> For the complete documentation index, see [llms.txt](https://docs.ionos.com/cloud/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ionos.com/cloud/containers/managed-kubernetes/how-tos/cluster_management.md).

# Set Up a Kubernetes Cluster

Set up a Managed Kubernetes cluster on IONOS CLOUD: configure cluster properties, node pool access, location, and additional settings using the DCD.

{% hint style="info" %}
**Prerequisite:** Only contract administrators, owners, and users with **Create Kubernetes Clusters** permission can create a cluster for Public and Private Node Pools. Other user types have **read-only** access.
{% endhint %}

{% hint style="info" %}
**Note:** Ensure to use the following naming convention for the Kubernetes cluster:

* Can be a maximum of 63 characters in length.
* Begins and ends with an alphanumeric character: `a-z0-9A-Z`.
* Must not contain spaces or any other white-space characters.
* Can contain dashes (-), underscores (\_), and dots (.) in between.
  {% endhint %}

## Cluster configuration

To create a cluster using the DCD, follow these steps:

{% stepper %}
{% step %}

### Navigate to Managed Kubernetes

1. In the **DCD**, go to **Menu** > **Containers** > **Managed Kubernetes**.
2. Select **Create cluster**.
   {% endstep %}

{% step %}

### Define Properties

1. Enter a **Name** for the cluster.
2. Select the **Kubernetes version** you want to run in the cluster from the drop-down list. It is best practice to run the latest stable Kubernetes version to maximize the time before your cluster reaches its End of Life (EOL). For more information, see [<mark style="color:blue;">Release Schedule</mark>](/cloud/containers/managed-kubernetes/overview/managed-k8s-schedule.md).

![Define Properties](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-91ebd411d49f126ef2faf45f929cc410bd00aef3%2Fmanaged-kubernetes-create-cluster-name.png?alt=media)
{% endstep %}

{% step %}

### Configure Location and network access

{% hint style="info" %}
**Note:** You cannot change these settings later.
{% endhint %}

{% tabs %}
{% tab title="Public Node Pools" %}
You can create a cluster using the [<mark style="color:blue;">DCD</mark>](https://docs.ionos.com/cloud/support/general-information/glossary-of-terms#data-center-designer-dcd) for Public Node Pools.

1. Select **Public** from the **Node pool access** options.

{% hint style="info" %}
**Note:** It is impossible to switch the **Node pool access** from **public to private** and vice versa. Public node pools assign external IP addresses to your nodes, allowing them to communicate directly with the Internet. Private node pools isolate nodes using only internal IP addresses, restricting them to your internal network. For more information, see [<mark style="color:blue;">Public Node Pools</mark>](/cloud/containers/managed-kubernetes/overview/public_node_pools.md) and [<mark style="color:blue;">Private Node Pools</mark>](/cloud/containers/managed-kubernetes/overview/private_node_pools.md).
{% endhint %}

2. Select a **Location** from the drop-down list. You can only create clusters in the following locations:
   * **Germany:** **Frankfurt am Main (de/fra)**
   * **United States:** **Newark (us/ewr)**, **Las Vegas (us/las)**, and **Lenexa (us/mci)**.

![Define Location and network](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-6828aee10026b647138c5db6ad34b8a0501b68b4%2Fmanaged-kubernetes-location-node-pool.png?alt=media)
{% endtab %}

{% tab title="Private Node Pools" %}
You can create a cluster using the [<mark style="color:blue;">DCD</mark>](https://docs.ionos.com/cloud/support/general-information/glossary-of-terms#data-center-designer-dcd) for Private Node Pools. For this cluster, you must provide a NAT gateway IP address. It is the IP address assigned to the deployed Network Address Translation (NAT) Gateway. To reserve an IPv4 address, in the **DCD** go to **Menu** > **Network Services** > **IP Management**.

