Skip to content

Distributed Regional Management Control Planes #1896

Description

@DinaBelova

Goals
The goal is to provide a solution that supports hosting k0rdent managed, hosted control planes (k0smotron based) for child clusters on a designated regional kubernetes cluster.

Drivers:

  • Network and security separation between the k0rdent Mothership and the cluster hosting the hosted control plane pods.
  • Provide for better resilience for the hosted control plane pods
  • Simplify separation of credentials for hosted control planes

The solution needs to provide for the following: (see high level use cases for more)

  • a standard out of the box mechanism that can be deployed by default with k0rdent.
  • The ability for an platform operator to designate remote kubernetes cluster(s) as the target for the hosted control plane

Functional Requirements:

  • Delegation of Hosted Control plane alternative regional cluster

Major deliverables

  • The ability for an platform operator to designate remote kubernetes cluster(s) as the target for the hosted control plane
  • Options for High resilience for hosted control planes
    • Recoverable within seconds
    • Highly Available
  • Highly secure deployments
  • Support for all standard k0rdent infrastructure providers
  • Strict network isolation of hosted control plane endpoints

Who it benefits
Enterprises and business that require large numbers of kubernetes clusters or who want to sell kubernetes clusters as a service

Acceptance criteria

  • Design proposal for the solution
  • Full automation of all steps when deploying a new child cluster
  • Full clean up of all resources when a child cluster is removed
  • Configurable target deployment cluster for hosted control planes
  • Standard cluster and service template patterns for hosted control plane regional clusters
  • Strong tenant separation of hosted control plane across tenants (Multi-tenancy)
  • Observability and alerting of hosted control plane components
  • Support for the Mothership Cluster and the Regional cluster that hosts the control planes to be on separate network segments with limited secured connectivity.

Assumptions
Modern open source solution exists. All components under k0rdent umbrella (Kubernetes, kcm, ksm, KOF, etc.) - all support k0smotron hosted control plane

Out of scope
For the first phase delivery:

  • IDM for the Child Clusters is out of scope, this will need to be addressed in a later iteration - Design proposals should be done in first phase
  • Demonstrable failover/recovery/High Availability mechanism this will be addressed later

User stories

  • As a Platform Lead I want to define regions and assign clusters to those regions so that I can manage them efficiently and maintain operational oversight during control plane outages.
  • As a platform lead I want to be able to separate the hosted control plane pods onto a separate host from the mothership cluster to support clear separation for security domains.

Activity

  1. added
    epicLarge body of work, can be broken down into individual issues
    on Aug 27, 2025
  2. added
    triage-okTriaged issue, can be taken into work
    and removed
    needs-triageNew / reopened / transferred issue that requires triage
    on Aug 27, 2025
  3. moved this from Todo to In Progress in k0rdenton Aug 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

epicLarge body of work, can be broken down into individual issuestriage-okTriaged issue, can be taken into work

Type

No type

Projects

  • Status
    In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions