Cloud-grade control plane, infrastructure-agnostic compute.

K8S Engine is designed like a managed cloud service—with the flexibility to run nodes anywhere. Here's how the architecture works.

K8

Control Plane (K8S Engine)

The control plane runs in K8S Engine's infrastructure. You don't manage any of these components.

Kubernetes API endpoint
Controllers and scheduler
etcd cluster (HA, encrypted)
Backup service
Upgrade orchestrator
Observability stack
You

Your Infrastructure

Nodes run in your accounts, on your hardware, in your datacenters. You control placement and cost.

Node Pools (via Cluster API)

Managed scaling across providers

Nodes across providers / bare metal

Your infrastructure, your choice

Workloads and namespaces

Your applications and services

Optional site connectivity components

For advanced networking scenarios

Connectivity model

Secure, outbound-first connectivity between your nodes and the K8S Engine control plane.

Outbound tunnels with mTLS

Nodes initiate connections to the control plane. No inbound firewall rules required on your infrastructure.

Identity-bound cluster association

Nodes authenticate using bootstrap tokens and certificates. Association is cryptographically verified.

Rate limiting and abuse prevention

API rate limiting and request validation protect against misconfigured clients and potential abuse.

Reliability model

Built for production workloads with defined availability guarantees.

HA control plane options

Pro and Enterprise tiers include highly available control planes with redundant components.

Continuous health checks

Control plane components are continuously monitored. Issues are detected and addressed automatically.

Automated failover

Component failures trigger automatic failover. Maintenance routines run without manual intervention.

Defined SLOs

Control plane availability SLOs are documented and tiered. Enterprise includes premium SLA commitments.

Technical specifications

Kubernetes versionsLatest 3 minor versions (e.g., 1.28, 1.29, 1.30)
etcdManaged, HA, encrypted at rest, daily backups
Control plane SLA99.9% (Pro), 99.99% (Enterprise)
Node connectivityOutbound tunnels, mTLS, certificate rotation
Supported providersAWS, Azure, GCP, Hetzner, IONOS, bare metal

Designed like a managed cloud service—without forcing a cloud migration.