vcluster Learning¶
A vcluster is a full Kubernetes API server running as a pod inside a namespace of a host cluster. Workloads you create in it are synced down and scheduled as real pods on the host. You get cluster-level objects (namespaces, CRDs, RBAC, your own API server version) without a second real cluster to pay for and operate.
Everything here uses the official vcluster Helm chart from https://charts.loft.sh, distro k8s, chart version 0.37.2.
Learning¶
- One values file drives everything. The chart reads
vcluster.yaml(passed as Helm-f values.yaml), so every option below is a block in the same file. - Pick the distro once.
controlPlane.distro.k8s.enabled: trueruns vanilla Kubernetes (the default). Only one distro can be enabled at a time. - The API server listens on
https://localhost:8443inside the pod. Anything reaching it under a different hostname needs that hostname in the certificate (controlPlane.proxy.extraSANs) and in the exported kubeconfig (exportKubeConfig.server). - vcluster always writes a kubeconfig secret
vc-<name>in the host namespace. SetexportKubeConfig.secret.nameto also write a second one with your own server URL for CI or GitOps. - A ResourceQuota only counts pods that declare requests. Enable
policies.limitRangealongsidepolicies.resourceQuotaso pods without requests still get defaults and still count. experimental.deployruns manifests and Helm charts inside the vcluster at startup. It is flagged experimental by vcluster: breaking changes can land between releases.- The virtual control plane is a single pod by default. Back it with embedded etcd or an external database if you need HA.
Cheatsheet¶
Install or upgrade¶
helm upgrade --install my-vcluster vcluster \
--repo https://charts.loft.sh \
--version 0.37.2 \
-n my-vcluster --create-namespace \
-f values.yaml
Connect with the CLI¶
Connect without the CLI (read the exported secret)¶
kubectl -n my-vcluster get secret vc-my-vcluster \
-o jsonpath='{.data.config}' | base64 -d > kubeconfig.yaml
export KUBECONFIG=$(pwd)/kubeconfig.yaml
kubectl get namespaces
List and delete¶
https://www.vcluster.com/docs/vcluster/ https://www.vcluster.com/docs/vcluster/configure/vcluster-yaml/