> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/harness-platform/3.0/harness-platform-resources/connectors/cloud-providers/add-tas-connector.md).

# Add a Tanzu Application Service (TAS) connector

This topic describes how to set up the Harness Delegate in your TAS environment and add the cloud provider used to connect to your Tanzu cloud for deployment.

### Install the Harness Delegate <a href="#install-the-harness-delegate" id="install-the-harness-delegate"></a>

Harness Delegate is a service you run in your local network or VPC to connect your artifacts, TAS infrastructure, and any other providers with the Harness Manager.

Expand the following section to learn how to install the Harness Delegate.

<details>

<summary>Use the delegate installation wizard</summary>

1. In your Harness project, select **Project Setup**.
2. Select **Delegates**.
3. Select **Install a Delegate**.
4. Follow the instructions in the delegate installation wizard.

Use this [delegate installation wizard video](https://www.youtube.com/watch?v=yLMCxs3onH8) to guide you through the process.

</details>

<details>

<summary>Use the terminal</summary>

The [Harness Delegate](/harness-platform/3.0/harness-platform-resources/delegates/delegate-closed-beta/delegate-overview.md) is a lightweight worker process that is installed on your infrastructure and communicates only via outbound HTTP/HTTPS to the Harness Platform. This enables the Harness Platform to leverage the delegate to execute the CI/CD and other tasks on your behalf, without any of your secrets leaving your network.

You can install the Harness Delegate on either Docker or Kubernetes.

### Install the default Harness Delegate <a href="#install-the-default-harness-delegate" id="install-the-default-harness-delegate"></a>

#### Create a new delegate token <a href="#create-a-new-delegate-token" id="create-a-new-delegate-token"></a>

You can install delegates from the Account, Project, or Org scope. In this example, we'll create a new token in the Account scope.

To create a new delegate token, do the following:

1. In Harness, select **Account Settings**, then select **Account Resources**. The Account Resources page opens.
2. Select **Delegates**. The Delegates list page opens.
3. Select the **Tokens** tab, then select **+New Token**. The **New Token** dialog opens.
4. Enter a token name, for example `firstdeltoken`.
5. Select **Apply**. Harness generates a new token for you.
6. Select **Copy** to copy and store the token in a temporary file.

   You will provide this token as an input parameter in the next installation step. The delegate will use this token to authenticate with the Harness Platform.

#### Get your Harness account ID <a href="#get-your-harness-account-id" id="get-your-harness-account-id"></a>

Along with the delegate token, you will also need to provide your Harness `accountId` as an input parameter during delegate installation. This `accountId` is present in every Harness URL. For example, in the following URL:

```
https://app.harness.io/ng/#/account/6_vVHzo9Qeu9fXvj-AcQCb/settings/overview
```

`6_vVHzo9Qeu9fXvj-AcQCb` is the `accountId`.

{% hint style="info" %}
**NOTE**

When you install a delegate via the Harness UI, several dependencies in this topic are prefilled for your convenience. This topic explains where to find the required information for CLI-based installation.
{% endhint %}

For more information, go to [View account info and subscribe to downtime alerts](/harness-platform/3.0/subscriptions-and-licenses/view-account-info-and-subscribe-to-alerts.md).

PrerequisiteEnsure that you have access to a Kubernetes cluster. For the purposes of this tutorial, we will use minikube.Install minikubeOn Windowschoco install minikubeFor Chocolatey installation instructions, go to Installing Chocolatey in the Chocolatey documentation.For additional options to install minikube on Windows, go to minikube start in the minikube documentation.On macOS:brew install minikubeFor Homebrew installation instructions, go to Installation in the Homebrew documentation.Now start minikube with the following config.minikube start --memory 4g --cpus 4Validate that you have kubectl access to your cluster.kubectl get pods -ANow that you have access to a Kubernetes cluster, you can install the delegate using any of the options below\.Install the Helm chartAs a prerequisite, you must have Helm v3 installed on the machine from which you connect to your Kubernetes cluster.You can now install the delegate using the delegate Helm chart. First, add the harness-delegate Helm chart repo to your local Helm registry.helm repo add harness-delegate <https://app.harness.io/storage/harness-download/delegate-helm-chart/helm> repo updatehelm search repo harness-delegateWe will use the harness-delegate/harness-delegate-ng chart in this tutorial.NAME CHART VERSION APP VERSION DESCRIPTIONharness-delegate/harness-delegate-ng 1.0.8 1.16.0 A Helm chart for deploying harness-delegateNow we are ready to install the delegate. The following example installs/upgrades firstk8sdel delegate (which is a Kubernetes workload) in the harness-delegate-ng namespace using the harness-delegate/harness-delegate-ng Helm chart.You can install delegates from the Account, Project, or Org scope. In this example, we'll install a delegate in the Account scope.To install a delegate, do the following:In Harness, select Account Settings, then select Account Resources. The Account Resources page opens.Select Delegates. The Delegates list page opens.Select New Delegate. The New Delegate dialog opens.Under Select where you want to install your Delegate, select Kubernetes.Under Install your Delegate, select Helm Chart.Copy the helm upgrade command.The command uses the default values.yaml file located in the delegate Helm chart GitHub repo. To make persistent changes to one or more values, you can download and update the values.yaml file according to your requirements. Once you have updated the file, you can use it by running the upgrade command below. helm upgrade -i firstk8sdel --namespace harness-delegate-ng --create-namespace \ harness-delegate/harness-delegate-ng \ -f values.yaml \ --set delegateName=firstk8sdel \ --set accountId=PUT\_YOUR\_HARNESS\_ACCOUNTID\_HERE \ --set delegateToken=PUT\_YOUR\_DELEGATE\_TOKEN\_HERE \ --set managerEndpoint=PUT\_YOUR\_MANAGER\_HOST\_AND\_PORT\_HERE \ --set delegateDockerImage=harness/delegate:yy.mm.verno \ --set replicas=1 --set upgrader.enabled=trueNOTETo install a Helm delegate for Harness Self-Managed Enterprise Edition in an air-gapped environment, you must pass your certificate when you add the Helm repo.helm repo add harness-delegate --ca-file <.PEM\_FILE\_PATH> \<HELM\_CHART\_URL\_FROM\_UI>For more information on requirements for air-gapped environments, go to Install in an air-gapped environment.Run the command.Create main.tf fileHarness uses a Terraform module for the Kubernetes delegate. This module uses the standard Terraform Helm provider to install the Helm chart onto a Kubernetes cluster whose config by default is stored in the same machine at the \~/.kube/config path. Copy the following into a main.tf file stored on a machine from which you want to install your delegate.module "delegate" { source = "harness/harness-delegate/kubernetes" version = "0.1.8" account\_id = "PUT\_YOUR\_HARNESS\_ACCOUNTID\_HERE" delegate\_token = "PUT\_YOUR\_DELEGATE\_TOKEN\_HERE" delegate\_name = "firstk8sdel" namespace = "harness-delegate-ng" manager\_endpoint = "PUT\_YOUR\_MANAGER\_HOST\_AND\_PORT\_HERE" delegate\_image = "harness/delegate:yy.mm.verno" replicas = 1 upgrader\_enabled = false # Additional optional values to pass to the helm chart values = yamlencode({ javaOpts: "-Xms64M" })}provider "helm" { kubernetes { config\_path = "\~/.kube/config" }}Now replace the variables in the file with your Harness account ID and delegate token values. Replace PUT\_YOUR\_MANAGER\_HOST\_AND\_PORT\_HERE with the Harness Manager Endpoint noted below. For Harness SaaS accounts, you can find your Harness Cluster Location on the Account Overview page under the Account Settings section of the left navigation.Run Terraform init, plan, and applyInitialize Terraform. This downloads the Terraform Helm provider to your machine.terraform initRun the following step to view the changes Terraform is going to make on your behalf.terraform planFinally, run this step to make Terraform install the Kubernetes delegate using the Helm provider.terraform applyWhen prompted by Terraform if you want to continue with the apply step, type yes, and then you will see output similar to the following.helm\_release.delegate: Creating...helm\_release.delegate: Still creating... \[10s elapsed]helm\_release.delegate: Still creating... \[20s elapsed]helm\_release.delegate: Still creating... \[30s elapsed]helm\_release.delegate: Still creating... \[40s elapsed]helm\_release.delegate: Still creating... \[50s elapsed]helm\_release.delegate: Still creating... \[1m0s elapsed]helm\_release.delegate: Creation complete after 1m0s \[id=firstk8sdel]Apply complete! Resources: 1 added, 0 changed, 0 destroyed.Download a Kubernetes manifest templatecurl -LO <https://raw.githubusercontent.com/harness/delegate-kubernetes-manifest/main/harness-delegate.yamlReplace> variables in the templateOpen the harness-delegate.yaml file in a text editor and replace PUT\_YOUR\_DELEGATE\_NAME\_HERE, PUT\_YOUR\_HARNESS\_ACCOUNTID\_HERE, and PUT\_YOUR\_DELEGATE\_TOKEN\_HERE with your delegate name (for example, firstk8sdel), Harness accountId, and delegate token values, respectively.Replace the PUT\_YOUR\_MANAGER\_HOST\_AND\_PORT\_HERE variable with the Harness Manager Endpoint noted below. For Harness SaaS accounts, you can find your Harness Cluster Location on the Account Overview page under the Account Settings section of the left navigation.Apply the Kubernetes manifestkubectl apply -f harness-delegate.yamlPrerequisitesEnsure that you have the Docker runtime installed on your host. If not, use one of the following options to install Docker:Docker for MacDocker for CentOSDocker for UbuntuDocker for DebianDocker for WindowsInstall on DockerYou can install delegates from the Account, Project, or Org scope. In this example, we'll install a delegate in the Project scope.To install a delegate, do the following:In Harness, select your project, then select Project Settings.Under Project-level resources, select Delegates.Select Install a Delegate to open the New Delegate dialog.Under Select where you want to install your Delegate, select Docker.Under Install your Delegate, enter a Delegate Name.Copy the docker run command.docker run --cpus=1 --memory=2g \ -e DELEGATE\_NAME=docker-delegate \ -e NEXT\_GEN="true" \ -e DELEGATE\_TYPE="DOCKER" \ -e ACCOUNT\_ID=YOUR\_HARNESS\_ACCOUNTID\_ \ -e DELEGATE\_TOKEN=YOUR\_DELEGATE\_TOKEN \ -e DELEGATE\_TAGS="" \ -e MANAGER\_HOST\_AND\_PORT=YOUR\_MANAGER\_HOST\_AND\_PORT \ harness/delegate:yy.mm.vernoThe docker run command doesn't allow you to select the delegate token. You can replace the token in the command with another token if required.Steps 6 and 7 are optional when installing a delegate using the CLI flow.(Optional) Replace the YOUR\_MANAGER\_HOST\_AND\_PORT\_HERE variable with the Harness Manager Endpoint noted below. For Harness SaaS accounts, to find your Harness cluster location, select Account Settings, and then select Overview. In Account Overview, look in Account Settings. It is listed next to Harness Cluster Hosting Account.For more information, go to View account info and subscribe to downtime alerts.For Harness CDCE, the endpoint varies based on the Docker vs. Helm installation options.Run the command.

