Kubernetes on OVHcloud, in your own project.

Ankra builds Kubernetes on Public Cloud instances in your own OVHcloud project, or creates and runs OVHcloud Managed Kubernetes (MKS) for you. OVHcloud bills you for the instances and Ankra operates the cluster, its add-ons and your applications.

There are two ways to run Kubernetes on OVHcloud with Ankra. An Ankra Managed cluster is kubeadm (the default, with Cilium) or k3s on Public Cloud instances, with private nodes behind a managed network gateway, and it can spread across the three availability zones of an OVHcloud 3-AZ region. A Cloud Managed cluster is MKS, where OVHcloud runs the control plane on its free or standard plan and Ankra handles node pools, upgrades, stacks and GitOps.

If you already run MKS, Ankra can discover the cluster in your Public Cloud project and adopt it without touching it.

What OVHcloud gives you, and what is left

OVHcloud sells instances, vRack private networking, block storage, load balancers and a managed Kubernetes service. The platform on top is still yours to build.

Private nodes take wiring

Nodes with private addresses only need a vRack network, a gateway for egress and a bastion before anything can be installed on them.

The invisible platform layer

Ingress, certificates, DNS, monitoring and secrets come before your first deploy, on MKS as much as on plain instances.

Zones are a placement decision

An instance's zone is chosen when it is created and never changes. A request that names no zone tends to put every node in the same one.

Storage is zonal

OVHcloud block storage is replicated inside one zone and cannot attach from another. Spreading nodes alone does not make a database survive a zone outage.

The Ankra approach

One command.
Network to running cluster.

Ankra creates the private network, a managed network gateway for egress, a bastion and the instances in your project, installs Kubernetes with the OpenStack cloud controller manager and Cinder CSI driver, and then operates the cluster. The bastion is the only instance with a public IP, and it is an SSH jump host, not a router.

Two options are on by default. The networking stack installs Traefik, cert-manager and a Let's Encrypt issuer behind an OVHcloud load balancer, and public DNS gives the cluster a subdomain on ankra.cc so an ingress hostname gets its record and certificate automatically.

ankra cli
ankra cluster ovh create \
  --name my-cluster \
  --credential-id <ovh-credential-id> \
  --ssh-key-credential-id <ssh-key-credential-id> \
  --region EU-WEST-PAR \
  --availability-zones eu-west-par-a,eu-west-par-b,eu-west-par-c \
  --control-plane-count 3 \
  --worker-count 3
provisioning network, gateway, bastion and instances in 3 zones

Three zones in one region

In the 3-AZ regions EU-WEST-PAR and EU-SOUTH-MIL, Ankra spreads control planes and each node group across the zones. A spread needs at least three control planes, so etcd keeps quorum when a zone goes down.

Regions you already use

Gravelines, Strasbourg, Beauharnois, Warsaw, Frankfurt, London, Singapore and Sydney are in the OVH reference. Ask the CLI which ones your project can deploy in.

MKS, created and operated

Create MKS on the free or standard control plane plan, with a private network, anti-affinity, autoscaling bounds and monthly or hourly node billing. Upgrades and pool changes run from the CLI, portal or API.

Stacks in Git

Ingress, cert-manager, monitoring and your applications live in versioned Stacks with dependency ordering, committed to a repository you connect.

First-boot scripts per node group

A node group can carry a cloud-init document that runs on every instance it creates, replacements included. Labels and taints can be set when the group is added.

AI operations

A failing pod gets an analysis that correlates logs, events and deploy history, and the AI drafts the fix for a person to approve.

Step by step

Create a Kubernetes cluster on OVHcloud

The same flow works in the dashboard, the CLI and the API. These are the CLI steps from the guide.

