Reference
Every package, account setting, file, firewall rule and system setting the installer puts on the machine you install from, the control plane, the workers and the GPU nodes.
Ask your agent: "what did the install change on tkamd2?". The agent reads the machine over SSH and answers with what this page lists: containerd.io, kubeadm, kubelet and kubectl installed and held at their versions, two services running every minute (one gives Kubernetes the machine’s current network address, one restarts a worker’s network when the router stops answering), the firewall enabled, and name resolution for your domain pointed at the cluster. Read this page before you install on a machine that already does other work.
The installer runs on one machine and changes the other machines over SSH. It leaves users, groups, the hostname, /etc/hosts and GRUB as they are, and it installs no snaps.
The machines
| Machine | What it is |
|---|---|
Install machine |
The machine the installer runs on. It can be one of the servers or a separate machine. It joins your tailnet and gets a few tools. When it is one of the servers, that server gets both sets of changes. |
Control plane |
The one server that runs the Kubernetes control plane. It carries most of the platform’s host-side tools. |
Worker |
Every other server. It runs your workloads and joins the control plane. |
GPU node |
A control plane or worker with an NVIDIA GPU. |
What it checks, and what it refuses
| Where | Check |
|---|---|
Install machine |
Ubuntu 24.04, not running as root, OpenSSH server installed and running, a connection to |
Every server |
The network scan finds a server when its SSH banner is Ubuntu’s. Hardware detection must report CPUs, memory and disk. |
Control plane |
Exactly one. At least 16 CPU cores and 64 GB of memory. The installer offers only machines this size for the role. The Kubernetes install stops on a smaller machine, and on a system other than Ubuntu 24.04. With a DGX Spark and other machines, choose another machine, so the Spark’s shared memory stays for AI work. A worker of any size joins the cluster. |
GPU node |
NVIDIA driver 580 or newer. A GPU older than Volta is reported as unsupported. |
Nothing checks for a clean machine. An existing Docker Engine, containerd or Python environment is not detected; the sections below say what happens to each.
Packages
| Machine | Installed |
|---|---|
Install machine |
From apt: |
Every server |
From apt: |
Control plane and workers |
From apt: |
Control plane |
From apt: |
GPU node without a working driver |
|
The GitHub CLI (gh) and the Argo CLI (argo) are installed for amd64 only.
Two apt repositories are added on the control plane and the workers, Docker’s and Kubernetes', with their keys.
Your account and SSH
| Machine | Change |
|---|---|
Every server |
Your user is added to |
Control plane |
Your user joins |
Install machine |
|
Files and directories
| Machine | Created or changed |
|---|---|
Install machine |
|
Control plane |
|
Control plane and workers |
|
GPU node |
|
Nothing is created under /opt. The shared filesystem is mounted inside the cluster, not on the hosts.
System settings
| Setting | Change |
|---|---|
Swap |
Turned off on the control plane and the workers, and its |
Kernel modules |
|
sysctl |
Bridged traffic through iptables, IP forwarding, and higher inotify limits, in |
DGX Spark |
|
Root volume |
On a server whose root is an LVM volume with more than 10 GB unallocated, the volume is grown to fill the group. This cannot be undone. |
Name resolution |
|
containerd |
|
GPU node without a driver |
nouveau blacklisted, the initramfs rebuilt. On every GPU node, a unit that marks the host driver ready at boot. |
DGX Spark |
|
Firewall
The firewall is turned on on the control plane and the workers, and the forward policy is set to accept. The default incoming policy is left as Ubuntu ships it.
| Machine | Allowed in |
|---|---|
Control plane |
SSH 22, the API server 6443, etcd 2379–2380, the scheduler 10259, the controller manager 10257, kubelet 10250, Cilium health 4240, VXLAN 8472/udp, Cilium metrics 9962, LLMNR 5355/udp. All traffic on the |
Worker |
SSH 22, kubelet 10250, 6443 for the local API proxy, Cilium health 4240, VXLAN 8472/udp, Cilium metrics 9962, LLMNR 5355/udp. All traffic on |
Every machine on the tailnet, the install machine included |
Tailscale 41641/udp and all traffic on the Tailscale interface. On a separate install machine these rules are added but the firewall is not turned on. |
The optional Prometheus component adds 9100 for node metrics on every node.
Network
| Change | What it is for |
|---|---|
Tailscale on every machine |
Each machine joins your tailnet under its hostname; Thinkube Kubernetes says what travels over it. |
|
The address every node uses for the Kubernetes API, so the cluster keeps working when the LAN address changes. |
The API proxy on workers |
Forwards |
|
Puts the machine’s current LAN address into kubelet’s settings. |
|
When the local router stops answering, restarts the network interface, then resets the device, then reboots. |
What happens to what was already there
| Already on the machine | What happens |
|---|---|
Docker Engine |
Not detected. |
containerd |
Installed at the held version, configuration replaced. |
A cluster from kubeadm |
On the control plane, |
k3s, k8s-snap, MicroK8s |
Not detected and not removed. Remove them before you install. |
|
Kept, but Ansible and the Kubernetes Python client are installed into it at the versions the platform needs, which can change what was there. |
|
Kept, and Ansible is installed into it; your shells are set to activate it. |
pip configuration on the control plane |
|
Ollama and its models |
Not touched. |