### Ephemeral Storage in Delegate Helm Charts <a href="#ephemeral-storage-in-delegate-helm-charts" id="ephemeral-storage-in-delegate-helm-charts"></a>

To manage temporary disk space efficiently, you can configure ephemeral storage for the Harness Delegate using Helm charts. This guide walks you through defining custom volumes and applying the configuration during Helm installation.

The setup is cloud-agnostic and works across providers by adjusting the storage class as needed.

1. Create a `values.yaml` file and add the following configuration to it.

   ```yaml
      custom_mounts:
      - mountPath: "/scratch"
         name: scratch-volume

      custom_volumes:
      - name: scratch-volume
         ephemeral:
            volumeClaimTemplate:
            metadata:
               labels:
                  type: <YOUR-TYPE-REFERENCE>
            spec:
               accessModes: [ "ReadWriteOnce" ]
               storageClassName: "<YOUR-STORAGE-CLASS>"
               resources:
                  requests:
                  storage: <STORAGE-SIZE>
   ```

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Before proceeding with installation, ensure a suitable StorageClass exists in your cluster. This is required for provisioning ephemeral volumes as defined in your values.yaml.</p><p>You can check the available storage classes using:</p><pre class="language-bash"><code class="lang-bash">kubectl get storageclass
   </code></pre><p>If your cluster doesn’t have a suitable <code>StorageClass</code>, you can create one using:</p><pre class="language-bash"><code class="lang-bash">kubectl apply -f storage-class.yaml
   </code></pre><p>Example <code>storage-class.yaml</code>:</p><pre class="language-yaml"><code class="lang-yaml">apiVersion: storage.k8s.io/v1
   kind: StorageClass
   metadata:
   name: &#x3C;YOUR-STORAGE-CLASS-NAME>
   provisioner: &#x3C;YOUR-STORAGE-PROVISIONER>  # e.g., kubernetes.io/aws-ebs, pd.csi.storage.gke.io
   parameters:
   type: &#x3C;YOUR-VOLUME-TYPE>               # e.g., gp2 for AWS
   reclaimPolicy: &#x3C;YOUR-RECLAIM-POLICY>     # e.g., Retain or Delete
   volumeBindingMode: WaitForFirstConsumer
   </code></pre><p>After creating the <code>StorageClass</code>, configure it in the Helm chart by setting: <code>--set persistence.storageClass=&#x3C;YOUR-STORAGE-CLASS-NAME></code></p></div>
2. Install the Helm chart using the example below, which applies the configuration from `values.yaml` file we created earlier:

   ```yaml
      helm upgrade -i <YOUR-DELEGATE-NAME> --namespace harness-delegate-ng --create-namespace \
      harness-delegate/harness-delegate-ng \
      --set delegateName=<YOUR-DELEGATE-NAME> \
      --set accountId=XXXXXXXXXXXXXXXX \
      --set delegateToken=XXXXXXXXXXXXXXXXXXXXXX \
      --set managerEndpoint=https://<YOUR-URL>.harness.io \
      --set delegateDockerImage=us-west1-docker.pkg.dev/gar-setup/docker/delegate:<DELEGATE-TAG-VERSION> \
      --set replicas=1 --set upgrader.enabled=true \
      -f values.yaml
   ```
3. Verify that the ephemeral storage has been mounted correctly by inspecting the pod’s volume mounts.

   * Get the Pod Name

     ```bash
     kubectl get pods -n harness-delegate-ng
     ```

     Output:

     ```bash
     NAME                                  READY   STATUS    RESTARTS   AGE
     delegate-ephemeral-storage            1/1     Running   0          2m
     ```
   * Describe the Pod

     ```bash
     kubectl describe pod delegate-ephemeral-storage -n harness-delegate-ng
     ```

     Look for the similar section below in your output

     ```bash
     Volumes:
     scratch-volume:
        Type:       PersistentVolumeClaim (a reference to a PVC)
        ClaimName:  scratch-volume-delegate-ephemeral-storage
        ReadOnly:   false

     Mounts:
     /scratch from scratch-volume (rw)
     ```

     This confirms that your ephemeral volume (scratch-volume) is mounted to /scratch in the pod.

