Skip to main content
Choose DigitalOcean when your team already runs on DigitalOcean and you want a Kubernetes cluster whose control plane you own, on Droplets in your own account. Ankra creates the VPC, NAT gateway, bastion and Droplets, installs Kubernetes and the DigitalOcean cloud integration, and then operates the cluster for you - this is an Ankra Managed cluster. DigitalOcean bills you directly. If you would rather DigitalOcean ran the control plane, use DOKS instead; Managed Kubernetes compares the two.

Before you start

  • A DigitalOcean personal access token with read and write scope, stored as a DigitalOcean credential. Tokens start with dop_v1_.
  • An SSH key credential - your own public key, or one Ankra generates. See SSH Key Credentials.
  • Room in your account limits for the Droplets, a VPC, load balancers and volumes. Check them in the DigitalOcean Control Panel; DigitalOcean support raises them.

Create the cluster

1

Open the create dialog

Go to Clusters, click Create cluster and pick DigitalOcean under Ankra Managed.
2

Credential & Region

Pick the DigitalOcean credential and an SSH key (or add either inline), and a region, for example nyc3, fra1 or lon1.
3

Network & Compute

Keep or change the VPC range, then pick the bastion Droplet size (for example s-1vcpu-1gb), the control plane count (1 or 3) and size (for example s-2vcpu-4gb), and one or more worker node groups. The wizard shows each size’s vCPUs, memory and monthly price.
4

Kubernetes

Keep kubeadm (the default, with Cilium) or pick k3s, and optionally the version. See Choices fixed at create time for the CNI and etcd options.
5

GitOps

Optionally connect a Git repository; Ankra commits the cluster’s stacks to it. Skipping GitOps still deploys the DigitalOcean cloud controller manager and CSI driver. Two checkboxes are on by default:
  • Include Networking Stack - Traefik, cert-manager and a Let’s Encrypt ClusterIssuer, with Traefik behind a DigitalOcean load balancer.
  • Include Public DNS - a delegated subdomain on ankra.cc with external-dns wired, so an ingress hostname under it gets its DNS record and TLS certificate automatically.
6

Details

Name the cluster, set its environment, and click Create cluster. A progress view follows the VPC, NAT gateway, bastion, Droplets, Kubernetes installation and Ankra Agent.

Verify

  1. The cluster moves from Provisioning to Online in the clusters list once the Ankra Agent has connected.
  2. Point kubectl at it through Ankra (this needs a Cluster Access grant) and check the nodes:
    Every control plane and worker should be Ready. See Accessing Clusters with kubectl.

What Ankra created in your account

  • A VPC for all traffic between the Droplets.
  • A VPC NAT gateway, set as the VPC’s default route - the egress path for the nodes. DigitalOcean bills it separately; see VPC NAT gateway pricing.
  • A bastion Droplet - the only Droplet with a public IP and the only SSH entry point. It carries no workload or egress traffic.
  • Control plane and worker Droplets with private IPs only, and dedicated etcd Droplets for a kubeadm cluster with external etcd.
  • Two tag-scoped cloud firewalls, kept as defence in depth.
  • The digitalocean-cloud-provider stack: the DigitalOcean cloud controller manager (load balancers for LoadBalancer Services) and CSI driver (block storage through the do-block-storage StorageClass), using your credential.
The DigitalOcean Reference has the full layout.

DigitalOcean specifics

  • Clusters created before private-Droplet support keep their original layout: every Droplet has a public IP and the tag-scoped cloud firewalls are the ingress boundary. Public networking is fixed when a Droplet is created, so those clusters - including nodes added when you scale them - stay on that model. Only new clusters get private nodes and a NAT gateway.
  • Resizing a node group powers each Droplet off, resizes it and powers it on again, with brief downtime for its workloads. Droplet sizes only grow; for smaller nodes, create a new group and delete the old one.
  • A stop deletes the node Droplets, the bastion and the VPC NAT gateway, and keeps the cluster’s configuration, network definition and SSH keys. The block storage volumes the CSI driver created are kept and keep billing while the cluster is stopped.
  • Terminating deletes the Droplets, NAT gateway, VPC and SSH keys. Anything left over from an earlier teardown can be removed in the DigitalOcean Control Panel.

Operate it

Day-2 tasks work the same way on every Ankra Managed provider, with the CLI name digitalocean:

Troubleshooting