Skip to content

Tenant Guide

For the people who use kMetal: running clusters in an Environment, and running workloads on them.

Everything here happens inside an Environment your platform team has already given you. If you do not have one, that is their job — see Platform Administration.

You work in two places

This is the single most useful thing to understand before anything else, and it explains most of the confusion new tenants hit.

What lives there Credential
Your Environment — a namespace on the platform's own cluster Cluster objects, network claims, backups, your quota Whatever your platform team gave you
Your clusters — real Kubernetes clusters, one control plane each Everything you run: workloads, volumes, Services A kubeconfig per cluster, from a Secret in the Environment

You are cluster-admin inside your clusters and can do anything there. In the Environment you can do a specific, bounded set of things — create clusters, claim addresses, take backups — and your quota is enforced there.

Commands on these pages say which of the two they mean whenever it is not obvious from context.

Clusters

Create Clusters — a Cluster object in your Environment, and the kubeconfig that comes out of it.

Scale Clusters — worker capacity, and what is and is not adjustable on the control plane.

Upgrade Clusters — moving to a new Kubernetes version.

Maintenance — health, node draining, and stopping a cluster without deleting it.

Delete Clusters — decommissioning, and what goes with it.

Workloads

Persistent Storage — claiming a volume, the quota that bounds it, snapshots and growth.

Exposing Workloads — LoadBalancer Services, external addresses, and Ingress.

Deploying Applications — what your cluster ships with, how it differs from a managed cloud cluster, and add-ons across clusters.

Data protection

Data Protection — which mechanism protects which loss, and what to settle before you need either.

Volume Snapshots — point-in-time copies of a volume, and restoring one.

Cluster Backup & Restore — archiving a cluster's objects, and rebuilding into a new cluster.

Access and diagnostics

Console Usage — the web console, and downloading a kubeconfig from it.

Troubleshooting — clusters that do not come up, workloads that will not run.

Two things that are not yours

Worth knowing early, because they are not gaps to work around:

Your quota. Storage, addresses and cluster count are capped on the platform side and refuse you when you make the request, not later. Raising one is a conversation, not a config change.

Your cluster's CNI and CSI. The platform delivers them and puts them back if they are changed. Everything else inside the cluster is yours.


Looking something up: Reference — the Cluster topology variables, the claims API, and the CLI.