- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
Kubernetes on VMware: What are the Options?
Learn about different ways to run Kubernetes on VMware, including the vSphere Kubernetes integration and Tanzu Kubernetes Grid Integrated Edition (TKGI)
Table of Contents
- How Does Kubernetes Run on VMware?
- Running Kubernetes Alongside VMware Workloads
- How Does vSphere with Kubernetes Work?
- Running Kubernetes in a Multi Cloud Environment with Tanzu Kubernetes Grid Integrated Edition (TKGI)
- Tanzu Kubernetes Grid Integrated Edition Features
- Tanzu Kubernetes Grid Integrated Edition vs Tanzu Kubernetes Grid
How Does Kubernetes Run on VMware?
Kubernetes is an open-source container orchestration platform that automates the management of containerized applications. VMware provides virtualization platforms used by a majority of enterprises. As containers become more popular, a growing requirement is to deploy containers and manage them alongside traditional virtual machines, on VMware infrastructure.
In 2019, VMware started supporting Kubernetes as part of its vSphere virtualization platform, which includes the ESXi hypervisor. It is now possible to run containers directly on ESXi, or use the Tanzu Kubernetes Grid platform to manage standard Kubernetes clusters, compatible with upstream Kubernetes development. Tanzu makes it possible to run Kubernetes in production, managing large numbers of Kubernetes clusters across VMware infrastructure, bare metal servers, and public clouds.
In this article, you will learn:
- Running Kubernetes Alongside VMware Workloads
- How Does vSphere with Kubernetes Work?
- Supervisor vs. Guest Clusters
- Running Kubernetes in a Multi Cloud Environment with Tanzu Kubernetes Grid Integrated Edition (TKGI)
- Tanzu Kubernetes Grid Integrated Edition Features
- Tanzu Kubernetes Grid Integrated Edition vs Tanzu Kubernetes Grid
Running Kubernetes Alongside VMware Workloads
VMware vSphere is VMware’s flagship virtualization platform. Since version 7, vSphere fully supports Kubernetes. It is built to support developers, who are familiar with Kubernetes, and IT staff who are familiar with vSphere system constructs:
- For developers, vSphere looks and acts like regular Kubernetes. They can use normal Kubernetes constructs and declarative configuration to request compute resources, storage, networking, and high availability. In the background, the requests are fulfilled via vSphere resources, but developers do not need to be aware of vSphere infrastructure.
- For IT administrators, vSphere works exactly like in the past, only with new workload management capabilities. vSphere Admins can work with “namespaces”, which behave just like regular virtualized workloads, but are also visible within Kubernetes. This is how admins can manage the security, resources, and networking available to the Kubernetes environment.
How Does vSphere with Kubernetes Work?
vSphere has been deeply integrated with Kubernetes, by adding the Kubernetes APIs as a new control plane. This lets Kubernetes users consume services seamlessly from the VMware environment, just like they would in a public cloud. vSphere can now manage workloads consistently, whether they are containers, applications, or virtual machines.
The ESXi hypervisor, which is at the core of vSphere, now includes the Kubernetes API, as well as the Spherelet, a management agent based on the Kubernetes Kubelet. This lets the ESXi hypervisor act as a native Kubernetes node, which can join Kubernetes clusters.
ESXi hosts can run containers directly on the hypervisor. This is made possible by a new container runtime called CRX, which is provided as part of vSphere. This approach does not require loading a full Linux guest OS, instead it uses a highly optimized Linux kernel and lightweight init process.
Within Kubernetes, these containers can be accessed as part of a vSphere Pod Service. The vSphere Pod Service lets you run vSphere containers in Kubernetes, but they are not fully conformant Kubernetes clusters.
Supervisor vs. Guest Clusters
vSphere lets users run two types of Kubernetes clusters:
- Supervisor cluster—a special kind of Kubernetes cluster that runs worker nodes directly on the ESXi hypervisor (not on Linux). Container workloads run in vSphere Pods, and offer the same security, high availability and performance of ESXi. However, a supervisor cluster is not a standard Kubernetes cluster, and cannot work seamlessly with existing Kubernetes deployments.
- Tanzu Kubernetes Cluster (guest cluster)—this is a cluster, based on VMware infrastructure, which is compatible with upstream Kubernetes. A Tanzu cluster runs on virtual machines, not vSphere Pods. It uses the open source Cluster API project, which uses the VM Operator to manage virtual machine workflows for the cluster.
Running Kubernetes in a Multi Cloud Environment with Tanzu Kubernetes Grid Integrated Edition (TKGI)
VMware Tanzu Kubernetes Grid Integrated Edition is a VMware platform that makes it possible to run Kubernetes on heterogeneous multi-cloud environments, including public clouds and on-premises VMware environments. It supports both day 1 (initial cluster deployment) and day 2 operations (patching, upgrades, and high availability).