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>IMPORTANT NOTE:</strong></p><p>Ephemeral storage is automatically deleted when the pod is terminated, and a new volume is created when a new pod starts. This ensures the storage is tied to the pod’s lifecycle and is not persistent.</p></div>

### Deploy using a custom role <a href="#deploy-using-a-custom-role" id="deploy-using-a-custom-role"></a>

During delegate installation, you have the option to deploy using a custom role. To use a custom role, you must edit the delegate YAML file.

Harness supports the following custom roles:

* `cluster-admin`
* `cluster-viewer`
* `namespace-admin`
* custom cluster roles

To deploy using a custom cluster role, do the following:

1. Open the delegate YAML file in your text editor.
2. Add the custom cluster role to the `roleRef` field in the delegate YAML.

   ```yaml
   ---
   apiVersion: rbac.authorization.k8s.io/v1beta1
   kind: ClusterRoleBinding
   metadata:
     name: harness-delegate-cluster-admin
   subjects:
     - kind: ServiceAccount
       name: default
       namespace: harness-delegate-ng
   roleRef:
     kind: ClusterRole
     name: cluster-admin
     apiGroup: rbac.authorization.k8s.io
   ---
   ```

   In this example, the `cluster-admin` role is defined.
3. Save the delegate YAML file.

### Verify delegate connectivity <a href="#verify-delegate-connectivity" id="verify-delegate-connectivity"></a>

Select **Continue**. After the health checks pass, your delegate is available for you to use. Select **Done** and verify your new delegate is listed.

#### Helm chart & Terraform Helm provider <a href="#helm-chart-and-terraform-helm-provider" id="helm-chart-and-terraform-helm-provider"></a>

#### Kubernetes manifest <a href="#kubernetes-manifest" id="kubernetes-manifest"></a>

#### Docker <a href="#docker" id="docker"></a>

You can now route communication to external systems in Harness connectors and pipelines by selecting this delegate via a delegate selector.

### Troubleshooting <a href="#troubleshooting" id="troubleshooting"></a>

The delegate installer provides troubleshooting information for each installation process. If the delegate cannot be verified, select **Troubleshoot** for steps you can use to resolve the problem. This section includes the same information.

Harness asks for feedback after the troubleshooting steps. You are asked, **Did the delegate come up?**

If the steps did not resolve the problem, select **No**, and use the form to describe the issue. You'll also find links to Harness Support and to [Delegate docs](/harness-platform/3.0/harness-platform-resources/delegates/delegate-closed-beta/delegate-overview.md).

