Pre-Requisites
kubectl#
First install kubectl if not already installed
Auto completions for kubectl (optional)#
Install Kubernetes (optional)#
To install sdc on a Kubernetes cluster we first need to install a Kubernetes cluster. Other than the minimum version being v1.291, sdc has no special requirements on the k8s cluster, so any k8s flavor should work, bearing in mind the minimum version1
Install cert-manager#
SDC depends on cert-manager to issue the TLS certificate served by the config-server's aggregated API server and to keep the APIService caBundle in sync with the SDC root CA via cainjector. cert-manager must be installed and ready before the SDC manifests are applied. See Cert-Manager & TLS Trust Chain for how the chain is built and rotated.
Install cert-manager (tested with v1.20.2):
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.20.2/cert-manager.yaml
Wait for all three cert-manager components to be Available — the controller issues certificates, the cainjector populates the APIService caBundle, and the webhook validates cert-manager CRs. SDC needs all three before its resources are applied:
kubectl wait -n cert-manager --for=condition=Available=True --timeout=300s \
deployment/cert-manager \
deployment/cert-manager-cainjector \
deployment/cert-manager-webhook
-
A minimum Kubernetes version of v1.29 is required to support API Priority and Fairness ↩↩