Your cloud
Create Spaces in your own AWS, Google Cloud or Modal account: connect it, check it, and clean up what Cua created there.
Create Spaces in your own AWS, Google Cloud or Modal account: connect it, check it, and clean up what Cua created there.
| Tool | Description |
|---|---|
cloud_status | List your clouds (AWS, Google Cloud, Modal): found credentials, the connected account and region, what each can run at what hourly cost, and what Cua created there. |
cloud_connect | Connect a cloud account Spaces can be created in. |
cloud_test | Check a cloud account without creating anything. |
cloud_disconnect | Forget a connected cloud account. |
cloud_sweep | Find and delete what Cua left in your clouds. |
List your clouds (AWS, Google Cloud, Modal): found credentials, the connected account and region, what each can run at what hourly cost, and what Cua created there.
Sandboxes and Spaces can run in the user's own cloud account: on="aws" (EC2), "gcp" (Compute Engine) or "modal" (Modal Sandboxes). EC2 and Compute Engine start one small VM per sandbox that runs the image with Docker; Modal runs one Modal sandbox. Either way the guest's cua-spacesd dials out to the cua.ai relay as a machine of the signed-in account (no inbound port), and the Space is that machine, relay:<machine>. Each cloud uses its own CLI sign-in; connect it first with cloud_connect (the user decides; it costs money in their account). Everything Cua creates is tagged cua-managed=true with this cua home's cua-owner and an expiry, recorded under the cua home, deleted with its sandbox, and ends itself at its expiry; cloud_sweep removes leftovers.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:cloud_status, in spaces:readonly; read-only, idempotent |
| Swift SDK | spaces.cloud.status(provider:) |
| Rust | cua_cloud::Clouds::status |
| Parameter | Type | Default | Description |
|---|---|---|---|
provider | string | none | Only this cloud (aws, gcp, modal). Default: every one. |
JSON: default_on, providers (each name, title, tier (vm: a VM that provides Spaces, sandbox: one sandbox per Space), connected, default, credentials (found, source), account, profile, region, zone, project, environment, label ("AWS ยท us-west-2"), ttl_hours and kinds (each image, kind, supported, reason, machine_type, usd_per_hour)) and resources (what Cua created: provider, id, type, space, region, state, created, expires, expired).
Connect a cloud account Spaces can be created in.
Runs cloud_test first and connects only when every check passes. Stores the profile, region, project or environment names under the cua home (never a key: the cloud's own CLI sign-in stays where it is). With make_default, create_space without on creates there (default.on).
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:cloud_connect; mutating, idempotent |
| Swift SDK | spaces.cloud.connect(_:makeDefault:ttlHours:) |
| Rust | cua_cloud::Clouds::connect |
| Parameter | Type | Default | Description |
|---|---|---|---|
environment | string | none | Modal environment (default: the profile's). |
make_default | boolean | false | Also make it the default location (default.on). Default false. |
profile | string | none | AWS: the profile in ~/.aws/config (default: default, or AWS_PROFILE). Modal: the profile in ~/.modal.toml (default: the active one). |
project | string | none | GCP project id (default: gcloud config get project). |
provider | string | required | aws, gcp or modal. |
region | string | none | AWS region (default: the profile's, else us-west-2) or GCP region (default us-central1). |
ttl_hours | integer | 8 | Every Space created there deletes itself after this many hours (the instance or sandbox terminates, the sweeper removes what is left). Default 8; 0 keeps Spaces until you delete them (Modal caps a sandbox at 24). At least 0. |
zone | string | none | GCP zone in the region (default: its -a zone). |
JSON: the connected cloud as cloud_status lists it, plus checks (each name, ok, detail) from the test it ran first.
Check a cloud account without creating anything.
Creates nothing: it signs in with the cloud's own CLI credentials, asks the cloud to validate a create without doing it (AWS DryRun, Google Cloud permission checks), and reads quotas. A failed check says what to fix.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:cloud_test, in spaces:readonly; read-only, idempotent |
| Swift SDK | spaces.cloud.test(_:) |
| Rust | cua_cloud::Clouds::test |
| Parameter | Type | Default | Description |
|---|---|---|---|
environment | string | none | Modal environment (default: the profile's). |
profile | string | none | AWS: the profile in ~/.aws/config (default: default, or AWS_PROFILE). Modal: the profile in ~/.modal.toml (default: the active one). |
project | string | none | GCP project id (default: gcloud config get project). |
provider | string | required | aws, gcp or modal. |
region | string | none | AWS region (default: the profile's, else us-west-2) or GCP region (default us-central1). |
zone | string | none | GCP zone in the region (default: its -a zone). |
JSON: provider, ok, account (the account, project or workspace the credentials reach) and checks (each name, ok, detail: credentials, permissions by dry run, quota, the region and machine types).
Forget a connected cloud account.
Forgets the connection (and default.on when it named this cloud). Nothing in the cloud is deleted.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:cloud_disconnect; mutating, idempotent |
| Swift SDK | spaces.cloud.disconnect(_:) |
| Rust | cua_cloud::Clouds::disconnect |
| Parameter | Type | Default | Description |
|---|---|---|---|
provider | string | required | aws, gcp or modal. |
JSON: provider, disconnected and left (resources Cua still records there; delete their Spaces, or cloud_sweep with all=true, to remove them).
Find and delete what Cua left in your clouds.
Acts only on resources that carry Cua's tags (cua-managed=true and this device's cua-owner) and that this cua home recorded, or that carry this device's owner id: never on anything else in the account. Default dry_run=true lists what it would delete: expired Spaces (past their ttl), resources whose Space is gone, and with all=true every Cua resource there.
| Providers | all (cloud, local, direct, relay) |
| Platforms | all (macos, windows, linux) |
| Metering | free |
| Approval | permission spaces:cloud_sweep; destructive |
| Swift SDK | spaces.cloud.sweep(provider:dryRun:all:) |
| Rust | cua_cloud::Clouds::sweep |
| Parameter | Type | Default | Description |
|---|---|---|---|
all | boolean | false | Also delete Cua resources that have not expired yet (every Space in that cloud). Default false: only expired ones, and resources no Space refers to any more. |
dry_run | boolean | true | List what would be deleted without deleting it. Default true. |
provider | string | none | Only this cloud. Default: every connected one. |
JSON: dry_run and resources, each provider, id, type, space, expires, action (delete, deleted, keep or failed) and reason.