Kubernetes on UpCloud, in your own account.

Ankra builds Kubernetes on servers in your own UpCloud account, or creates and runs UpCloud Managed Kubernetes (UKS) for you. Either way UpCloud bills you for the servers and Ankra operates the cluster, its add-ons and your applications.

There are two ways to run Kubernetes on UpCloud with Ankra. An Ankra Managed cluster is kubeadm (the default, with Cilium) or k3s on UpCloud servers, with private nodes behind a managed NAT gateway. A Cloud Managed cluster is UKS, where UpCloud runs the control plane and Ankra handles node pools, upgrades, stacks and GitOps.

Ankra's own production platform runs on UpCloud in Helsinki. We wrote up the move, the bill and the rough edges in We Moved Our Production to UpCloud. To try it, pair Ankra's free tier with UpCloud's 500 euro trial.

What UpCloud gives you, and what is left

UpCloud sells fast servers, private SDN networks, load balancers and a managed Kubernetes service. The platform on top is still yours to build.

Networks stay inside one zone

Every UpCloud private network, router and managed load balancer lives in a single zone. A cluster that should survive a zone outage needs more than one network and something to join them.

The invisible platform layer

Ingress, certificates, DNS, monitoring and secrets come before your first deploy, on UKS as much as on plain servers.

Node autoscaling on UKS is a separate job

On UKS you run UpCloud's Cluster Autoscaler yourself. Ankra sets a pool to a fixed count and never fights the autoscaler once the pool is marked as externally managed.

Private nodes take wiring

Nodes with no public interface need a router, a NAT gateway and a bastion before anything can be installed on them.

The Ankra approach

One command.
Router to running cluster.

Ankra creates the SDN router, the private network, the managed NAT gateway, a bastion and the servers in your account, installs Kubernetes and the UpCloud cloud controller manager and CSI driver, and then operates the cluster. The bastion is the only server with a public IP, and it is an SSH jump host only.

Two options are on by default. The networking stack installs Traefik, cert-manager and a Let's Encrypt issuer behind an UpCloud load balancer, and public DNS gives the cluster a subdomain on ankra.cc so an ingress hostname gets its record and certificate automatically.

ankra cli
ankra cluster upcloud create \
  --name my-cluster \
  --credential-id <upcloud-credential-id> \
  --ssh-key-credential-id <ssh-key-credential-id> \
  --zone fi-hel1 \
  --control-plane-count 1 \
  --control-plane-plan 2xCPU-4GB \
  --worker-count 2 \
  --worker-plan 4xCPU-8GB
provisioning router, network, NAT gateway, bastion and servers

Thirteen zones

Pick any UpCloud zone in Helsinki (two zones), Stockholm, Frankfurt, Amsterdam, London, Warsaw, Madrid, Chicago, New York, San Jose, Singapore and Sydney. The UpCloud reference lists them.

UKS, created and operated

Create UKS with a development or production control plane plan, add and scale node pools with live pricing, upgrade Kubernetes, or import a UKS cluster you already run.

Stacks in Git

Ingress, cert-manager, monitoring and your applications live in versioned Stacks with dependency ordering, committed to a repository you connect.

Across zones, over WireGuard

Ankra can stretch a kubeadm cluster over three or more zones with one network and NAT gateway per zone, joined by a WireGuard mesh. It is in closed beta and switched on per organisation.

Cluster Mesh with Proxmox

Join UpCloud and Proxmox VE clusters into one Cilium ClusterMesh, so a global service resolves to healthy backends in either place.

AI operations

A failing pod gets an analysis that correlates logs, events and deploy history, and the AI drafts the fix for a person to approve.

Step by step

Create a Kubernetes cluster on UpCloud

The same flow works in the dashboard, the CLI and the API. These are the CLI steps from the guide.

