kubernetes
Reading order: RKE2/Kubernetes from scratch
- What Kubernetes actually is, and how it works
- What RKE2 actually is, and how its pieces fit together
- Installing a single-node RKE2 server for a lab
- Getting kubectl to work against RKE2 from off the node
- Pods, Deployments, Services — the minimum object model
- RKE2's default CNI is Canal, and you pick it before the first start
- RKE2 ships no default StorageClass, and a PVC will sit Pending forever
- RKE2's ingress default moved to Traefik, because ingress-nginx is ending
- Going HA with RKE2: three servers, one address, and the datastore choice
- RKE2's etcd snapshots run on schedule, but a fresh cluster starts with none
- RKE2 leaves its servers schedulable, so your workloads have been running on the control plane all along
Everything in this topic, oldest first
What Kubernetes actually is, and how it works - 2026-09-17
Starting a series on learning Kubernetes via RKE2 from scratch. Before touching RKE2 specifically, the part worth getting solid first: what a Kubernetes cluster is made of, and the one idea — reconcile actual state toward desired state, continuously — that everything else is…
Cleanly stopping an RKE2 node for planned maintenance - 2026-09-17
Draining and stopping a node the right way for a patch/reboot is mostly ordinary Kubernetes practice; the one RKE2-specific trap is reaching for the wrong bundled script to actually stop it.
Installing a single-node RKE2 server for a lab - 2026-09-18
Third entry in the RKE2/Kubernetes series. A lab needs the minimum viable cluster: one machine running rke2-server, which acts as both control plane and worker — no separate node to join, no agent install at all for this size.
Getting kubectl to work against RKE2 from off the node - 2026-09-18
Fourth entry in the RKE2/Kubernetes series. The lab-install entry got a node running and pointed out the trap without fixing it: the generated kubeconfig only works from the node itself. Here's why, and what actually needs to change to run kubectl from a workstation instead.
What RKE2 actually is, and how its pieces fit together - 2026-09-18
A closer look at the "packaging" the Kubernetes-fundamentals entry waved at: what RKE2 specifically is, why it exists as a separate thing from plain kubeadm Kubernetes or Rancher's own older RKE, and how its control plane actually starts up given that a Kubernetes control plane…
Pods, Deployments, Services — the minimum object model - 2026-09-18
Fifth entry in the RKE2/Kubernetes series. kubectl has been reachable from off the node since the previous entry; this is the first one to actually point it at something — the three objects that account for almost everything you'll run day to day, and one RKE2-specific gap…
RKE2's default CNI is Canal, and you pick it before the first start - 2026-09-18
Sixth entry in the RKE2/Kubernetes series. Everything in the previous entry — Pods getting IPs, a Service reaching Pods that might be on another node — quietly assumed pod networking already worked. The component providing that is the CNI plugin, and on RKE2 it's the one…
RKE2's ingress default moved to Traefik, because ingress-nginx is ending - 2026-09-18
Eighth entry in the RKE2/Kubernetes series. The storage entry was about something RKE2 never shipped. This one is about something it did ship, for years, as the obvious default — and has now moved away from, because the upstream project is shutting down.
RKE2 ships no default StorageClass, and a PVC will sit Pending forever - 2026-09-18
Seventh entry in the RKE2/Kubernetes series. The CNI entry covered something RKE2 bundles and makes permanent; this one covers the opposite — a thing it deliberately doesn't bundle at all, where the failure mode is silence rather than an error.
Going HA with RKE2: three servers, one address, and the datastore choice - 2026-09-18
Ninth entry in the RKE2/Kubernetes series. Everything so far has run on the single node from the lab install, where "the control plane" and "that one machine" are the same thing. This is what changes when they stop being the same thing — and the two decisions that get made…
RKE2's etcd snapshots run on schedule, but a fresh cluster starts with none - 2026-09-19
Tenth entry in the RKE2/Kubernetes series. The HA entry closed on a warning: snapshots run without being configured, but quorum surviving a node dying and cluster state being recoverable are different guarantees. This entry actually tests that second one — snapshot, corrupt the…
Restoring RKE2 etcd across an HA cluster, and backing snapshots up to S3 - 2026-09-20
The etcd snapshot/restore drill on this site covers the single-node case end to end, including the two gotchas that aren't in RKE2's own docs — the server: URL check that blocks cluster-reset, and the teardown that runs before that check does. This entry is the reference for…
RKE2 leaves its servers schedulable, so your workloads have been running on the control plane all along - 2026-09-20
Eleventh entry in the RKE2/Kubernetes series. Ten entries in, every Pod created along the way has landed on a node without anyone choosing which one — including on the multi-server cluster from the HA entry, where some of those Pods were sharing a machine with etcd and the API…