Platform hierarchy and onboarding
The 0.2.0 hosted service uses a top-level Team tenant, presented as an organization in parts of the console. Projects, registered environments, members, and access records are scoped to that tenant.
Hierarchy
Organization / Team
├── Project
│ └── Registered environment binding
└── Members and project access
Environment
└── Approved Kubernetes namespace target
└── NexoProxy and generated resources
| Object | 0.2.0 purpose |
|---|---|
| Organization / Team | Tenant, membership, tier, and limits |
| Project | Pipeline configuration and deployment intent |
| Environment | Registered Kubernetes cluster identity with connect token and heartbeat state |
| Namespace | Namespaced location for Nexo custom resources and generated workloads |
The retired organization → team → cluster → project nesting is not the authoritative storage model.
Roles
Admin, manager, editor, and viewer roles provide tenant- or project-scoped capabilities. Server-side authorization is authoritative; a visible console action is not permission.
Onboarding
- Create or join the tenant.
- Create a project and pipeline intent.
- Register a Kubernetes environment.
- Install the exact 0.2.0 console-generated command.
- Verify Manager heartbeat and pinned component identity.
- Select an approved namespace.
- Deploy and verify the active graph.
No public standalone sandbox, trial, Docker workflow, or self-service artifact distribution is part of the 0.2.0 contract.
The retired app.nexo.io Manager Helm command with an inline token is not a valid 0.2.0
installation instruction; use the protected console-generated command and Secret path.
Targeting and reuse
Project and environment selectors determine eligibility. Namespace authorization remains separate. Legacy project cloning, YAML import/export, typed-name deploy confirmation, and “one Helm install equals one cluster” statements are not stable 0.2.0 contracts.
Limits
No immutable historical 0.2.0 commercial price sheet is archived in this documentation. Do not backport current unlimited-project, unlimited-cluster, team-count, or trial claims. The 0.2.0 pricing and entitlement page separates canonical tier vocabulary from verified runtime execution.