Use the following steps to troubleshoot your installation of the delegate using Helm.Verify that Helm is correctly installed:Check for Helm:helmAnd then check for the installed version of Helm:helm versionIf you receive the message Error: rendered manifests contain a resource that already exists..., delete the existing namespace, and retry the Helm upgrade command to deploy the delegate.For further instructions on troubleshooting your Helm installation, go to Helm troubleshooting guide.Check the status of the delegate on your cluster:kubectl describe pods -n \<NAMESPACE>If the pod did not start, check the delegate logs:kubectl logs -f \<DELEGATE\_NAME> -n \<NAMESPACE>If the state of the delegate pod is CrashLoopBackOff, check your allocation of compute resources (CPU and memory) to the cluster. A state of CrashLoopBackOff indicates insufficient Kubernetes cluster resources.If the delegate pod is not healthy, use the kubectl describe command to get more information:kubectl describe \<POD\_NAME> -n \<NAMESPACE>Use the following steps to troubleshoot your installation of the delegate using Terraform.Verify that Terraform is correctly installed:terraform -versionFor further instructions on troubleshooting your installation of Terraform, go to the Terraform troubleshooting guide.Check the status of the delegate on your cluster:kubectl describe pods -n \<namespace>If the pod did not start, check the delegate logs:kubectl logs -f \<DELEGATE\_NAME> -n \<NAMESPACE>If the state of the delegate pod is CrashLoopBackOff, check your allocation of compute resources (CPU and memory) to the cluster. A state of CrashLoopBackOff indicates insufficient Kubernetes cluster resources.If the delegate pod is not healthy, use the kubectl describe command to get more information:kubectl describe \<POD\_NAME> -n \<NAMESPACE>Use the following steps to troubleshoot your installation of the delegate using Kubernetes.Check the status of the delegate on your cluster:kubectl describe pods -n \<NAMESPACE>If the pod did not start, check the delegate logs:kubectl logs -f \<DELEGATE\_NAME> -n \<NAMESPACE>If the state of the delegate pod is CrashLoopBackOff, check your allocation of compute resources (CPU and memory) to the cluster. A state of CrashLoopBackOff indicates insufficient Kubernetes cluster resources.If the delegate pod is not healthy, use the kubectl describe command to get more information:kubectl describe \<POD\_NAME> -n \<NAMESPACE>Use the following steps to troubleshoot your installation of the delegate using Docker:Check the status of the delegate on your cluster:docker container ls -aIf the pod is not running, check the delegate logs:docker container logs \<DELEGATE\_NAME> -fRestart the delegate container. To stop the container:docker container stop \<DELEGATE\_NAME>To start the container:docker container start \<DELEGATE\_NAME>Make sure the container has sufficient CPU and memory resources. If not, remove the older containers:docker container rm \[container id]

</details>

To learn more, watch the [Delegate overview](/harness-platform/3.0/harness-platform-resources/delegates/delegate-closed-beta/delegate-overview.md) video.

### Install the Cloud Foundry Command Line Interface (cf CLI) on your Harness Delegate <a href="#install-the-cloud-foundry-command-line-interface-cf-cli-on-your-harness-delegate" id="install-the-cloud-foundry-command-line-interface-cf-cli-on-your-harness-delegate"></a>

After the delegate pods are created, you must edit your Harness Delegate YAML to install CF CLI v7, `autoscaler`, and `Create-Service-Push` plugins.

1. Open `delegate.yaml` in a text editor.
2. Locate the environment variable `INIT_SCRIPT` in the `Deployment` object.

   ```
   - name: INIT_SCRIPT
   value: ""
   ```
3. Replace `value: ""` with the following script to install CF CLI, `autoscaler`, and `Create-Service-Push` plugins.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Harness Delegate uses Red Hat–based distributions such as Red Hat Enterprise Linux (RHEL) or Red Hat Universal Base Image (UBI). Hence, we recommend that you use <code>microdnf</code> commands to install CF CLI on your delegate. If you are using a package manager in Debian-based distributions such as Ubuntu, use <code>apt-get</code> commands to install CF CLI on your delegate.</p></div>

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Make sure to use your API token for pivnet login in the following script.</p></div>

{% tabs %}
{% tab title="microdnf" %}

```
- name: INIT_SCRIPT
value: |
 # update package manager, install necessary packages, and install CF CLI v7
 microdnf update
 microdnf install yum
 microdnf install --nodocs unzip yum-utils
 microdnf install -y yum-utils
 echo y | yum install wget
 wget -O /etc/yum.repos.d/cloudfoundry-cli.repo https://packages.cloudfoundry.org/fedora/cloudfoundry-cli.repo
 echo y | yum install cf7-cli -y

 # autoscaler plugin
 # download and install pivnet
 wget -O pivnet https://github.com/pivotal-cf/pivnet-cli/releases/download/v0.0.55/pivnet-linux-amd64-0.0.55 && chmod +x pivnet && mv pivnet /usr/local/bin;
 pivnet login --api-token=<replace with api token>

 # download and install autoscaler plugin by pivnet
 pivnet download-product-files --product-slug='pcf-app-autoscaler' --release-version='2.0.295' --product-file-id=912441
 cf install-plugin -f autoscaler-for-pcf-cliplugin-linux64-binary-2.0.295

 # install Create-Service-Push plugin from community
 cf install-plugin -r CF-Community "Create-Service-Push"

 # verify cf version
 cf --version

 # verify plugins
 cf plugins
```

