subfolders searchedAt most 50The first 50 subfolders of the scan root, in alphabetical order. Hidden folders, node_modules and vendor are never searched.
Services per importAt most 20Services ticked for one import. More answers 422. In a file with more services, the first 20 are ticked and the rest wait for a second import.
Service slug1 to 30 charactersLowercase letters and digits in single-hyphen-separated segments, starting with a letter.
Volumes kept per processAt most 5Volumes beyond the fifth are not kept, and a note says their data is lost on redeploy.
Environment files readAt most 16Distinct env_file files read across the whole Compose file. A file that several services name counts once. The variables of further files are not imported.
Environment file sizeAt most 64 KiBEach env_file and each .env file. A larger file is not used.

Variables and files

Limits on variables, variable expressions and the files a service mounts.

LimitValueApplies to
Variable keyUppercase letters, digits and _, not starting with a digit^[A-Z_][A-Z0-9_]*$. A key outside the shape answers 422. The database enforces the same rule.
secret(N) length16 to 128 charactersThe N of a secret(N) expression. A value outside the range answers 422. The default is 32 characters.
Reference chain depthAt most 5References that point at values that are themselves references. Saving a variable does not check the chain. A deeper chain, or a cycle, is refused when a deployment compiles the variables, and the request answers 400.
File mounts per serviceAt most 20Variables mounted as files. More answers 422.

Databases

Limits on a database service and on the console's query tab.

LimitValueApplies to
Query run time5 secondsOne console query. A query over the limit is stopped.
Query rowsAt most 500Rows returned by one console query.
Query textAt most 16 KiBA longer query answers 422.
Result cellAt most 2 KiBA longer cell is cut and marked as cut.
Result sizeAt most 512 KiBOnce the cells of a result reach this size as JSON, the result stops growing.
Table listing time5 secondsThe table list the Data tab loads.
Concurrent console commandsAt most 4 per agentA command over the limit is answered at once with a busy result and is not queued.
Database name1 to 63 charactersThe name in a create request. A name outside the range answers 422.
Database slugAt most 40 charactersThe slug derived from the name. A longer slug answers 422.
Postgres instances1 to 6The replica count of a Postgres database: one writer and 0 to 5 readers. A value outside the range answers 422.
Daily dump retention, default7 dumpsThe schedule a new database gets keeps its 7 newest dumps.
Point-in-time recovery prefixAt most 256 charactersThe archive prefix. It is a slash-separated path without spaces, backslashes or ... A longer prefix answers 422.
Restored service nameAt most 63 charactersThe name of the new service in a restore into a new service. A longer name answers 422.

Volumes and backups

Limits on volumes, their backups and restores.

LimitValueApplies to
Volume sizeGreater than 0A console volume, an environment override and the data volume of a new database. A size of 0 or less answers 422.
Backup schedules per volume and environment1A second schedule replaces the first.
Schedule retentionAt least 1 backupkeepLast. A value below 1 answers 422. Older succeeded backups of the schedule are deleted after each new one succeeds.
Schedule expression5 fields, evaluated in UTCMinute, hour, day of month, month and day of week. Descriptors, a seconds field and a time zone override answer 422.
Backup archive sizeAt most 1,250 GiBThe compressed archive of one volume. A larger archive is deleted after upload, no backup is recorded and the backup fails.
Backup download link15 minutesA signed download URL stops working after this time.
Restore into a new serviceWaits up to 2 hoursThe restore waits for the new service to start, which includes image pull, volume creation and any approval. It fails after that time.
Object store check15 secondsThe write, read and delete probe when you verify an object store. Adding or editing a store does not run it. A store that cannot finish the probe in this time is not verified, and the error is shown on the store.

Builds

Limits on builds from a git source.

LimitValueApplies to
Build run time30 minutesA build that runs longer fails.
Concurrent builds per clusterAt most 2A third build waits in the queue.
Wait for a pushed image15 minutesA trigger-only service checks every 20 seconds. The build fails with a message that the tag did not appear when the tag is still missing after 15 minutes.
Build log lineAt most 8 KiBA longer line is truncated.
Build log retention7 daysBuild log lines older than 7 days are deleted. The sweep runs hourly.

Deployments and approvals

Limits on deployments, approvals and freezes, rollbacks and promotions and deploy order.

LimitValueApplies to
Approval wait24 hoursA request nobody decides expires. The deployment it gates is cancelled.
Deploy concurrency per projectAt least 1A project that sets it refuses a deployment while that many are in flight, with 409. A project that sets nothing has no limit.
Deploy freeze windowsAt most 28Windows in an organization's freeze policy. More answers 422.
Change set messageAt most 500 charactersA longer message answers 422.
Commits shown on an approvalAt most 50A longer comparison shows the 50 most recent commits.
Stage budget: pending1 minuteA deployment that stays in the stage longer is flagged with the delivery or stalled blocker, whichever names the cause.
Stage budget: admitted3 minutesThe same, for the admitted stage.
Stage budget: releasing30 minutesThe same, for the releasing stage.
Stage budget: starting10 minutesThe same, for the starting stage.
Stage budget: qualifying7 minutesThe same, for the qualifying stage.
Stage budget: activating4 minutesThe same, for the activating stage.
Stage budget: draining20 minutesThe same, for the draining stage.
Qualifying timeout5 minutesA release whose readiness is unmet after 5 minutes fails with the readiness blocker.
Volume claim timeout2 minutesA volume claim that stays unbound fails with the pvc-attachment blocker.
Route activation timeout2 minutesA traffic switch that keeps failing fails with the route-activation blocker.
Drain restart threshold3 restartsA container of the new release that has restarted 3 or more times during the drain window, or a new release with fewer ready replicas than desired. Traffic goes back to the previous release and the new release fails with the readiness blocker.
Agent offline afterMore than 1 minute without a heartbeatA deployment that has stalled on a cluster whose agent is offline gets the delivery blocker.

Preview environments

Limits on preview environments.

LimitValueApplies to
Idle lifetime1, 3 or 7 daysA preview with no push for this long is deleted. Any other value answers 422. The default is 3 days.

Domains

Limits on domains.

LimitValueApplies to
HostnameA valid RFC 1123 subdomain, at most 253 charactersA hostname outside the shape answers 422.
Unverified hostname reservation7 daysAn unverified public hostname stays reserved for this time. After it expires, the reservation can be replaced once a fresh DNS check allows it.
Tailnet device removal10 minutesThe control plane removes a recorded device that no domain reports and the operator has not removed within this time.

Clusters

Limits on clusters and their agents. For clusters that serve other clusters' domains, see edge clusters.

LimitValueApplies to
Clusters per organizationAt most 16The WireGuard address plan holds 16 clusters. Creating a 17th answers 409.
Enrollment token lifetime1 hourThe token printed when you create a cluster.
Join command lifetime300 seconds to 24 hoursA join command's ttlSeconds and the organization default. A value outside the range answers 422. The default is 1 hour.
Node labels per join commandAt most 20A longer map answers 422.
SSH port1 to 65,535The port of an install over SSH. The default is 22. A value outside the range answers 422.
SSH connection time15 secondsThe TCP connect and SSH handshake of an install. A slower host fails.
SSH install time20 minutesOne whole install over SSH. A longer run is treated as wedged and fails.
Agent update deadline, default10 minutesA running agent update that the new agent has not confirmed by then is rolled back automatically.
Agent update history20 attemptsThe attempts a cluster's agent history lists, newest first.
Cluster allocation windows1, 6 or 24 hoursThe windows the allocation chart accepts.

Observability and retention

Limits on logs and metrics and on how long telemetry is kept.

LimitValueApplies to
Telemetry retention7 UTC daysContainer logs, pod metrics, traffic samples and canvas metric samples. Older data is dropped hourly.
Cluster allocation retention7 daysThe samples behind the cluster allocation chart.
Service metrics window1h, 6h or 24h; 1h, 24h or 7d for the summaryThe window of the resource and traffic metrics takes 1h, 6h or 24h. The window of the metrics summary behind the console Metrics tab takes 1h, 24h or 7d. Any other value answers 422. The default is 1 hour.
Canvas metrics window30 minutesFixed. The canvas card shows up to 30 points in 60-second buckets.
Canvas cron historyAt most 7 runsThe runs a cron card lists, newest first.
Canvas Postgres status age2 minutesAfter 2 minutes without a report, the card shows no instance markers.
Cluster events in the runtime view50The most recent cluster events a service's runtime view returns.
Log shipping rate2,000 lines per second per agentAcross all pods of one cluster. Lines over the rate are dropped and counted.
Container log lineAt most 8 KiBA longer line is truncated.
Log batch bodyAt most 8 MiBThe body of one log batch from an agent. This is the one request body limit above 1 MiB.
Agent event batchAt most 200 eventsA batch with more events answers 422.
Service Logs tab buffer5,000 linesThe console keeps the newest 5,000 lines of the service Logs tab.
Log viewer buffer10,000 linesThe console keeps the newest 10,000 lines of the environment logs panel. The deployment detail card loads at most the first 5,000 lines of a build log (5 pages of 1,000) and, for runtime output, the latest 200 retained lines plus at most 1,000 live lines.

Notifications

Limits on notifications and their channels.

LimitValueApplies to
Channel label1 to 100 bytesThe label with surrounding whitespace trimmed. A label outside the range answers 422.
Delivery attemptsAt most 24After 24 failed attempts the channel gives up on that notification. A refusal that retrying cannot fix, such as an HTTP 4xx other than 408 or 429 or a host that resolves only to private addresses, gives up on the first attempt.
Retry delay30 seconds, doubling to at most 1 hourThe wait after each failed delivery.
Delivery time10 secondsOne send to a channel. A slower response counts as a failed attempt.
Slack message textAt most 3,000 bytesThe text of a section block, title and body together. Longer text is truncated and ends in ….
PagerDuty summaryAt most 1,024 bytesThe summary, which is the notification title. A longer summary is truncated and ends in ….

Git connections

Limits on an organization's git connections.

LimitValueApplies to
Connection label1 to 20 bytesA label outside the range, or one that starts with GitHub or Gist in any case, answers 422. A label already used in the organization answers 409.
Webhook bodyAt most 1 MiBA larger webhook delivery is refused.

Organizations and access

Limits on organizations, members and teams and API tokens.

LimitValueApplies to
Organization slug1 to 63 charactersLowercase letters and digits in single-hyphen-separated segments. A slug outside the shape answers 422.
Invitation lifetime7 daysAn invitation that is not accepted expires. Accepting it afterwards answers 409.
Browser session30 daysA session ends 30 days after sign-in, however active it is.
Sign-in flow10 minutesThe time between starting a sign-in and its callback.
API token lifetime1 day or morelifetimeDays. A value below 1 answers 422. A token created without it never expires.
API token project listAt least 1 projectA token limited to projects must name at least one. An empty list answers 422. Omit the list for a token that reaches every project.

Updates

Limits on updates of the control plane and the cluster agents.

LimitValueApplies to
Automatic update checkEvery 6 hoursThe control plane checks the release feed and the K3s channel feed.
Forced update checkOnce every 30 secondsA check requested within 30 seconds of the last one returns the last result without a new lookup.
Updater online window2 minutesThe console offers an update only if the updater polled within this time.
Update with no updater poll15 minutesA running update with no updater poll for this long is marked failed.
Update history10 updatesThe finished control plane updates the console lists.

On this page