  1. 1

    Store your OVHcloud API credentials

    Ankra needs an application key, application secret, consumer key and your Public Cloud project ID. The CLI prompts for the keys.

    ankra credentials ovh create --name my-ovh-cred --project-id <project-id>
  2. 2

    Add an SSH key credential

    Bring your own public key or let Ankra generate one. It goes on every instance.

    ankra credentials ovh ssh-key create --name my-ssh-key --generate
  3. 3

    Check which regions your project can use

    Regions differ per project, and one that is not enabled on the private network fails during network setup. Add --with-zones to see which regions are 3-AZ.

    ankra cluster ovh regions --credential-id <ovh-credential-id> --with-zones
  4. 4

    Create the cluster

    Pick the region, the control plane count and the worker count. Flavors default to b3-16 for control planes and workers and c3-4 for the bastion. Keep kubeadm or pass --distribution k3s.

  5. 5

    Check the nodes

    The cluster turns Online once the Ankra Agent connects. Point kubectl at it through Ankra and every node should be Ready.

    ankra cluster kubeconfig add my-cluster --use
    kubectl get nodes

Public Cloud instances or MKS

Both run with Ankra. The choice is who runs the control plane and how much placement control you need.

Ankra Managed on OVHcloud instancesOVHcloud MKS through Ankra
Control planeRuns on your instances, operated by AnkraRun by OVHcloud, on the free or standard plan
Distributionkubeadm with Cilium, or k3sMKS
Availability zonesSpread or pin node groups in 3-AZ regionsAnti-affinity where OVHcloud supports it
Node autoscalingAutoscaling bounds per node groupAutoscaling bounds per node pool
Already running oneBuild a new clusterImport the MKS cluster untouched
Know before you start

OVHcloud specifics worth knowing

These come straight from the guide.

  • Node groups move to larger flavors only. Each node is powered off, resized and powered on. For smaller nodes, create a new group and delete the old one.
  • Stopping a cluster releases the instances, the bastion and the network gateway. The private network is kept for the next start, and Cinder volumes are kept and billed.
  • Zone placement for volumes is pending on OVHcloud. Until it is re-enabled, pin each stateful replica to a node group in one zone so its pod is always scheduled where its volume is.
  • A zone-tolerant database needs replication at the application layer, for example CloudNativePG with one replica per zone, as well as spread nodes.
  • Control planes cannot be moved to new zones in place. A zone-spread control plane on an existing cluster means recreating the cluster. Workers can be moved by adding a pinned node group.

Questions teams actually ask

Does OVHcloud have managed Kubernetes?+

Yes. OVHcloud Managed Kubernetes (MKS) runs the control plane on a free or standard plan. Ankra can create MKS clusters, manage their node pools and upgrades, and import MKS clusters you already run. Ankra can also build kubeadm or k3s on Public Cloud instances when you want control over the distribution, the network and zone placement.

Can a Kubernetes cluster on OVHcloud span availability zones?+

Yes, in the 3-AZ regions EU-WEST-PAR and EU-SOUTH-MIL. Ankra spreads control planes and each node group across the three zones, and refuses a spread with fewer than three control planes. Every other OVHcloud region is a single failure domain.

Which OVHcloud regions does Ankra support?+

The Ankra reference lists Gravelines, Strasbourg, Beauharnois, Warsaw, Frankfurt, London, Singapore and Sydney, and Ankra supports the 3-AZ regions for zone spread. The regions enabled on each project differ, so run ankra cluster ovh regions with your credential before you create a cluster.

What does Ankra cost on top of OVHcloud?+

Ankra bills on worker vCPUs only. Every plan includes 30 worker vCPUs free, controller nodes are never billed, and the free tier needs no credit card. OVHcloud bills you directly for the instances, storage and network.

Free tier available

Your first OVHcloud cluster fits in the free allowance

30 worker vCPUs included, controller nodes never billed, and no credit card for the free tier. Bring your OVHcloud project.

Ankra is an independent platform and is not affiliated with or endorsed by OVH SAS. OVHcloud prices and regions can change, so check ovhcloud.com for current terms. Product details on this page were checked against the Ankra documentation in October 2026.