BKE Bahriya Kubernetes Engine Start a 14-day trial

Register your cluster

A licence covers one cluster. Registration is how we know which one.

It happens before install.sh, on the machine that will become your first control-plane node. It needs no config.yaml, installs nothing, and touches no cluster — at this point there is no cluster to touch.

Place your token

Your licence token is shown against the licence in the console. Put it on the machine as a file:

install -d -m 0755 /etc/bke
printf '%s\n' 'YOUR-TOKEN' > /etc/bke/license
chmod 0600 /etc/bke/license

Mode 0600. Everything BKE fetches under licence uses this file as the credential, and it is never passed as a command-line argument — an argument is readable by every local user through /proc/<pid>/cmdline and survives in shell history long after the run.

Report first

curl -sL https://bke.maml.uk/register.sh | sh

With no flags it reports and changes nothing. It derives this machine’s fingerprint, asks us what this licence is currently bound to, and tells you what would happen. Read the output before going further — in particular, check that the control-plane endpoint it names is the one you intend to use.

Then bind

curl -sL https://bke.maml.uk/register.sh | sh -s -- --commit

This writes one file, /etc/bke/registration, recording when registration happened and the fingerprint it used. Re-running --commit on the same machine with the same licence is not an error and writes nothing further.

Binding is not self-service to undo. If this is not the machine that will be your first control-plane node, stop.

Why it takes no arguments

register.sh accepts --commit and nothing else. Every BKE script works this way: the default reports and changes nothing, and --commit acts. Two things it deliberately does not take:

No --token. The token is a credential, and credentials do not belong in argv. It is read from /etc/bke/license.

No --endpoint. The control-plane endpoint was set in the console when the licence was created, so we already hold it. Retyping it here could only introduce a disagreement between two records of the same thing. Later, when a cluster exists, apply.sh reads the endpoint back from the cluster’s own kubeadm-config and refuses if it does not match the licence — so the endpoint is proven, not declared.

What the fingerprint is

Registration derives a machine identity from the hardware UUID (/sys/class/dmi/id/product_uuid) and the machine ID (/etc/machine-id), and sends a hash of the two. Neither value is transmitted; only the hash is.

If either is unreadable, registration refuses rather than proceeding with a partial identity. A confident-looking hash derived from missing inputs would be worse than no hash at all, because nothing downstream could tell the difference.

This is also why registration cannot be run inside a container: a container has no DMI table of its own.

Until you register

Nothing licensed can be fetched. apply.sh is refused, with a message saying so and telling you to run this script. check.sh and install.sh still work — provisioning a node is not a licensed artefact — but a cluster cannot get its components until the licence has a machine.

If the machine changes

A rebuild of the first control-plane node changes its fingerprint, so the licence needs rebinding. That is a support request today rather than a console action. The same applies if you are moving a licence between clusters, which is a transfer and not something the node can decide for itself.