Register your cluster
A licence covers one cluster. Registration is how we know which one.
It happens before install.sh, on the machine that will become your first
control-plane node. It needs no config.yaml, installs nothing, and touches no
cluster — at this point there is no cluster to touch.
Place your token
Your licence token is shown against the licence in the console. Put it on the machine as a file:
install -d -m 0755 /etc/bke
printf '%s\n' 'YOUR-TOKEN' > /etc/bke/license
chmod 0600 /etc/bke/license
Mode 0600. Everything BKE fetches under licence uses this file as the
credential, and it is never passed as a command-line argument — an argument is
readable by every local user through /proc/<pid>/cmdline and survives in shell
history long after the run.
Report first
curl -sL https://bke.maml.uk/register.sh | sh
With no flags it reports and changes nothing. It derives this machine’s fingerprint, asks us what this licence is currently bound to, and tells you what would happen. Read the output before going further — in particular, check that the control-plane endpoint it names is the one you intend to use.
Then bind
curl -sL https://bke.maml.uk/register.sh | sh -s -- --commit
This writes one file, /etc/bke/registration, recording when registration
happened and the fingerprint it used. Re-running --commit on the same machine
with the same licence is not an error and writes nothing further.
Binding is not self-service to undo. If this is not the machine that will be your first control-plane node, stop.
Why it takes no arguments
register.sh accepts --commit and nothing else. Every BKE script works this way: the default reports and changes nothing, and --commit acts. Two things it deliberately
does not take:
No --token. The token is a credential, and credentials do not belong in
argv. It is read from /etc/bke/license.
No --endpoint. The control-plane endpoint was set in the console when the
licence was created, so we already hold it. Retyping it here could only introduce
a disagreement between two records of the same thing. Later, when a
cluster exists, apply.sh reads the endpoint back from the cluster’s own
kubeadm-config and refuses if it does not match the licence — so the endpoint
is proven, not declared.
What the fingerprint is
Registration derives a machine identity from the hardware UUID
(/sys/class/dmi/id/product_uuid) and the machine ID (/etc/machine-id), and
sends a hash of the two. Neither value is transmitted; only the hash is.
If either is unreadable, registration refuses rather than proceeding with a partial identity. A confident-looking hash derived from missing inputs would be worse than no hash at all, because nothing downstream could tell the difference.
This is also why registration cannot be run inside a container: a container has no DMI table of its own.
Until you register
Nothing licensed can be fetched. apply.sh is refused, with a message saying so
and telling you to run this script. check.sh and
install.sh still work — provisioning a node is not a licensed artefact — but a
cluster cannot get its components until the licence has a machine.
If the machine changes
A rebuild of the first control-plane node changes its fingerprint, so the licence needs rebinding. That is a support request today rather than a console action. The same applies if you are moving a licence between clusters, which is a transfer and not something the node can decide for itself.