{% endtab %}

{% tab title="apt-get" %}

```
- name: INIT_SCRIPT
value: |
 # update package manager, install necessary packages, and install CF CLI v7
 apt-get install wget
 wget -q -O - https://packages.cloudfoundry.org/debian/cli.cloudfoundry.org.key | apt-key add -
 echo "deb https://packages.cloudfoundry.org/debian stable main" | tee /etc/apt/sources.list.d/cloudfoundry-cli.list
 apt-get update
 apt-get install cf7-cli

 # autoscaler plugin
 # download and install pivnet
 wget -O pivnet https://github.com/pivotal-cf/pivnet-cli/releases/download/v0.0.55/pivnet-linux-amd64-0.0.55 && chmod +x pivnet && mv pivnet /usr/local/bin;
 pivnet login --api-token=<replace with api token>

 # download and install autoscaler plugin by pivnet
 pivnet download-product-files --product-slug='pcf-app-autoscaler' --release-version='2.0.295' --product-file-id=912441
 cf install-plugin -f autoscaler-for-pcf-cliplugin-linux64-binary-2.0.295

 # install Create-Service-Push plugin from community
 cf install-plugin -r CF-Community "Create-Service-Push"

 # verify cf version
 cf --version

 # verify plugins
 cf plugins
```

{% endtab %}
{% endtabs %}

4. Apply the profile to the delegate profile and check the logs.

   The output for `cf --version` is `cf version 7.2.0+be4a5ce2b.2020-12-10`.

   Here is the output for `cf plugins`.

   ```
   App Autoscaler        2.0.295   autoscaling-apps              Displays apps bound to the autoscaler
   App Autoscaler        2.0.295   autoscaling-events            Displays previous autoscaling events for the app
   App Autoscaler        2.0.295   autoscaling-rules             Displays rules for an autoscaled app
   App Autoscaler        2.0.295   autoscaling-slcs              Displays scheduled limit changes for the app
   App Autoscaler        2.0.295   configure-autoscaling         Configures autoscaling using a manifest file
   App Autoscaler        2.0.295   create-autoscaling-rule       Create rule for an autoscaled app
   App Autoscaler        2.0.295   create-autoscaling-slc        Create scheduled instance limit change for an autoscaled app
   App Autoscaler        2.0.295   delete-autoscaling-rule       Delete rule for an autoscaled app
   App Autoscaler        2.0.295   delete-autoscaling-rules      Delete all rules for an autoscaled app
   App Autoscaler        2.0.295   delete-autoscaling-slc        Delete scheduled limit change for an autoscaled app
   App Autoscaler        2.0.295   disable-autoscaling           Disables autoscaling for the app
   App Autoscaler        2.0.295   enable-autoscaling            Enables autoscaling for the app
   App Autoscaler        2.0.295   update-autoscaling-limits     Updates autoscaling instance limits for the app
   Create-Service-Push   1.3.2     create-service-push, cspush   Works in the same manner as cf push, except that it will create services defined in a services-manifest.yml file first before performing a cf push.
   ```

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The CF Command script does not require <code>cf login</code>. Harness logs in by using the credentials in the TAS cloud provider set up in the infrastructure definition for the workflow executing the CF Command.</p></div>

### Add the Harness TAS provider <a href="#add-the-harness-tas-provider" id="add-the-harness-tas-provider"></a>

You can connect Harness to a TAS space by adding a TAS connector.

Perform the following steps to add a TAS connector.

