Skip to content

Kubernetes cluster

The cluster, command-line tools, and cluster add-ons to have ready before you create a runtime plane. The portal wizard (Settings → Runtime Plane) asks you to confirm each item before it lets you continue, and offers a Download Script that auto-verifies the CLI tools, Kubernetes version, and Metrics Server on your cluster.

Not needed on Trust3 AI Cloud

A Trust3 AI Cloud plane runs in Trust3AICloud, so there is no cluster for you to provide. See Deployment Options.


Cluster requirements

You provide a Kubernetes cluster on AWS (EKS), Azure (AKS), or Google Cloud (GKE).

Requirement Details
EKS cluster Kubernetes v1.34 or later. Nodes must be r5.2xlarge or a similar instance type with equivalent compute and memory. Node group configured with a minimum of 1 and a maximum of 10 nodes.
Terminal access A terminal with network connectivity to the EKS cluster API server and cluster-admin permissions, to create global resources such as namespaces and storage classes.
Command-line tools AWS CLI v2.12.0+, kubectl v1.34+, Helm v3.9.0+, and curl or wget. Optional: k9s for interactive cluster monitoring.
Metrics Server Must be installed and running — see Install the Metrics Server.
Outbound access The cluster must allow outbound (egress) HTTPS traffic to https://api.privaceracloud.com so the Runtime Agent can reach the control plane.
Requirement Details
AKS cluster Kubernetes v1.34 or later. Nodes must be Standard_E8s_v3 or a similar VM size with equivalent compute and memory. Node pool configured with a minimum of 1 and a maximum of 10 nodes.
Terminal access A terminal with network connectivity to the AKS cluster API server and cluster-admin permissions.
Command-line tools Azure CLI v2.50.0+, kubectl v1.34+, Helm v3.9.0+, and curl or wget. Optional: k9s for interactive cluster monitoring.
Metrics Server Must be installed and running — see Install the Metrics Server.
Outbound access The cluster must allow outbound (egress) HTTPS traffic to https://api.privaceracloud.com so the Runtime Agent can reach the control plane.
Requirement Details
GKE cluster Kubernetes v1.34 or later. Both Standard and Autopilot clusters are supported. Nodes must be n2-standard-8 or a similar machine type with equivalent compute and memory. Node pool autoscaling from 1 to 10 nodes.
Terminal access A terminal with Kubernetes Engine Cluster Admin or equivalent permissions, to create global resources such as namespaces and storage classes.
Command-line tools Google Cloud SDK 450.0.0+, kubectl v1.34+, Helm v3.9.0+, and curl or wget. Optional: k9s for interactive cluster monitoring.
Metrics Server Must be installed and running — see Install the Metrics Server.
Outbound access The cluster must allow outbound (egress) HTTPS traffic to https://api.privaceracloud.com so the Runtime Agent can reach the control plane.

You provide a Kubernetes cluster on AWS (Amazon EKS).

Requirement Details
EKS cluster Kubernetes v1.34 or later. Nodes must be r5.2xlarge or a similar instance type with equivalent compute and memory. Node group configured with a minimum of 1 and a maximum of 10 nodes.
Terminal access A terminal with network connectivity to the EKS cluster API server and cluster-admin permissions, to create global resources such as namespaces and storage classes.
Command-line tools AWS CLI v2.12.0+, kubectl v1.34+, Helm v3.9.0+, and curl or wget. Optional: k9s for interactive cluster monitoring.
Metrics Server Must be installed and running — see Install the Metrics Server.
Outbound access Required only when AI Features is enabled. The cluster must allow outbound (egress) HTTPS traffic to the Anthropic API (or to your LLM endpoint, if you set one) and to the Trust3 product documentation site, which the assistant uses to answer documentation questions.
AWS Load Balancer Controller Installed on the cluster — see DNS and ingress.
OIDC provider (IRSA) The cluster's OpenID Connect provider must be associated with IAM — see Cloud permissions.
AI Features (optional) An AI assistant served from the runtime plane. Needs an Anthropic API key secret — see Storage, database, and secrets.

Verify terminal access

On Azure and Google Cloud, point kubectl at your cluster first. On AWS, use your existing context.

Bash
az aks get-credentials --resource-group <resource-group> --name <cluster-name>
Bash
gcloud container clusters get-credentials <cluster-name> --zone <zone> --project <project-id>

Then confirm you are pointed at the right cluster:

Bash
kubectl config get-contexts

Ensure the asterisk (*) is next to the correct cluster name.

Bash
kubectl auth can-i '*' '*' --all-namespaces

This must return yes. If it returns no, you do not have sufficient permissions to proceed.


Install the Metrics Server

The Kubernetes Metrics Server provides resource metrics for pods and nodes, which are essential for monitoring and autoscaling.

Check whether it is already installed:

Bash
kubectl get deployment metrics-server -n kube-system

If it is not, install it:

Bash
kubectl apply -f https://github.com/kubernetes-sigs/metrics-server/releases/latest/download/components.yaml

Amazon EKS needs an extra patch

On EKS — both Partially Managed (D2P) on AWS and Self-Managed — specific flags are needed to handle TLS certificates:

Bash
kubectl patch deployment metrics-server -n kube-system --type='json' \
  -p='[{"op": "add", "path": "/spec/template/spec/hostNetwork", "value": true}, {"op": "add", "path": "/spec/template/spec/containers/0/args/-", "value": "--kubelet-insecure-tls"}, {"op": "add", "path": "/spec/template/spec/containers/0/args/-", "value": "--kubelet-preferred-address-types=InternalIP,Hostname,ExternalIP"}]'

Verify (metrics may take 1–2 minutes to appear):

Bash
kubectl top nodes