Before you start
- A Morpheus API credential: the appliance URL and a long-lived API access token. See Morpheus Credentials.
- An SSH key credential for instance access - your own public key, or one Ankra generates. See SSH Key Credentials.
- In Morpheus: a group and a cloud the token can provision into, a network with DHCP (instances get their addresses from it), an instance layout based on a Linux cloud image (optionally pinned to a virtual image), and service plans to size the bastion, control plane and workers.
- API reachability. The Morpheus API must be reachable from Ankra, directly or through an SSH jumphost.
Hybrid connectivity (SSH jumphost)
If Ankra cannot reach the Morpheus appliance and the instance network directly, attach an SSH jumphost (host, port, username and private key) to the Morpheus credential; Ankra then tunnels both the Morpheus API calls and the SSH connections to your nodes through it. If the appliance uses a self-signed certificate, enable TLS insecure (tls_insecure) on the credential. Both are set on the credential - see Morpheus Credentials.
Create the cluster
- Dashboard
- CLI
- API
1
Open the create dialog
Go to Clusters, click Create cluster and pick Morpheus under Ankra Managed.
2
Credential
Pick the Morpheus credential and an SSH key, or add either inline.
3
Placement
Pick the Morpheus Group, Cloud and Network for the instances, and the Layout they are provisioned from. The network must provide DHCP.
4
Compute
Pick the bastion’s service plan, the control plane count (1 or 3) and service plan, worker node groups, and for kubeadm the etcd topology. The wizard shows each plan’s vCPUs and memory; cost estimates are not available for Morpheus.
5
Kubernetes
Keep kubeadm (the default, with Cilium) or pick k3s and its CNI, and optionally the version. See Choices fixed at create time.
6
Review
Name the cluster and set its environment. Two checkboxes are on by default:
- Include Networking Stack - Traefik and cert-manager as Ankra-managed stacks. On k3s they run through the built-in service load balancer; unchecked, k3s keeps its bundled Traefik and no certificate manager (a kubeadm cluster gets no ingress controller or certificate manager at all).
- Include Public DNS - a delegated subdomain on
ankra.ccwith external-dns wired, so an ingress hostname under it gets its DNS record and TLS certificate automatically.
Verify
- The cluster moves from Provisioning to Online in the clusters list once the Ankra Agent has connected.
-
Point
kubectlat it through Ankra (this needs a Cluster Access grant) and check the nodes:Every control plane and worker should beReady. See Accessing Clusters with kubectl.
What Ankra created through your appliance
- A bastion instance - the only SSH access point Ankra uses to reach the nodes. It carries no workload or egress traffic. With a jumphost on the credential, Ankra reaches both the Morpheus API and the bastion through it.
- Control plane and worker instances in the group, cloud and network you picked, booting from the layout’s image, plus dedicated etcd instances for a kubeadm cluster with external etcd.
LoadBalancer Services are not provisioned, so expose workloads with NodePort Services, an ingress controller, or a load balancer you deploy yourself. The Morpheus Reference has the full layout.
Morpheus specifics
- Numeric IDs everywhere. Groups, clouds, networks, layouts, virtual images and service plans are the numeric IDs from your appliance; node groups are sized by a numeric
plan_id. - Resizing a node group moves it to a larger service plan: each instance is powered off, resized and powered on again, with brief downtime for its workloads. Plans only grow; for smaller nodes, create a new group and delete the old one.
- Restarting a single node is not available for Morpheus clusters. The bastion is resized from the dashboard or the API;
ankra cluster morpheus nodes list|getlists and inspects the nodes. - A stop captures the cluster’s etcd state through the credential’s jump host before the instances are deleted. Terminating deletes every instance Ankra created (bastion, control planes, workers and etcd instances) and leaves your Morpheus groups, clouds, networks and virtual images untouched.
- No cost estimate in the create wizard. Cloud Cost prices running clusters once you set a rate card on the Morpheus credential; until then they show as not priced.
Operate it
Day-2 tasks work the same way on every Ankra Managed provider, with the CLI namemorpheus:
- Node groups and legacy worker scaling
- Control plane
- The bastion
- SSH access and keys
- Upgrade Kubernetes
- Stop and start
- Terminate a cluster