VOOZH about

URL: https://thenewstack.io/how-to-cut-through-a-thicket-of-kubernetes-clusters/

⇱ How to Cut Through a Thicket of Kubernetes Clusters - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2023-05-01 07:17:07
How to Cut Through a Thicket of Kubernetes Clusters
sponsor-vmware,sponsored-post-contributed,
Kubernetes / Operations / Software Development

How to Cut Through a Thicket of Kubernetes Clusters

DIY Kubernetes is hard. If you’re looking for a solution to help you scale your modern application platform, be sure to look for these features.
May 1st, 2023 7:17am by Pawel Piotrowski
👁 Featued image for: How to Cut Through a Thicket of Kubernetes Clusters
VMware Tanzu sponsored this post.

Kubernetes clusters and microservices have opened up a plethora of new possibilities for developing and running modern applications, and they bring many advantages including distributed architecture, increased redundancy, high availability and nondisruptive upgrades. But as with most things, those benefits come with challenges.

Due to the nature of Kubernetes and increasing interest in the technology in general, there are more and more options for running it. Today, we can get Kubernetes in a public cloud or on premises. If we go to the public cloud, we can choose from one of the many hyperscalers, or even more than one, that have their own offering to provide us with Kubernetes clusters. We also have a variety of choices to get it on premises, such as VMware Tanzu, Openshift, Rancher and many more solutions.

But why not install Kubernetes clusters on our own from scratch so that we have everything under our own control? The reason is pretty simple: It’s time consuming and not an easy task. If you’ve never tried, I’d recommend checking out Kelsey Hightower’s “Kubernetes the Hard Way.”

This was further confirmed by the latest State of Kubernetes report, which found that many companies are moving away from DIY Kubernetes.

Trusted by enterprises and loved by developers, VMware Tanzu is built for platform and data teams who want to accelerate agentic software delivery and AI-ready data. Tanzu provides a pre-engineered, agentic app platform and an AI-ready data intelligence platform that helps enterprises build, run, manage and safeguard agents, their integrations and data so you can capitalize on AI at scale. 
Learn More
The latest from VMware Tanzu
Hear more from our sponsor

Because of this, many organizations use either an offering from a hyperscaler or one of the on-premises options. For a mid- to enterprise-size environment, it’s common to go with a combination of the two. This multicloud approach helps avoid being locked in with a particular solution or vendor, and it’s also a way to build redundancy and resilience into an infrastructure.

As platform engineers, we need to manage and maintain dozens, hundreds or even thousands of Kubernetes clusters using different platforms and solutions — what is often described as Kubernetes cluster sprawl.

That might not sound too scary, until you start thinking about that management. How can you ensure that these clusters are conformant and follow security standards, especially if your organization is bound with some security regulations?

Think about access, resource, security and network policy management, image restrictions enforcement, as well as package and Kubernetes life-cycle management.

Defining a YAML with some policies and applying them to a single cluster might not sound like a huge challenge, but doing it at scale — tens or hundreds of times, where different clusters should be configured with slightly different policies — quickly gets more complicated.

This degree of management requires a mindset change, especially if you’ve got roots in more traditional infrastructure management and perhaps have only a couple of big hypervisor clusters hosting your virtual machines.

Current Challenge: Manage Diverse Kubernetes Clusters 

So how should one go about managing all these clusters on different platforms? That’s a question I hear frequently from colleagues who are platform engineers, and it’s also a challenge I’ve been dealing with in my own organization.

Every Kubernetes cluster provides basic resources that could be used to define, for example, policies. Let’s consider network policies for a moment. I can create a YAML and apply it to any cluster with a simple automation. Pretty easy, right? However, it is easier said than done.

First, I need a YAML that will define the config. Not a big deal. Even if I’m not too confident with a YAML manifest, I can still use some tools like the network policy editor provided for free as part of the Cilium project. But how do I group my clusters, ensuring the proper YAML was applied on the correct cluster? And most importantly, how do I ensure that my clusters are still compliant with the configuration we’ve previously defined?

With network policies, we have an editor that could be used. What about other configurations, such as role-based access control (RBAC), security, etc.? There are some dedicated tools and editors we can use, but this isn’t a perfect solution if we cannot assign a huge team of people to take care of it.

Fortunately, key players in the Kubernetes landscape noticed our challenges and provided more comprehensive solutions to help relieve the pain and save time, increase productivity and standardization, and decreasing time to market. Some of the available options we can choose from today include:

  • VMware Tanzu Mission Control
  • Google Anthos Config Management
  • Azure Arc for Kubernetes
  • Rancher Server
  • Advanced Cluster Management for Kubernetes (provided by Red Hat OpenShift)

That’s not a complete list, which doesn’t make the choice easier. How should leaders choose the best one for their organization? It might be partially based on some personal and corporate preferences or the fact that they are already using a specific vendor’s platform.

It should go without saying, but such a decision should always be made based on an organization’s specific set of requirements. We don’t buy a product just for the sake of buying a product or because it’s “nice and shiny.” 😊

However, when trying to identify the best solution for your environment, there are a few features that can be lifesavers, or at least time savers that eventually affect the bottom line:

  • Diverse Kubernetes cluster management: Try to avoid solutions that are limited to a single platform. Just because you use a single platform today doesn’t mean you won’t be using others next year.
  • Policy-driven management: A product should provide a relatively straightforward option to define policies, preferably without deep experience with YAML manifests. Some of the most useful configurations that can be managed via policies could be related to, but not limited to, network (firewall rules), security, image management, RBAC, resource quotas, etc.
  • Life-cycle management: Being able to easily upgrade your clusters with newer versions of Kubernetes at scale is important if you consider how frequently new releases are becoming available.
  • Package management: There are plenty of additional components you might need to get installed on your Kubernetes clusters. A feature that lets you install them remotely in a centralized way is a must-have.
  • Cluster group management: Look for the ability to define various structures to group clusters and namespaces based on the environment type, its criticality, service-level agreement or any other factors applicable to your organization. This might be related to the concept of multitenancy, but it doesn’t have to be.

Additional capabilities and features could be considered a plus, but in my opinion, these are the most important ones to look for to help streamline Kubernetes cluster management in multicloud environments, even with a really huge scale.

Trusted by enterprises and loved by developers, VMware Tanzu is built for platform and data teams who want to accelerate agentic software delivery and AI-ready data. Tanzu provides a pre-engineered, agentic app platform and an AI-ready data intelligence platform that helps enterprises build, run, manage and safeguard agents, their integrations and data so you can capitalize on AI at scale. 
Learn More
The latest from VMware Tanzu
Hear more from our sponsor
TRENDING STORIES
Pawel Piotrowski is a solutions architect with extensive experience focused on the entire software-defined data center stack, building platforms for modern applications. He has more than 12 years’ experience in IT, mostly working with enterprise products and solutions on various...
Read more from Pawel Piotrowski
VMware Tanzu sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.