Chuyển đến nội dung chính

LESSON 42: CLUSTER API AND INFRASTRUCTURE AS CODE

Cluster API (CAPI) v1.9+: manages Kubernetes clusters as Kubernetes objects. Machine, MachineSet, MachineDeployment, ClusterClass. Crossplane comparison. Infrastructure as Code with Terraform/Pulumi.

🔒 DevSecOps — Lesson 42 LESSON 42: CLUSTER API AND INFRASTRUCTURE AS CODE

KUBERNETES: FROM BASIC TO ADVANCED

Module 9: Cluster Management

xdev.asia

🎯 Lesson Objective_

Understand Cluster API — how to manage K8s clusters like K8s objects. Learn about ClusterClass, Machine management, and compare with other IaC approaches (Terraform, Crossplane).

1. What is Cluster API?

Cluster API (CAPI) is a Kubernetes project that allows managing the lifecycle of Kubernetes clusters using the Kubernetes API — "Kubernetes to create Kubernetes".

Main concepts__HTMLTAG_79___:

  • Management Cluster: cluster running CAPI controllers, managing workload clusters
  • Workload Cluster: cluster created and managed by CAPI
  • Infrastructure Provider: AWS (CAPA), GCP (CAPG), Azure (CAPZ), vSphere (CAPV)
  • Bootstrap Provider: kubeadm (KubeadmControlPlane), RKE2

2. CAPI Core Resources

# Cluster: đại diện cho một workload cluster
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
  name: production-cluster
  namespace: default
spec:
  clusterNetwork:
    pods:
      cidrBlocks: ["10.0.0.0/16"]
    services:
      cidrBlocks: ["10.96.0.0/12"]
  # Reference tới infrastructure provider (AWS/GCP/etc)
  infrastructureRef:
    apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
    kind: AWSCluster
    name: production-cluster
  # Reference tới control plane provider
  controlPlaneRef:
    apiVersion: controlplane.cluster.x-k8s.io/v1beta1
    kind: KubeadmControlPlane
    name: production-cluster-control-plane
# MachineDeployment: quản lý worker nodes (giống Deployment cho VMs)
apiVersion: cluster.x-k8s.io/v1beta1
kind: MachineDeployment
metadata:
  name: production-workers
spec:
  clusterName: production-cluster
  replicas: 3
  selector:
    matchLabels:
      cluster.x-k8s.io/cluster-name: production-cluster
  template:
    spec:
      bootstrap:
        configRef:
          apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
          kind: KubeadmConfigTemplate
          name: production-worker-config
      infrastructureRef:
        apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
        kind: AWSMachineTemplate
        name: production-worker-machine
      version: "v1.32.0"

3. ClusterClass — Template for Clusters

ClusterClass (CAPI v1.4+) allows defining standard templates to create multiple clusters from one spec:

apiVersion: cluster.x-k8s.io/v1beta1
kind: ClusterClass
metadata:
  name: aws-production-class
spec:
  controlPlane:
    ref:
      apiVersion: controlplane.cluster.x-k8s.io/v1beta1
      kind: KubeadmControlPlaneTemplate
      name: aws-cp-template
    machineInfrastructure:
      ref:
        apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
        kind: AWSMachineTemplate
        name: aws-cp-machine-template
  infrastructure:
    ref:
      apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
      kind: AWSClusterTemplate
      name: aws-cluster-template
  workers:
    machineDeployments:
    - class: default-worker
      template:
        bootstrap:
          ref:
            apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
            kind: KubeadmConfigTemplate
            name: worker-bootstrap
        infrastructure:
          ref:
            apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
            kind: AWSMachineTemplate
            name: aws-worker-template
  # Variables có thể customize per-cluster
  variables:
  - name: region
    required: true
    schema:
      openAPIV3Schema:
        type: string
  - name: instanceType
    schema:
      openAPIV3Schema:
        type: string
        default: m5.xlarge
# Tạo cluster từ ClusterClass
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
  name: team-alpha-cluster
spec:
  topology:
    class: aws-production-class
    version: v1.32.0
    controlPlane:
      replicas: 3
    workers:
      machineDeployments:
      - name: workers
        replicas: 5
    variables:
    - name: region
      value: ap-southeast-1
    - name: instanceType
      value: c5.2xlarge