1. Open a Harness project, and then select **Connectors** under **Project Setup**.
2. Select **New Connector**, and select **Tanzu Application Service** under **Cloud Providers**.
3. Enter a connector name, enter an optional description and tag, and then select **Continue**.

   Harness automatically creates an [**ID**](/harness-ai/use-harness-platform/references/entity-identifier-reference.md) for the connector. The ID is based on the connector's name.
4. Enter the TAS **Endpoint URL**. For example, `https://api.system.tas-mycompany.com`.
5. In **Authentication**, select one of the following options:
   * **Plaintext** - Enter the username and password. For password, you can either create a new secret or use an existing one.
   * **Encrypted** - Enter the username and password. You can create a new secret for your username and password or use exiting ones.
6. Select **Continue**.
7. In **Connect to the provider**, select **Connect through a Harness Delegate**, and then select **Continue**.

   We don't recommend using the **Connect through Harness Platform** option here because you'll need a delegate later for connecting to your TAS environment. Typically, the **Connect through Harness Platform** option is a quick way to make connections without having to use delegates.
8. In **Set Up Delegates**, select the **Connect using Delegates with the following Tags** option, and then enter the name of the [delegate](#install-the-harness-delegate) you created earlier.
9. Select **Save and Continue**.
10. Once the test connection succeeds, select **Finish**.

    The connector now appears in the **Connectors** list.

#### Refresh Token Support <a href="#refresh-token-support" id="refresh-token-support"></a>

{% hint style="info" %}
Harness Delegate version 23.12.81804 or later is required to use this feature.
{% endhint %}

Harness provides the option to use a Refresh token to authenticate with the Tanzu connector. This Refresh token is used by Harness to verify your Tanzu instance. However, you still need to provide a username and password to authenticate with Tanzu. These credentials are used to obtain a new Refresh token. Once the Refresh token is provided in the connector, Harness uses it to authenticate and perform each task. Harness will authenticate with the Refresh token before executing each Tanzu step defined in the pipeline.

You can retrieve the Refresh token via the `config.json` file you receive when authenticating with the CF client. You can pass the Refresh token as a secret stored in the Harness Secrets Manager or your secrets manager of choice.

#### Custom configuration for extensible authentication <a href="#custom-configuration-for-extensible-authentication" id="custom-configuration-for-extensible-authentication"></a>

For Harness Delegate version 23.12.81811 and later, you can create a Tanzu connector by setting the `AS_REFRESH_TOKEN_CLIENT_ID`, `TAS_REFRESH_TOKEN_CLIENT_SECRET`, `ENABLE_TAS_REFRESH_TOKEN_CLIENT_ID` parameters, and providing the Refresh token. The connector will generate a Refresh token using the Client ID and Secret ID env variables.

* **ENABLE\_TAS\_REFRESH\_TOKEN\_CLIENT\_ID**: This is the setting to configure the alternative authentication mode on the Harness Delegate for Tanzu.
* **TAS\_REFRESH\_TOKEN\_CLIENT\_ID**: This is the Client ID parameter for Tanzu Authentication.
* **TAS\_REFRESH\_TOKEN\_CLIENT\_SECRET**: This is the Client Secret parameter for Tanzu Authentication.

**Configure the delegate YAML**

To configure the delegate YAML, do the following:

1. Go to the Kubernetes delegate YAML (deployment) or the actual deployed resource.
2. Under `spec.template.spec.containers.env`, add the following environment variables.

```yaml
   - name: ENABLE_TAS_REFRESH_TOKEN_CLIENT_ID
      value: "true"
   - name: TAS_REFRESH_TOKEN_CLIENT_ID
      value: gam
   - name: TAS_REFRESH_TOKEN_CLIENT_SECRET
      value: public
```

**Demo Video**

{% embed url="<https://www.loom.com/share/f0231a6142324d8e8b780d332d04bb78?sid=c2f2c774-8262-449b-bdc4-fd79a3938b34>" %}
