🎯 Lesson Objective_
Understand Cluster API — how to manage K8s clusters like K8s objects. Learn about ClusterClass, Machine management, and compare with other IaC approaches (Terraform, Crossplane).
1. What is Cluster API?
Cluster API (CAPI) is a Kubernetes project that allows managing the lifecycle of Kubernetes clusters using the Kubernetes API — "Kubernetes to create Kubernetes".
Main concepts__HTMLTAG_79___:
- Management Cluster: cluster running CAPI controllers, managing workload clusters
- Workload Cluster: cluster created and managed by CAPI
- Infrastructure Provider: AWS (CAPA), GCP (CAPG), Azure (CAPZ), vSphere (CAPV)
- Bootstrap Provider: kubeadm (KubeadmControlPlane), RKE2
2. CAPI Core Resources
# Cluster: đại diện cho một workload cluster
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
name: production-cluster
namespace: default
spec:
clusterNetwork:
pods:
cidrBlocks: ["10.0.0.0/16"]
services:
cidrBlocks: ["10.96.0.0/12"]
# Reference tới infrastructure provider (AWS/GCP/etc)
infrastructureRef:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSCluster
name: production-cluster
# Reference tới control plane provider
controlPlaneRef:
apiVersion: controlplane.cluster.x-k8s.io/v1beta1
kind: KubeadmControlPlane
name: production-cluster-control-plane
# MachineDeployment: quản lý worker nodes (giống Deployment cho VMs)
apiVersion: cluster.x-k8s.io/v1beta1
kind: MachineDeployment
metadata:
name: production-workers
spec:
clusterName: production-cluster
replicas: 3
selector:
matchLabels:
cluster.x-k8s.io/cluster-name: production-cluster
template:
spec:
bootstrap:
configRef:
apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
kind: KubeadmConfigTemplate
name: production-worker-config
infrastructureRef:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSMachineTemplate
name: production-worker-machine
version: "v1.32.0"
3. ClusterClass — Template for Clusters
ClusterClass (CAPI v1.4+) allows defining standard templates to create multiple clusters from one spec:
apiVersion: cluster.x-k8s.io/v1beta1
kind: ClusterClass
metadata:
name: aws-production-class
spec:
controlPlane:
ref:
apiVersion: controlplane.cluster.x-k8s.io/v1beta1
kind: KubeadmControlPlaneTemplate
name: aws-cp-template
machineInfrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSMachineTemplate
name: aws-cp-machine-template
infrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSClusterTemplate
name: aws-cluster-template
workers:
machineDeployments:
- class: default-worker
template:
bootstrap:
ref:
apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
kind: KubeadmConfigTemplate
name: worker-bootstrap
infrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSMachineTemplate
name: aws-worker-template
# Variables có thể customize per-cluster
variables:
- name: region
required: true
schema:
openAPIV3Schema:
type: string
- name: instanceType
schema:
openAPIV3Schema:
type: string
default: m5.xlarge
# Tạo cluster từ ClusterClass
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
name: team-alpha-cluster
spec:
topology:
class: aws-production-class
version: v1.32.0
controlPlane:
replicas: 3
workers:
machineDeployments:
- name: workers
replicas: 5
variables:
- name: region
value: ap-southeast-1
- name: instanceType
value: c5.2xlarge
4. CAPI Settings
# Cài clusterctl CLI curl -L https://github.com/kubernetes-sigs/cluster-api/releases/latest/download/clusterctl-linux-amd64 -o /usr/local/bin/clusterctl chmod +x /usr/local/bin/clusterctlInit management cluster (ví dụ AWS provider)
export AWS_REGION=ap-southeast-1 export AWS_ACCESS_KEY_ID=... export AWS_SECRET_ACCESS_KEY=... export AWS_SESSION_TOKEN=... # nếu dùng MFA
Prepare AWS credentials
clusterawsadm bootstrap iam create-cloudformation-stack
export AWS_B64ENCODED_CREDENTIALS=$(clusterawsadm bootstrap credentials encode-as-profile)
Init CAPI
clusterctl init --infrastructure aws
Verify
kubectl get pods -n capi-system kubectl get pods -n capa-system # AWS provider
Xem providers
clusterctl describe provider
5. Creating and Managing Clusters
# Generate cluster manifest từ template clusterctl generate cluster production-cluster \ --infrastructure aws \ --kubernetes-version v1.32.0 \ --control-plane-machine-count 3 \ --worker-machine-count 5 \ > production-cluster.yamlApply
kubectl apply -f production-cluster.yaml
Theo dõi provisioning
clusterctl describe cluster production-cluster kubectl get machines -A -w
Lấy kubeconfig của workload cluster
clusterctl get kubeconfig production-cluster > production.kubeconfig
Upgrade workload cluster
kubectl patch cluster production-cluster --patch '{"spec": {"topology": {"version": "v1.33.0"}}}' --type merge
Scale worker nodes
kubectl patch machinedeployment production-workers --patch '{"spec": {"replicas": 10}}' --type merge
Delete cluster (tất cả VMs, LBs sẽ được dọn dẹp)
kubectl delete cluster production-cluster
6. Crossplane — Control Plane Framework
Crossplane is an alternative/complement to CAPI — manage cloud resources (not just clusters) with Kubernetes CRDs:
# Cài Crossplane helm repo add crossplane-stable https://charts.crossplane.io/stable helm install crossplane crossplane-stable/crossplane -n crossplane-system --create-namespaceCài AWS provider
kubectl apply -f - <<EOF apiVersion: pkg.crossplane.io/v1 kind: Provider metadata: name: provider-aws-ec2 spec: package: xpkg.upbound.io/upbound/provider-aws-ec2:latest EOF
# Tạo RDS instance bằng Crossplane
apiVersion: rds.aws.upbound.io/v1beta1
kind: Instance
metadata:
name: my-postgres
spec:
forProvider:
region: ap-southeast-1
instanceClass: db.t3.medium
engine: postgres
engineVersion: "16.3"
allocatedStorage: 20
username: admin
skipFinalSnapshot: true
writeConnectionSecretToRef:
namespace: default
name: my-postgres-conn # K8s Secret với connection info
7. IaC Comparison 2026
Tool Use Case Approach ────────────────────────────────────────────────────────────── Terraform Multi-cloud infra provisioning HCL, state file Pulumi Infra as code với real languages Python/TS/Go CAPI K8s cluster lifecycle K8s API, GitOps-friendly Crossplane Cloud resources via K8s API K8s API, Composition Helm K8s app deployment Templates, values Kustomize K8s manifest overlay Patch-based, no templates2026 Trend: CAPI + Crossplane combination
- CAPI: quản lý cluster lifecycle
- Crossplane: quản lý cloud resources (RDS, S3, etc.) được tham chiếu bởi apps
- ArgoCD/Flux: deploy tất cả qua GitOps
Summary
- Cluster API: manage K8s cluster lifecycle using K8s objects
- ClusterClass: standard template to create multiple consistent clusters
- Management cluster + Workload clusters: clearly separated
- Crossplane: manage cloud resources (DB, storage, network) with K8s CRDs
- CAPI + Crossplane + ArgoCD: full GitOps platform engineering stack 2026