Kubernetes on Proxmox VE
Kubernetes on the Proxmox hosts you already own.
Ankra creates the virtual machines in your Proxmox VE datacenter, installs kubeadm or k3s, and then operates the cluster for you, with upgrades, node groups and GitOps stacks. You bring the Proxmox nodes, storage and bridges, and there is no cloud bill.
To run Kubernetes on Proxmox with Ankra, you store a Proxmox VE API token as a credential and pick a host, or several hosts to spread over. Ankra fills in safe defaults where they are missing, such as an Ubuntu 24.04 cloud-init template and a private NAT network, then clones the bastion, control plane and worker VMs and installs Kubernetes.
It works on-premises and on dedicated servers. When the Proxmox API is not reachable from the internet, Ankra tunnels the API calls and the SSH connections through a jumphost you attach to the credential.
Proxmox gives you VMs. A cluster needs more.
Hand-built Kubernetes on Proxmox works until it has to be upgraded, grown or rebuilt by someone else.
Templates, bridges and DHCP first
Every VM needs a cloud-init template, a bridge and an address before Kubernetes can even start. Getting that right on each host is half the work.
Scripts that only one person understands
Terraform plus kubeadm or k3s scripts work until the person who wrote them moves on. Upgrades become the job nobody wants.
The invisible platform layer
Ingress, certificates, DNS, monitoring and secrets come before your first deploy, and none of them ship with Proxmox.
One host is one failure
If every VM sits on one Proxmox node, losing that node takes the whole cluster with it.
One command.
VMs to running cluster.
When you save the credential, Ankra checks each node. If a node has no cloud-init template, it downloads the Ubuntu 24.04 cloud image and registers it. If no bridge exists, it can convert the management interface to vmbr0. It also creates a private SDN network called ankra with NAT and DHCP, so VMs reach the internet without being exposed.
Then it clones the bastion, control plane and worker VMs, installs Kubernetes, and operates the cluster from there. Two options are on by default, a networking stack with Traefik and cert-manager, and a public DNS subdomain on ankra.cc.
ankra cluster proxmox create \
--name my-cluster \
--credential-id <proxmox-credential-id> \
--ssh-key-credential-id <ssh-key-credential-id> \
--node pve01 \
--storage local-lvm \
--bridge ankra \
--control-plane-count 1 \
--control-plane-instance-type px-medium \
--worker-count 2 \
--worker-instance-type px-mediumSpread across hosts
Pick two or more Proxmox nodes and Ankra places each control plane, etcd member and worker on the host with the fewest members of that role or group. Every node is labelled with its host, so topology spread works out of the box.
Behind a firewall
Attach an SSH jumphost to the credential and Ankra reaches the Proxmox API and the VMs through it. Self-signed certificates are fine with TLS insecure switched on.
Stacks in Git
Ingress, cert-manager, monitoring and your applications live in versioned Stacks with dependency ordering, committed to a repository you connect.
Cluster Mesh with UpCloud
Join Proxmox and UpCloud clusters into one Cilium ClusterMesh, so services in your rack and in the cloud reach each other over an encrypted WireGuard overlay.
Costs for hardware you own
Proxmox has no list pricing, so Cloud Cost prices each cluster from a rate card on its credential. It starts with default rates you can change.
AI operations
A failing pod gets an analysis that correlates logs, events and deploy history, and the AI drafts the fix for a person to approve.
Create a Kubernetes cluster on Proxmox VE
The same flow works in the dashboard, the CLI and the API. These are the CLI steps from the guide.
- 1
Prepare each Proxmox node
Install dnsmasq for the private network's DHCP and leave its own service disabled. The Proxmox API must use HTTPS and be reachable from Ankra, directly or through a jumphost.
apt install dnsmasq && systemctl disable --now dnsmasq - 2
Store the Proxmox VE credential
Give Ankra the API URL and an API token with VM management privileges. If Ankra should set up storage or networking, the token also needs Datastore.Allocate, Sys.Modify and SDN.Use. The CLI prompts for the token secret.
ankra credentials proxmox create --name my-proxmox \ --api-url https://pve.example:8006 --token-id 'root@pam!ankra' - 3
Add an SSH key credential
A Proxmox cluster takes a single key, your own or one Ankra generates.