The main goal of TKGI is to expose Kubernetes in standard form, making Tanzu clusters fully compatible with existing Kubernetes deployments and upstream Kubernetes development. Developers work with the native Kubernetes CLI and APIs just like if they were deploying Kubernetes locally or on a public cloud.
The platform lets you deploy Kubernetes clusters on:
- On-premises bare metal
- OpenShift
- On-premises VMware vSphere environments
- Public clouds including Amazon, Microsoft Azure, and Google Cloud Platform, Amazon EC2, and Microsoft Azure
TKGI provides robust management tools, including Tanzu Mission Control, which manages Kubernetes clusters on one pane of glass, whether they reside on vSphere, PKS, OpenShift, or public cloud services. Mission Control also provides policies that govern user access, resource quotas, backups, and many other aspects of a cluster, in a unified way across clouds.
TKGI comes pre-integrated with a full stack of solutions, including:
- Cloud Foudry BOSH for cluster lifecycle management
- VMware NSX-T for pod networking and load balancing
- Harbor as cloud native repository handling container images, vulnerability scanning, etc.
- Docker Community Edition (Docker-CE) as container engine
- Velero for backup and disaster recovery of Kubernetes clusters
- Prometheus for Kubernetes monitoring, with Grafana for visualization
- Sonobuoy for diagnosing the state of Kubernetes clusters.
- Fluentbit for log processing and forwarding
Tanzu Kubernetes Grid Integrated Edition Features
Here are some of the key features of Tanzu Kubernetes Integrated Edition (formerly Enterprise PKS).
- High availability—supports multi-AZ replication and multi-master etcd deployments. Monitors health of all underlying virtual machines and heals VMs upon failure. It manages rolling upgrades for fleets of Kubernetes clusters with no downtime.
- Persistent storage—supports both stateless and stateful applications. Provides both the vSphere Cloud Provider storage plugin and standard CSI storage, supporting Persistent Volumes (PV), Persistent Volume Claims (PVC), Storage Classes and Stateful Sets. All these constructs can be used to provision vSphere storage including vSAN.
- Kubernetes lifecycle management—provides central control over the entire lifecycle of Kubernetes clusters running on bare metal, VMware vSphere or in the public cloud.
- Unified access management—centralized management for cluster access, letting the organization define in one place which teams can access which clusters, as an added management layer above Active Directory groups.
- Security and configuration management—defining security and network policies at scale across multiple clusters. Allows administrators to manage policies by grouping Kubernetes clusters together in workspaces, divided according to functional teams or development stages, and applying policies to all clusters in a group at once.
Related content: read our guide to Kubernetes security best practices ›
Tanzu Kubernetes Grid Integrated Edition vs Tanzu Kubernetes Grid
Alongside TKGI, VMware also provides Tanzu Kubernetes Grid (TKG). This is a separate offering with a deeper vSphere integration, but which is less suitable for multi-cloud deployment.
The following table summarizes three flavors of the VMware Tanzu platform.
| Tanzu Kubernetes Grid Integrated Edition (TKGI) | Formerly named Enterprise Pivotal Container Service (PKS). Primarily focused on integration of Kubernetes, BOSH for cluster lifecycle management, NSX-T for pod networking and load balancing, Harbor as a container registry, and the Docker engine (Docker-CE). Comes in three editions – Basic, Standard and Advanced |
| Tanzu Kubernetes Grid (TKG) | Formerly called Essential Pivotal Container Service (PKS). Can run as part of vSphere deployments, or on AWS using EC2 compute instances. Also supports VMware Cloud Foundation (VCF) 3.9.x. |
| Tanzu Kubernetes Grid Service for vSphere | Also called TKS for VMware Cloud Foundation. The only supported Kubernetes option for vSphere 7 and VCF 4. Makes it possible to manage clusters using the vSphere WebClient. |
- What Is Kubernetes?
- 10 Kubernetes Alternatives and Why You Need Them
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster: 11 Key Components
- Kubernetes Nodes: Components and Basic Operations
- Kubernetes Pods
- Kubernetes Jobs: A Practical Guide
- What Are Kubernetes Workloads, How They Work, and Security Tips
- Kubernetes Monitoring: Metrics, Challenges, and Best Practices
- Kubernetes Security
- Kubernetes RBAC: Why You Need It and 4 Tips for Success
- How Secret Scanning Works and 4 Places to Scan for Secrets
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes Vulnerability Scanning: What You Should Know
- Managing Containers in Kubernetes
- What is K3s? Architecture, Setup, and Security
- eBPF in Kubernetes: Improving Observability for K8s Clusters
- Kubernetes Dashboard: Ultimate Quick Start Guide
- Kubernetes Operators: How they Work and 6 Operators to Try
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap: Creating, Viewing, Consuming & Managing
- Kubernetes Management
- Kubernetes Helm
- Top 6 Kubernetes as a Service Providers and Why You Need Them
- Kubernetes Serverless
- 70 Best Kubernetes Tutorials
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!