Component Reference¶
The components a kMetal release installs on the under cluster, in install order.
Position in this list only says when a component can start; what it actually needs is its dependencies. The category says what breaks if it never becomes ready — which is what you read off a stalled install to decide whether the failure matters to you.
Versions are pinned by the operator release and are not configurable. Read the ones your platform is actually running off the object:
kubectl get km kmetal -o jsonpath='{range .status.components[*]}{.name}{"\t"}{.category}{"\t"}{.installedVersion}{"\t"}{.desiredVersion}{"\t"}{.phase}{"\n"}{end}'
Install order¶
| # | Component | Category | Depends on | What it provides |
|---|---|---|---|---|
| 0 | flux | — | — | Component zero. Applied by the operator directly, since every other component is a Flux object. |
| 1 | repositories | Sources | — | The chart and artifact sources everything below is fetched through. |
| 2 | cert-manager | PKI | repositories | Certificate issuance and renewal for the platform. |
| 3 | cert-manager-issuer | PKI | cert-manager | The kmetal-ca ClusterIssuer. |
| 4 | kube-ovn | Networking | repositories | The tenant-facing overlay: VPCs, subnets, EIPs, SNAT. Non-primary CNI. |
| 5 | multus | Networking | — | Attaches tenant workloads to Kube-OVN alongside the primary CNI. |
| 6 | metallb | Networking | repositories | LoadBalancer addresses on the under cluster. |
| 7 | metallb-pools | Networking | metallb | The tenant-cp-pool and mgmt-pool address pools. |
| 8 | kamaji-crds | MulticlusterManagement | repositories | Kamaji's types, split out so they exist before anything references them. |
| 9 | sveltos-crds | AddonDelivery | repositories | Sveltos' types, for the same reason. |
| 10 | capsule | MultiTenancy | cert-manager | Tenants, namespace ownership, quota enforcement. |
| 11 | kmetal-webhook | MultiTenancy | cert-manager | Enforces the tenant storage class and quota on tenant workloads. |
| 12 | yaki-operator | NodeLifecycle | cert-manager | Declarative Kubernetes upgrades for the under cluster's own nodes. Idle until a KubernetesNodeUpgrade is created. |
| 13 | kamaji | MulticlusterManagement | kamaji-crds, cert-manager | Hosted control planes for tenant clusters. |
| 14 | kmetal-networking | Networking | kamaji, kube-ovn, cert-manager | The claim controllers: VpcClaim, SubnetClaim, EipClaim. |
| 15 | provider-networks | Networking | kmetal-networking | The ProviderNetwork objects from spec.networking.providerNetworks. |
| 16 | kmetal-kubevirt | MulticlusterManagement | cert-manager | KubeVirt and CDI, bundled — tenant workers as VMs, and the volumes they boot from. |
| 17 | capi-operator | MulticlusterManagement | cert-manager | Manages the Cluster API controllers. |
| 18 | capi-core-provider | MulticlusterManagement | capi-operator | Cluster API core. |
| 19 | capi-providers | MulticlusterManagement | capi-core-provider | Bootstrap (kubeadm), infrastructure (KubeVirt), control plane (Kamaji). |
| 20 | kairos-operator | MulticlusterManagement | — | Immutable-OS support for tenant nodes. |
| 21 | kairos-capi | MulticlusterManagement | capi-core-provider | The Kairos Cluster API provider. |
| 22 | clusterclass-kmetal | MulticlusterManagement | capi-providers | The ClusterClass tenant clusters are created from. |
| 23 | image-builder | MulticlusterManagement | repositories | Builds tenant OS artifacts declaratively, as Kubernetes objects. |
| 24 | kmetal-backup | DataProtection | capi-operator | Backup and restore for tenant clusters. |
| 25 | headlamp | Console | metallb-pools, cert-manager | The web console with the kMetal plugin. Last, and nothing depends on it. |
| 26 | kubevirt-csi-driver-operator | TenantStorage | cert-manager | The CSI driver tenant clusters get their volumes through. |
| 27 | snapshot-controller | TenantStorage | cert-manager | Volume snapshots, which tenant boot volumes are cloned from. |
| 28 | storage-profile | TenantStorage | kmetal-kubevirt | Pins CDI's capabilities for the tenant StorageClass. |
| 29 | cdi-filesystem-overhead | TenantStorage | kmetal-kubevirt | Pins CDI's filesystem overhead to zero on the tenant class. |
| 30 | sveltos | AddonDelivery | sveltos-crds | Delivers add-ons into tenant clusters. |
Categories¶
These are the values the operator reports in status.components[].category, and they group components by what an install failure blocks.
They are finer-grained than the seven capabilities in Platform Components, which is the view to read if you want to know what kMetal does rather than what a stalled component costs you.
| Category | Loses you |
|---|---|
| Sources | Everything: no component below can be fetched. |
| PKI | Most of the platform — webhooks and controllers wait on certificates. |
| Networking | Tenant VPCs, subnets, egress, and every LoadBalancer address. |
| MultiTenancy | Isolation and quota enforcement between tenants. |
| MulticlusterManagement | The ability to create tenant clusters at all. |
| AddonDelivery | The add-ons that land inside tenant clusters. |
| TenantStorage | Persistent volumes inside tenant clusters. |
| DataProtection | Backup and restore. |
| NodeLifecycle | Declarative upgrades of the under cluster's own nodes. No tenant is affected. |
| Console | The web console only. |
Phases¶
Each component reports one of five phases:
| Phase | Meaning |
|---|---|
Pending |
Not emitted yet, because something it depends on is not ready. |
Installing |
Being installed for the first time; its objects are reconciling. |
Upgrading |
Installed at a version other than the one this release wants, and being moved across. |
Ready |
Reconciled, running the version this release pins. |
Failed |
Reconciled with an error. Components ordered after it stay Pending. |
Upgrading is distinct from Installing on purpose: a failure there leaves a working older version behind, whereas a failed install leaves nothing.
Two conditions worth scripting against¶
| Condition | Meaning |
|---|---|
FluxReady |
Component zero. Nothing else can progress while this is false — read it first when an install stalls at the start. |
Ready |
Every component reconciled at the version this release pins. status.version advances at the same moment, so a partially applied upgrade never reports as the new release. |
Prerequisites kMetal does not install¶
| Prerequisite | Why it is yours |
|---|---|
| The primary CNI | Kube-OVN runs non-primary and never takes over pod eth0. Pod networking must work before the operator starts. |
| StorageClasses | kMetal installs no CSI driver or provisioner. You name existing classes in spec.storage. |
| Registry credentials | Referenced as Secrets, never carried in a cluster-scoped spec. |
| Node labels | Kube-OVN's per-node DaemonSets run only where the overlay label is present. |
See Also: Platform Components for what the set is for · Platform Configuration Reference for the fields · Component Configuration for what can be changed