ankra credentials proxmox ssh-key create --name my-ssh-key --generate - 4
See what the credential can use
List hosts, storages, bridges, templates and the VM sizes before you create the cluster.
ankra cluster proxmox hosts --credential-id <proxmox-credential-id> ankra cluster proxmox sizes - 5
Create the cluster and check the nodes
Pick the node, storage and the
ankranetwork, then the control plane and worker sizes. Add--placement-nodes pve01,pve02,pve03to spread across hosts. Once the cluster is Online, every node should be Ready.ankra cluster kubeconfig add my-cluster --use kubectl get nodes
Hand-built on Proxmox, or built by Ankra
Two honest ways to get Kubernetes onto hardware you own.
| Your own scripts on Proxmox | Proxmox VE + Ankra | |
|---|---|---|
| Templates and networking | Built and kept in sync by hand | Created where missing when the credential is saved |
| Distribution | Whatever the scripts install | kubeadm with Cilium, or k3s with Flannel, Calico or Cilium |
| Spread across hosts | Placed by hand | Balanced per role or node group, labelled by host |
| Upgrades and node groups | Your runbook | Upgrade, add, scale and resize from the CLI, dashboard or API |
| Ingress and certificates | Assemble it yourself | Optional networking stack with Traefik and cert-manager |
| When it breaks | You, with kubectl | AI analysis with a drafted fix for you to approve |
Proxmox specifics worth knowing
These come straight from the guide.
- There is no cloud controller manager, so
LoadBalancerServices are not provisioned. Expose workloads with NodePort, an ingress controller or a load balancer you deploy yourself. - Host spread needs at least three control planes, and three or more hosts are recommended. With two hosts, losing the one with the control plane majority still takes the API down.
- Ankra does not enrol VMs in Proxmox HA groups and never live-migrates VMs after a failure. Resilience comes from Kubernetes replicas spread across hosts.
- The bastion runs on the primary node and is not spread. If that host fails, workloads keep running but Ankra cannot manage the cluster until it returns.
- Node groups grow to larger sizes only. Each VM is powered off, resized and powered on. For smaller VMs, create a new group and delete the old one.
k3s on Proxmox
Pick k3s in the Kubernetes step of the wizard or pass --distribution k3s on the CLI. Flannel is the default CNI for k3s, and Calico or Cilium are available. With the networking stack on, Traefik and cert-manager run as Ankra managed stacks through the k3s service load balancer. With it off, k3s keeps its bundled Traefik.
kubeadm stays the default and always uses Cilium. Pick it when you want dedicated etcd VMs (the external etcd topology) or Cluster Mesh, which needs kubeadm.
VM sizes run from px-small to px-xlarge, listed in the Proxmox VE reference.
Guides and comparisons
Questions teams actually ask
Can Proxmox run Kubernetes?+
Yes. Kubernetes runs on Proxmox VE as virtual machines. Ankra creates those VMs from a cloud-init template, installs kubeadm or k3s, and operates the cluster afterwards, including upgrades and node groups.
Should I use k3s or kubeadm on Proxmox?+
Both are supported. kubeadm is the default, uses Cilium, offers dedicated etcd VMs and is required for Cluster Mesh. k3s is lighter and lets you pick Flannel, Calico or Cilium as the CNI.
Do LoadBalancer Services work on Proxmox?+
Not out of the box. Proxmox has no cloud controller manager, so Ankra does not provision LoadBalancer Services there. Use the optional ingress stack, NodePort Services or a load balancer you deploy yourself.
Does my Proxmox server need to be on the internet?+
No. Attach an SSH jumphost to the Proxmox credential and Ankra tunnels the API calls and node SSH through it. The Ankra agent inside the cluster only makes outbound connections.
What does Ankra cost for a Proxmox cluster?+
Ankra bills on worker vCPUs only. Every plan includes 30 worker vCPUs free, controller nodes are never billed, and the free tier needs no credit card. There is no cloud bill, because the hardware is yours.
Your first Proxmox cluster fits in the free allowance
30 worker vCPUs included, controller nodes never billed, and no credit card for the free tier. Bring your Proxmox hosts.
Ankra is an independent platform and is not affiliated with or endorsed by Proxmox Server Solutions GmbH. Product details on this page were checked against the Ankra documentation in October 2026.