Choose how the data reaches us
CostGraph pulls it
You supply read-only credentials and we call OVHcloud once a day. Nothing to run.
You push it
You send us FOCUS records over the API. Credentials never leave your infrastructure.
Before you begin
- In the OVHcloud Control Panel, go to Identity, Security & Operations > Identities > Service account and click Add a service account. Name it, describe it, and click Create.
- Copy both values from the confirmation window. The service account name is the client id and the password is the client secret. OVHcloud displays the secret only at creation and can’t retrieve or regenerate it, so a lost secret means a new service account.
- Attach an IAM policy to the service account under Identity, Security & Operations > Identities > Policies. The following table lists what CostGraph calls. OVHcloud’s managed Global billingAccount permission group covers the billing side across every product.
The client id prefix selects the API region and must match the region your account
lives in:
EU., CA., or US.. A client id from another region fails with
invalid_client. The API console shows the IAM action each route needs on its
IAM actions line. For the full walkthrough, see OVHcloud’s
service account guide.
Let CostGraph pull
- Open Settings > Integrations and pick OVHcloud.
- Name the connection and pick the tenant these charges belong to.
- Enter the client id and client secret. Add a Public Cloud project id to scope the running month to one project, or leave it empty for every project the service account reads.
- Select Connect.
/me.
Credentials are encrypted at rest and used only to read billing data. Revoke them in
OVHcloud at any time and the connection stops; nothing else is affected.
Push it yourself
Send the charges to CostGraph as FOCUS records instead. Push FOCUS data covers the connection id, thefocus:write key, and the request shape.
Run the exporter
Rather than build that request yourself, run our exporter. It reads OVHcloud on a schedule and pushes the records for you, wherever you want to run it: a container, a KubernetesCronJob, or a binary on a machine you already have.