Integrations
Integrations connect Opfield to accounts and hosts you already control. Start in Settings > Integrations. The available actions depend on your Opfield permissions, plan, and the credentials accepted by the external system.
Choose the connection
Section titled “Choose the connection”| Goal | Integration | Continue with |
|---|---|---|
| Create and operate provider VMs | Hosting providers: Proxmox VE, DigitalOcean, Hetzner Cloud, HOSTKEY, CloudBlast | Add a node |
| Select repositories for builds or source operations | Git hosting: GitLab, GitHub, generic Git | Docker builds, Pages Git deployments |
| Reach a named external host over SSH | SSH connections | Trusted host access and eligible hosting installation |
| Discover DNS zones and manage DNS for Domains and certificates | Cloudflare | Domains, Routes, and TLS |
Container registries are configured in the Docker area; Git integrations can also discover eligible registries. Email and webhooks have their own delivery settings. API and MCP connect tools to Opfield, rather than connecting Opfield to a hosting or Git account.
Three independent access checks
Section titled “Three independent access checks”- Opfield permissions: who may view or administer the connector and act on the selected resource.
- Connector selection: which accounts, repositories, zones, hosts, or allocation pools that connection covers.
- External credentials: what the provider token or remote operating-system account actually permits.
Being an Opfield system administrator does not give a Proxmox API token or SSH account more privileges. Conversely, an administrator token at the provider does not grant an Opfield user permission to every resource. See Permissions.
Connect, verify, and maintain
Section titled “Connect, verify, and maintain”Use a dedicated credential, verify TLS or SSH host identity, and restrict access before enabling automation. A successful connection test establishes connectivity and the capabilities that were checked; it does not prove that a VM was provisioned, a build deployed, or a DNS change reached clients.
Before rotating, disabling, or deleting a connection, identify dependent nodes, source bindings, registries, Domains, and certificates. Verify the replacement with the corresponding workflow. Do not paste provider tokens or private keys into chat, URLs, screenshots, or logs.