Kubernetes on UpCloud
Kubernetes on UpCloud, in your own account.
Ankra builds Kubernetes on servers in your own UpCloud account, or creates and runs UpCloud Managed Kubernetes (UKS) for you. Either way UpCloud bills you for the servers and Ankra operates the cluster, its add-ons and your applications.
There are two ways to run Kubernetes on UpCloud with Ankra. An Ankra Managed cluster is kubeadm (the default, with Cilium) or k3s on UpCloud servers, with private nodes behind a managed NAT gateway. A Cloud Managed cluster is UKS, where UpCloud runs the control plane and Ankra handles node pools, upgrades, stacks and GitOps.
Ankra's own production platform runs on UpCloud in Helsinki. We wrote up the move, the bill and the rough edges in We Moved Our Production to UpCloud. To try it, pair Ankra's free tier with UpCloud's 500 euro trial.
What UpCloud gives you, and what is left
UpCloud sells fast servers, private SDN networks, load balancers and a managed Kubernetes service. The platform on top is still yours to build.
Networks stay inside one zone
Every UpCloud private network, router and managed load balancer lives in a single zone. A cluster that should survive a zone outage needs more than one network and something to join them.
The invisible platform layer
Ingress, certificates, DNS, monitoring and secrets come before your first deploy, on UKS as much as on plain servers.
Node autoscaling on UKS is a separate job
On UKS you run UpCloud's Cluster Autoscaler yourself. Ankra sets a pool to a fixed count and never fights the autoscaler once the pool is marked as externally managed.
Private nodes take wiring
Nodes with no public interface need a router, a NAT gateway and a bastion before anything can be installed on them.
One command.
Router to running cluster.
Ankra creates the SDN router, the private network, the managed NAT gateway, a bastion and the servers in your account, installs Kubernetes and the UpCloud cloud controller manager and CSI driver, and then operates the cluster. The bastion is the only server with a public IP, and it is an SSH jump host only.
Two options are on by default. The networking stack installs Traefik, cert-manager and a Let's Encrypt issuer behind an UpCloud load balancer, and public DNS gives the cluster a subdomain on ankra.cc so an ingress hostname gets its record and certificate automatically.
ankra cluster upcloud create \
--name my-cluster \
--credential-id <upcloud-credential-id> \
--ssh-key-credential-id <ssh-key-credential-id> \
--zone fi-hel1 \
--control-plane-count 1 \
--control-plane-plan 2xCPU-4GB \
--worker-count 2 \
--worker-plan 4xCPU-8GBThirteen zones
Pick any UpCloud zone in Helsinki (two zones), Stockholm, Frankfurt, Amsterdam, London, Warsaw, Madrid, Chicago, New York, San Jose, Singapore and Sydney. The UpCloud reference lists them.
UKS, created and operated
Create UKS with a development or production control plane plan, add and scale node pools with live pricing, upgrade Kubernetes, or import a UKS cluster you already run.
Stacks in Git
Ingress, cert-manager, monitoring and your applications live in versioned Stacks with dependency ordering, committed to a repository you connect.
Across zones, over WireGuard
Ankra can stretch a kubeadm cluster over three or more zones with one network and NAT gateway per zone, joined by a WireGuard mesh. It is in closed beta and switched on per organisation.
Cluster Mesh with Proxmox
Join UpCloud and Proxmox VE clusters into one Cilium ClusterMesh, so a global service resolves to healthy backends in either place.
AI operations
A failing pod gets an analysis that correlates logs, events and deploy history, and the AI drafts the fix for a person to approve.
Create a Kubernetes cluster on UpCloud
The same flow works in the dashboard, the CLI and the API. These are the CLI steps from the guide.
- 1
Store an UpCloud API token
Create a token with permission to manage servers, networking, storage and Kubernetes, and store it as an UpCloud credential. The CLI prompts for the token.
ankra credentials upcloud create --name my-upcloud-token - 2
Add an SSH key credential
Bring your own public key or let Ankra generate one. It goes on every server.
ankra credentials upcloud ssh-key create --name my-ssh-key --generate - 3
Create the cluster
Pick a zone, the control plane count and plan, and the worker plan and count. Keep kubeadm or pass
--distribution k3s. In the dashboard the wizard shows each plan's vCPUs, RAM and monthly price. - 4
Check the nodes
The cluster turns Online once the Ankra Agent connects. Point kubectl at it through Ankra and every node should be Ready.
ankra cluster kubeconfig add my-cluster --use kubectl get nodes
UpCloud servers or UKS
Both run with Ankra. The choice is who runs the control plane and what you need from it.
| Ankra Managed on UpCloud servers | UKS through Ankra | |
|---|---|---|
| Control plane | Runs on your UpCloud servers, operated by Ankra | Run by UpCloud |
| Distribution | kubeadm with Cilium, or k3s | UKS, with a development or production plan |
| Spread across zones | WireGuard mesh over three or more zones (closed beta) | Not managed by Ankra |
| Prices while you build | Each plan's monthly price in the wizard | Live node plan pricing and a monthly summary |
| Node autoscaling | Autoscaling bounds per node group | UpCloud Cluster Autoscaler, run by you |
| Cluster Mesh with Proxmox | Yes, on kubeadm | No |
| Already running one | Build a new cluster | Import the UKS cluster untouched |
UpCloud specifics worth knowing
These come straight from the guide.
- Node groups move to larger plans only. Each node is powered off, resized and powered on. For smaller nodes, create a new group and delete the old one.
- Stopping a cluster releases the servers, the bastion and the NAT gateway. CSI storage volumes are kept, and UpCloud keeps billing them.
- Block storage is zone local. On a multi-zone cluster, persistent volumes are created in the primary zone, so run stateful workloads there or use replicated storage.
- Multi-zone placement needs kubeadm, at least three zones and three control planes, and it is decided at create time. A single-zone cluster that may grow is created with
--network-mode wireguard_mesh.
Guides and comparisons
Questions teams actually ask
Does UpCloud have managed Kubernetes?+
Yes. UpCloud Managed Kubernetes (UKS) runs the control plane for you. Ankra can create UKS clusters, manage their node pools and upgrades, and import UKS clusters you already run. Ankra can also build kubeadm or k3s clusters on plain UpCloud servers when you want control over the distribution and networking.
Which UpCloud zones does Ankra support?+
Ankra lists thirteen UpCloud zones in its reference, covering Helsinki (two zones), Stockholm, Frankfurt, Amsterdam, London, Warsaw, Madrid, Chicago, New York, San Jose, Singapore and Sydney. Available plans can vary by zone.
Can a Kubernetes cluster span several UpCloud zones?+
UpCloud private networks stay inside one zone, so a cluster is single-zone by default. Ankra can stretch a kubeadm cluster across three or more zones with one network per zone and a WireGuard mesh between the nodes. This is in closed beta, so contact support to have it switched on.
What does Ankra cost on top of UpCloud?+
Ankra bills on worker vCPUs only. Every plan includes 30 worker vCPUs free, controller nodes are never billed, and the free tier needs no credit card. UpCloud bills you directly for the servers, storage and network.
Is there an UpCloud trial?+
UpCloud has offered a 500 euro trial over 30 days through its signup page. Check the current terms on UpCloud's site before you rely on it.
Your first UpCloud cluster fits in the free allowance
30 worker vCPUs included, controller nodes never billed, and no credit card for the free tier. Bring your UpCloud account.
Ankra is an independent platform and is not affiliated with or endorsed by UpCloud Ltd. UpCloud prices and offers can change, so check upcloud.com for current terms. Product details on this page were checked against the Ankra documentation in October 2026.