1. Select **Private** from the **Node pool access** options.

{% hint style="info" %}
**Note:**

* When defining a private node pool, you must provide a data center in the **same location** as the cluster for which you create the node pool.
* It is impossible to switch the **Node pool access** from **private to public** and vice versa. Public node pools assign external IP addresses to your nodes, allowing them to communicate directly with the Internet. Private node pools isolate nodes using only internal IP addresses, restricting them to your internal network. For more information, see [<mark style="color:blue;">Public Node Pools</mark>](/cloud/containers/managed-kubernetes/overview/public_node_pools.md) and [<mark style="color:blue;">Private Node Pools</mark>](/cloud/containers/managed-kubernetes/overview/private_node_pools.md).
  {% endhint %}

2. Select a **Location** from the drop-down list. You can only create clusters in the following locations:
   * **Germany:** **Frankfurt am Main (de/fra)**
   * **United States:** **Newark (us/ewr)**, **Las Vegas (us/las)**, and **Lenexa (us/mci)**.

{% hint style="info" %}
**Note:** You can only create the cluster for Private Node Pools in the [<mark style="color:blue;">Virtual Data Centers (VDCs)</mark>](https://docs.ionos.com/cloud/support/general-information/glossary-of-terms#virtual-data-center-vdc) in the same region as the cluster.
{% endhint %}

3. Select an unused, reserved IP address from the drop-down list in **NAT gateway IP address**. To do this, you must reserve an IPv4 address assigned by <code class="expression">space.vars.ionos\_cloud</code> that is not already in use by another resource. For more information, see [<mark style="color:blue;">Reserve an IPv4 Address</mark>](/cloud/network-services/vdc-networking/ip-address/ipv4/how-tos/reserve-ipv4.md).
4. (*Optional*) Define a **Node subnet** for the private LAN. This must be an address of a **prefix length /16** in the Classless Inter-Domain Routing (CIDR) block. If you do not specify a subnet, a default network range is automatically assigned.

{% hint style="info" %}
**Note:**

* The subnet value cannot intersect with the cluster's networks for pods and services. For clusters created with:
  * Kubernetes version 1.30 and above, the networks are `100.96.0.0/12` and `100.64.0.0/18`.
  * Older Kubernetes versions, the networks are `10.208.0.0/12` and `10.233.0.0/18`.
* Once provisioned, the **Region**, **NAT gateway IP address**, and **Node subnet** values cannot be changed.
  {% endhint %}

![Define Location and network](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-b697ce97dd1b54000cc2c1b8d3e3b8b4f0003148%2Fset-up-kubernetes-cluster-private.png?alt=media)
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}

### Configure Additional settings

1. Toggle **Audit logging** to activate or deactivate audit logging for the cluster. When activated, a **Target Object Storage bucket** field appears; enter the name of an existing Object Storage bucket where audit logs will be stored.
2. (*Optional*) Enter an IP address range in **Allowed IPs** to restrict API access to the cluster. Leave empty to allow access from anywhere.
3. (*Optional*) Configure the **Maintenance window**:
   * **Day**: Select the day of the week for scheduled maintenance from the drop-down list.
   * **Start time (UTC)**: Enter the start time for the maintenance window in UTC.

![Configure Audit logging and maintenance window](https://1737632334-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MifAzdGvKLDTtvJP8sm%2Fuploads%2Fgit-blob-a1ae7812c2f43d095183585ab9fc0d74e457dce2%2Fmanaged-kubernetes-create-cluster.png?alt=media)

{% hint style="info" %}
**Note:**

* To access the Kubernetes API provided by the cluster, download the `kubeconfig` file and use it with tools such as `kubectl`. For more information, see [<mark style="color:blue;">Download Kubeconfig</mark>](/cloud/containers/managed-kubernetes/how-tos/download-kubeconfig-file.md).
* The maintenance window starts at the time of your choosing and remains open for another four hours. All planned maintenance work will be performed within this window, however, not necessarily at the beginning.
  {% endhint %}
  {% endstep %}

{% step %}

### Create cluster

To finalize your setup, click **Create cluster**.
{% endstep %}
{% endstepper %}

{% hint style="success" %}
**Result:** A cluster is successfully created and listed in the clusters list. The status remains in **Deploying** until it is created successfully. The cluster can be modified and populated with node pools once its status is **Active**.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.ionos.com/cloud/containers/managed-kubernetes/how-tos/cluster_management.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