4. CAPI Settings

# Cài clusterctl CLI
curl -L https://github.com/kubernetes-sigs/cluster-api/releases/latest/download/clusterctl-linux-amd64 -o /usr/local/bin/clusterctl
chmod +x /usr/local/bin/clusterctl

Init management cluster (ví dụ AWS provider)

export AWS_REGION=ap-southeast-1 export AWS_ACCESS_KEY_ID=... export AWS_SECRET_ACCESS_KEY=... export AWS_SESSION_TOKEN=... # nếu dùng MFA

Prepare AWS credentials

clusterawsadm bootstrap iam create-cloudformation-stack

export AWS_B64ENCODED_CREDENTIALS=$(clusterawsadm bootstrap credentials encode-as-profile)

Init CAPI

clusterctl init --infrastructure aws

Verify

kubectl get pods -n capi-system kubectl get pods -n capa-system # AWS provider

Xem providers

clusterctl describe provider

5. Creating and Managing Clusters

# Generate cluster manifest từ template
clusterctl generate cluster production-cluster \
  --infrastructure aws \
  --kubernetes-version v1.32.0 \
  --control-plane-machine-count 3 \
  --worker-machine-count 5 \
  > production-cluster.yaml

Apply

kubectl apply -f production-cluster.yaml

Theo dõi provisioning

clusterctl describe cluster production-cluster kubectl get machines -A -w

Lấy kubeconfig của workload cluster

clusterctl get kubeconfig production-cluster > production.kubeconfig

Upgrade workload cluster

kubectl patch cluster production-cluster --patch '{"spec": {"topology": {"version": "v1.33.0"}}}' --type merge

Scale worker nodes

kubectl patch machinedeployment production-workers --patch '{"spec": {"replicas": 10}}' --type merge

Delete cluster (tất cả VMs, LBs sẽ được dọn dẹp)

kubectl delete cluster production-cluster

6. Crossplane — Control Plane Framework

Crossplane is an alternative/complement to CAPI — manage cloud resources (not just clusters) with Kubernetes CRDs:

# Cài Crossplane
helm repo add crossplane-stable https://charts.crossplane.io/stable
helm install crossplane crossplane-stable/crossplane -n crossplane-system --create-namespace

Cài AWS provider

kubectl apply -f - <<EOF apiVersion: pkg.crossplane.io/v1 kind: Provider metadata: name: provider-aws-ec2 spec: package: xpkg.upbound.io/upbound/provider-aws-ec2:latest EOF

# Tạo RDS instance bằng Crossplane
apiVersion: rds.aws.upbound.io/v1beta1
kind: Instance
metadata:
  name: my-postgres
spec:
  forProvider:
    region: ap-southeast-1
    instanceClass: db.t3.medium
    engine: postgres
    engineVersion: "16.3"
    allocatedStorage: 20
    username: admin
    skipFinalSnapshot: true
  writeConnectionSecretToRef:
    namespace: default
    name: my-postgres-conn     # K8s Secret với connection info

7. IaC Comparison 2026

Tool        Use Case                          Approach
──────────────────────────────────────────────────────────────
Terraform   Multi-cloud infra provisioning    HCL, state file
Pulumi      Infra as code với real languages  Python/TS/Go
CAPI        K8s cluster lifecycle             K8s API, GitOps-friendly
Crossplane  Cloud resources via K8s API       K8s API, Composition
Helm        K8s app deployment                Templates, values
Kustomize   K8s manifest overlay              Patch-based, no templates

2026 Trend: CAPI + Crossplane combination

- CAPI: quản lý cluster lifecycle

- Crossplane: quản lý cloud resources (RDS, S3, etc.) được tham chiếu bởi apps

- ArgoCD/Flux: deploy tất cả qua GitOps

Summary

  • Cluster API: manage K8s cluster lifecycle using K8s objects
  • ClusterClass: standard template to create multiple consistent clusters
  • Management cluster + Workload clusters: clearly separated
  • Crossplane: manage cloud resources (DB, storage, network) with K8s CRDs
  • CAPI + Crossplane + ArgoCD: full GitOps platform engineering stack 2026