🎯 Mục tiêu bài học
Hiểu Cluster API — cách quản lý K8s clusters như K8s objects. Tìm hiểu ClusterClass, Machine management, và so sánh với các IaC approaches khác (Terraform, Crossplane).
1. Cluster API là gì?
Cluster API (CAPI) là Kubernetes project cho phép quản lý lifecycle của Kubernetes clusters sử dụng Kubernetes API — "Kubernetes để tạo Kubernetes".
Các khái niệm chính:
- Management Cluster: cluster chạy CAPI controllers, quản lý các workload clusters
- Workload Cluster: cluster được tạo và quản lý bởi CAPI
- Infrastructure Provider: AWS (CAPA), GCP (CAPG), Azure (CAPZ), vSphere (CAPV)
- Bootstrap Provider: kubeadm (KubeadmControlPlane), RKE2
2. CAPI Core Resources
# Cluster: đại diện cho một workload cluster
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
name: production-cluster
namespace: default
spec:
clusterNetwork:
pods:
cidrBlocks: ["10.0.0.0/16"]
services:
cidrBlocks: ["10.96.0.0/12"]
# Reference tới infrastructure provider (AWS/GCP/etc)
infrastructureRef:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSCluster
name: production-cluster
# Reference tới control plane provider
controlPlaneRef:
apiVersion: controlplane.cluster.x-k8s.io/v1beta1
kind: KubeadmControlPlane
name: production-cluster-control-plane
# MachineDeployment: quản lý worker nodes (giống Deployment cho VMs)
apiVersion: cluster.x-k8s.io/v1beta1
kind: MachineDeployment
metadata:
name: production-workers
spec:
clusterName: production-cluster
replicas: 3
selector:
matchLabels:
cluster.x-k8s.io/cluster-name: production-cluster
template:
spec:
bootstrap:
configRef:
apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
kind: KubeadmConfigTemplate
name: production-worker-config
infrastructureRef:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSMachineTemplate
name: production-worker-machine
version: "v1.32.0"
3. ClusterClass — Template cho Clusters
ClusterClass (CAPI v1.4+) cho phép định nghĩa template chuẩn để tạo nhiều clusters từ một spec:
apiVersion: cluster.x-k8s.io/v1beta1
kind: ClusterClass
metadata:
name: aws-production-class
spec:
controlPlane:
ref:
apiVersion: controlplane.cluster.x-k8s.io/v1beta1
kind: KubeadmControlPlaneTemplate
name: aws-cp-template
machineInfrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSMachineTemplate
name: aws-cp-machine-template
infrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSClusterTemplate
name: aws-cluster-template
workers:
machineDeployments:
- class: default-worker
template:
bootstrap:
ref:
apiVersion: bootstrap.cluster.x-k8s.io/v1beta1
kind: KubeadmConfigTemplate
name: worker-bootstrap
infrastructure:
ref:
apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
kind: AWSMachineTemplate
name: aws-worker-template
# Variables có thể customize per-cluster
variables:
- name: region
required: true
schema:
openAPIV3Schema:
type: string
- name: instanceType
schema:
openAPIV3Schema:
type: string
default: m5.xlarge
# Tạo cluster từ ClusterClass
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
name: team-alpha-cluster
spec:
topology:
class: aws-production-class
version: v1.32.0
controlPlane:
replicas: 3
workers:
machineDeployments:
- name: workers
replicas: 5
variables:
- name: region
value: ap-southeast-1
- name: instanceType
value: c5.2xlarge
4. Cài đặt CAPI
# Cài clusterctl CLI curl -L https://github.com/kubernetes-sigs/cluster-api/releases/latest/download/clusterctl-linux-amd64 -o /usr/local/bin/clusterctl chmod +x /usr/local/bin/clusterctlInit management cluster (ví dụ AWS provider)
export AWS_REGION=ap-southeast-1 export AWS_ACCESS_KEY_ID=... export AWS_SECRET_ACCESS_KEY=... export AWS_SESSION_TOKEN=... # nếu dùng MFA
Prepare AWS credentials
clusterawsadm bootstrap iam create-cloudformation-stack
export AWS_B64ENCODED_CREDENTIALS=$(clusterawsadm bootstrap credentials encode-as-profile)
Init CAPI
clusterctl init --infrastructure aws
Verify
kubectl get pods -n capi-system kubectl get pods -n capa-system # AWS provider
Xem providers
clusterctl describe provider
5. Tạo và Quản lý Clusters
# Generate cluster manifest từ template clusterctl generate cluster production-cluster \ --infrastructure aws \ --kubernetes-version v1.32.0 \ --control-plane-machine-count 3 \ --worker-machine-count 5 \ > production-cluster.yamlApply
kubectl apply -f production-cluster.yaml
Theo dõi provisioning
clusterctl describe cluster production-cluster kubectl get machines -A -w
Lấy kubeconfig của workload cluster
clusterctl get kubeconfig production-cluster > production.kubeconfig
Upgrade workload cluster
kubectl patch cluster production-cluster --patch '{"spec": {"topology": {"version": "v1.33.0"}}}' --type merge
Scale worker nodes
kubectl patch machinedeployment production-workers --patch '{"spec": {"replicas": 10}}' --type merge
Delete cluster (tất cả VMs, LBs sẽ được dọn dẹp)
kubectl delete cluster production-cluster
6. Crossplane — Control Plane Framework
Crossplane là alternative/complement cho CAPI — quản lý cloud resources (không chỉ clusters) bằng Kubernetes CRDs:
# Cài Crossplane helm repo add crossplane-stable https://charts.crossplane.io/stable helm install crossplane crossplane-stable/crossplane -n crossplane-system --create-namespaceCài AWS provider
kubectl apply -f - <<EOF apiVersion: pkg.crossplane.io/v1 kind: Provider metadata: name: provider-aws-ec2 spec: package: xpkg.upbound.io/upbound/provider-aws-ec2:latest EOF
# Tạo RDS instance bằng Crossplane
apiVersion: rds.aws.upbound.io/v1beta1
kind: Instance
metadata:
name: my-postgres
spec:
forProvider:
region: ap-southeast-1
instanceClass: db.t3.medium
engine: postgres
engineVersion: "16.3"
allocatedStorage: 20
username: admin
skipFinalSnapshot: true
writeConnectionSecretToRef:
namespace: default
name: my-postgres-conn # K8s Secret với connection info
7. IaC Comparison 2026
Tool Use Case Approach ────────────────────────────────────────────────────────────── Terraform Multi-cloud infra provisioning HCL, state file Pulumi Infra as code với real languages Python/TS/Go CAPI K8s cluster lifecycle K8s API, GitOps-friendly Crossplane Cloud resources via K8s API K8s API, Composition Helm K8s app deployment Templates, values Kustomize K8s manifest overlay Patch-based, no templates2026 Trend: CAPI + Crossplane combination
- CAPI: quản lý cluster lifecycle
- Crossplane: quản lý cloud resources (RDS, S3, etc.) được tham chiếu bởi apps
- ArgoCD/Flux: deploy tất cả qua GitOps
Tóm tắt
- Cluster API: quản lý K8s cluster lifecycle bằng K8s objects
- ClusterClass: template chuẩn để tạo nhiều clusters consistent
- Management cluster + Workload clusters: tách biệt rõ ràng
- Crossplane: quản lý cloud resources (DB, storage, network) bằng K8s CRDs
- CAPI + Crossplane + ArgoCD: full GitOps platform engineering stack 2026