Skip to content

Component Reference

The components a kMetal release installs on the under cluster, in install order.

Position in this list only says when a component can start; what it actually needs is its dependencies. The category says what breaks if it never becomes ready — which is what you read off a stalled install to decide whether the failure matters to you.

Versions are pinned by the operator release and are not configurable. Read the ones your platform is actually running off the object:

kubectl get km kmetal -o jsonpath='{range .status.components[*]}{.name}{"\t"}{.category}{"\t"}{.installedVersion}{"\t"}{.desiredVersion}{"\t"}{.phase}{"\n"}{end}'

Install order

# Component Category Depends on What it provides
0 flux — — Component zero. Applied by the operator directly, since every other component is a Flux object.
1 repositories Sources — The chart and artifact sources everything below is fetched through.
2 cert-manager PKI repositories Certificate issuance and renewal for the platform.
3 cert-manager-issuer PKI cert-manager The kmetal-ca ClusterIssuer.
4 kube-ovn Networking repositories The tenant-facing overlay: VPCs, subnets, EIPs, SNAT. Non-primary CNI.
5 multus Networking — Attaches tenant workloads to Kube-OVN alongside the primary CNI.
6 metallb Networking repositories LoadBalancer addresses on the under cluster.
7 metallb-pools Networking metallb The tenant-cp-pool and mgmt-pool address pools.
8 kamaji-crds MulticlusterManagement repositories Kamaji's types, split out so they exist before anything references them.
9 sveltos-crds AddonDelivery repositories Sveltos' types, for the same reason.
10 capsule MultiTenancy cert-manager Tenants, namespace ownership, quota enforcement.
11 kmetal-webhook MultiTenancy cert-manager Enforces the tenant storage class and quota on tenant workloads.
12 yaki-operator NodeLifecycle cert-manager Declarative Kubernetes upgrades for the under cluster's own nodes. Idle until a KubernetesNodeUpgrade is created.
13 kamaji MulticlusterManagement kamaji-crds, cert-manager Hosted control planes for tenant clusters.
14 kmetal-networking Networking kamaji, kube-ovn, cert-manager The claim controllers: VpcClaim, SubnetClaim, EipClaim.
15 provider-networks Networking kmetal-networking The ProviderNetwork objects from spec.networking.providerNetworks.
16 kmetal-kubevirt MulticlusterManagement cert-manager KubeVirt and CDI, bundled — tenant workers as VMs, and the volumes they boot from.
17 capi-operator MulticlusterManagement cert-manager Manages the Cluster API controllers.
18 capi-core-provider MulticlusterManagement capi-operator Cluster API core.
19 capi-providers MulticlusterManagement capi-core-provider Bootstrap (kubeadm), infrastructure (KubeVirt), control plane (Kamaji).
20 kairos-operator MulticlusterManagement — Immutable-OS support for tenant nodes.
21 kairos-capi MulticlusterManagement capi-core-provider The Kairos Cluster API provider.
22 clusterclass-kmetal MulticlusterManagement capi-providers The ClusterClass tenant clusters are created from.
23 image-builder MulticlusterManagement repositories Builds tenant OS artifacts declaratively, as Kubernetes objects.
24 kmetal-backup DataProtection capi-operator Backup and restore for tenant clusters.
25 headlamp Console metallb-pools, cert-manager The web console with the kMetal plugin. Last, and nothing depends on it.
26 kubevirt-csi-driver-operator TenantStorage cert-manager The CSI driver tenant clusters get their volumes through.
27 snapshot-controller TenantStorage cert-manager Volume snapshots, which tenant boot volumes are cloned from.
28 storage-profile TenantStorage kmetal-kubevirt Pins CDI's capabilities for the tenant StorageClass.
29 cdi-filesystem-overhead TenantStorage kmetal-kubevirt Pins CDI's filesystem overhead to zero on the tenant class.
30 sveltos AddonDelivery sveltos-crds Delivers add-ons into tenant clusters.

Categories

These are the values the operator reports in status.components[].category, and they group components by what an install failure blocks. They are finer-grained than the seven capabilities in Platform Components, which is the view to read if you want to know what kMetal does rather than what a stalled component costs you.

Category Loses you
Sources Everything: no component below can be fetched.
PKI Most of the platform — webhooks and controllers wait on certificates.
Networking Tenant VPCs, subnets, egress, and every LoadBalancer address.
MultiTenancy Isolation and quota enforcement between tenants.
MulticlusterManagement The ability to create tenant clusters at all.
AddonDelivery The add-ons that land inside tenant clusters.
TenantStorage Persistent volumes inside tenant clusters.
DataProtection Backup and restore.
NodeLifecycle Declarative upgrades of the under cluster's own nodes. No tenant is affected.
Console The web console only.

Phases

Each component reports one of five phases:

Phase Meaning
Pending Not emitted yet, because something it depends on is not ready.
Installing Being installed for the first time; its objects are reconciling.
Upgrading Installed at a version other than the one this release wants, and being moved across.
Ready Reconciled, running the version this release pins.
Failed Reconciled with an error. Components ordered after it stay Pending.

Upgrading is distinct from Installing on purpose: a failure there leaves a working older version behind, whereas a failed install leaves nothing.

Two conditions worth scripting against

Condition Meaning
FluxReady Component zero. Nothing else can progress while this is false — read it first when an install stalls at the start.
Ready Every component reconciled at the version this release pins. status.version advances at the same moment, so a partially applied upgrade never reports as the new release.

Prerequisites kMetal does not install

Prerequisite Why it is yours
The primary CNI Kube-OVN runs non-primary and never takes over pod eth0. Pod networking must work before the operator starts.
StorageClasses kMetal installs no CSI driver or provisioner. You name existing classes in spec.storage.
Registry credentials Referenced as Secrets, never carried in a cluster-scoped spec.
Node labels Kube-OVN's per-node DaemonSets run only where the overlay label is present.

See Also: Platform Components for what the set is for · Platform Configuration Reference for the fields · Component Configuration for what can be changed