  1. 1

    Store an UpCloud API token

    Create a token with permission to manage servers, networking, storage and Kubernetes, and store it as an UpCloud credential. The CLI prompts for the token.

    ankra credentials upcloud create --name my-upcloud-token
  2. 2

    Add an SSH key credential

    Bring your own public key or let Ankra generate one. It goes on every server.

    ankra credentials upcloud ssh-key create --name my-ssh-key --generate
  3. 3

    Create the cluster

    Pick a zone, the control plane count and plan, and the worker plan and count. Keep kubeadm or pass --distribution k3s. In the dashboard the wizard shows each plan's vCPUs, RAM and monthly price.

  4. 4

    Check the nodes

    The cluster turns Online once the Ankra Agent connects. Point kubectl at it through Ankra and every node should be Ready.

    ankra cluster kubeconfig add my-cluster --use
    kubectl get nodes

UpCloud servers or UKS

Both run with Ankra. The choice is who runs the control plane and what you need from it.

Ankra Managed on UpCloud serversUKS through Ankra
Control planeRuns on your UpCloud servers, operated by AnkraRun by UpCloud
Distributionkubeadm with Cilium, or k3sUKS, with a development or production plan
Spread across zonesWireGuard mesh over three or more zones (closed beta)Not managed by Ankra
Prices while you buildEach plan's monthly price in the wizardLive node plan pricing and a monthly summary
Node autoscalingAutoscaling bounds per node groupUpCloud Cluster Autoscaler, run by you
Cluster Mesh with ProxmoxYes, on kubeadmNo
Already running oneBuild a new clusterImport the UKS cluster untouched
Know before you start

UpCloud specifics worth knowing

These come straight from the guide.

  • Node groups move to larger plans only. Each node is powered off, resized and powered on. For smaller nodes, create a new group and delete the old one.
  • Stopping a cluster releases the servers, the bastion and the NAT gateway. CSI storage volumes are kept, and UpCloud keeps billing them.
  • Block storage is zone local. On a multi-zone cluster, persistent volumes are created in the primary zone, so run stateful workloads there or use replicated storage.
  • Multi-zone placement needs kubeadm, at least three zones and three control planes, and it is decided at create time. A single-zone cluster that may grow is created with --network-mode wireguard_mesh.

Questions teams actually ask

Does UpCloud have managed Kubernetes?+

Yes. UpCloud Managed Kubernetes (UKS) runs the control plane for you. Ankra can create UKS clusters, manage their node pools and upgrades, and import UKS clusters you already run. Ankra can also build kubeadm or k3s clusters on plain UpCloud servers when you want control over the distribution and networking.

Which UpCloud zones does Ankra support?+

Ankra lists thirteen UpCloud zones in its reference, covering Helsinki (two zones), Stockholm, Frankfurt, Amsterdam, London, Warsaw, Madrid, Chicago, New York, San Jose, Singapore and Sydney. Available plans can vary by zone.

Can a Kubernetes cluster span several UpCloud zones?+

UpCloud private networks stay inside one zone, so a cluster is single-zone by default. Ankra can stretch a kubeadm cluster across three or more zones with one network per zone and a WireGuard mesh between the nodes. This is in closed beta, so contact support to have it switched on.

What does Ankra cost on top of UpCloud?+

Ankra bills on worker vCPUs only. Every plan includes 30 worker vCPUs free, controller nodes are never billed, and the free tier needs no credit card. UpCloud bills you directly for the servers, storage and network.

Is there an UpCloud trial?+

UpCloud has offered a 500 euro trial over 30 days through its signup page. Check the current terms on UpCloud's site before you rely on it.

Free tier available

Your first UpCloud cluster fits in the free allowance

30 worker vCPUs included, controller nodes never billed, and no credit card for the free tier. Bring your UpCloud account.

Ankra is an independent platform and is not affiliated with or endorsed by UpCloud Ltd. UpCloud prices and offers can change, so check upcloud.com for current terms. Product details on this page were checked against the Ankra documentation in October 2026.