Skip to main content
Version: 0.5.6

k3s HA Cluster on Aruba Cloud

Deploy a 3-node k3s HA control-plane cluster on Aruba Cloud using Terraform and cloud-init. Uses an external MySQL 8.0 database as the HA datastore via the embedded kine shim.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

k3s is a lightweight, CNCF-certified Kubernetes distribution optimized for edge and resource-constrained environments. This example deploys a 3-node HA control-plane — all three nodes can serve the Kubernetes API and schedule workloads. It:

  • Creates three identical control-plane nodes (each with its own Elastic IP)
  • Uses an external MySQL 8.0 datastore for cluster state (Aruba Cloud DBaaS or bring your own)
  • Opens SSH (22), Kubernetes API (6443), HTTP (80), and HTTPS (443)
  • Disables the built-in ServiceLB (Klipper) — use an external LB or MetalLB instead

External DB required: You must provision a MySQL 8.0 database separately before running terraform apply. Create a k3s database and a dedicated user with full privileges on it.


Architecture Overview​


Infrastructure Created​

ResourceCountName patternDescription
arubacloud_project1k3sha-prodProject container
arubacloud_vpc1k3sha-prod-vpcVirtual Private Cloud
arubacloud_subnet1k3sha-prod-subnetBasic subnet
arubacloud_securitygroup1k3sha-prod-sgShared security group
arubacloud_securityrule5k3sha-prod-{ssh,api,http,https,egress}Ingress/egress rules
arubacloud_elasticip3k3sha-prod-node-{1,2,3}-eipOne public IP per node
arubacloud_blockstorage3k3sha-prod-node-{1,2,3}-boot40 GB boot disk per node
arubacloud_keypair1k3sha-prod-keypairShared SSH public key
arubacloud_cloudserver3k3sha-prod-node-{1,2,3}Control-plane VMs

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
3× CloudServer VMCSO4A8 — 4 vCPU / 8 GB~€120
3× Boot disk40 GB Performance~€18
3× Elastic IP—~€9
External MySQLAruba Cloud DBaaS (varies)~€15
Total~€162/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair
  • An external MySQL 8.0 database reachable from the VMs

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
k3s_tokenShared cluster token (generate with openssl rand -hex 32, min 16 chars)
db_hostMySQL 8.0 hostname or IP
db_passwordMySQL password

Optional​

VariableDefaultDescription
k3s_version"latest"k3s version (e.g. "v1.32.0+k3s1")
db_port3306MySQL port
db_name"k3s"MySQL database name
db_user"k3s"MySQL username
ssh_cidr"0.0.0.0/0"CIDR for SSH access
api_cidr"0.0.0.0/0"CIDR for k3s API server (port 6443) — restrict in production
app_name"k3sha"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO4A8"CloudServer flavor per node
vm_disk_size_gb40Boot disk size per node (min 20 GB)

Outputs​

OutputDescription
node_public_ipsMap of node name → public IP
ssh_commandsMap of node name → SSH command
api_endpointsMap of node name → https://<IP>:6443

Deployment Instructions​

1. Provision the external MySQL database​

Create a MySQL 8.0 database before deploying:

CREATE DATABASE k3s;
CREATE USER 'k3s'@'%' IDENTIFIED BY 'your-password';
GRANT ALL PRIVILEGES ON k3s.* TO 'k3s'@'%';
FLUSH PRIVILEGES;

2. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/k3s-ha

3. Configure variables​

cp terraform.tfvars.example terraform.tfvars

4. Deploy​

terraform init
terraform plan
terraform apply

The three nodes are created simultaneously. Each bootstraps in 2–5 minutes.

5. Retrieve the kubeconfig​

# SSH into node-1
ssh ubuntu@<node-1-ip>
sudo cat /etc/rancher/k3s/k3s.yaml

Copy the kubeconfig to your local machine and replace 127.0.0.1 with the node's public IP:

export KUBECONFIG=~/.kube/k3s-ha.yaml
kubectl get nodes

References​