Understanding VKS Core and Standard Packages in VMware Cloud Foundation

Kubernetes is now an important part of many modern application platforms. However, running Kubernetes in an enterprise environment is not only about creating a cluster.

You also need networking, storage, authentication, security, observability, backup, scaling and other services around the Kubernetes platform.

This is where vSphere Kubernetes Service (VKS) and its package model become interesting.

VKS provides a set of packages that extend the Kubernetes platform running on VMware Cloud Foundation (VCF). These packages are divided into two main groups:

  • Core Packages
  • Standard Packages

Understanding the difference between these two groups is important when designing and operating Kubernetes environments on VCF.

Core Packages: The Foundation

Core Packages are the components that provide the fundamental functionality required by a VKS cluster.

They are installed by default, bundled with the vSphere Kubernetes Release (VKr), and lifecycle-managed as part of the Kubernetes platform. They are also fully runtime-supported. 

The main Core Packages cover authentication, storage, networking, cloud provider integration, and package and secret management.

Authentication and Access

VKS includes components such as Pinniped and the guest-cluster-auth-service.

Pinniped provides authentication integration with external identity providers, while the authentication service provides the mechanisms required to authenticate users accessing the Kubernetes environment.

This means authentication is integrated into the platform instead of being something that administrators need to build separately for every cluster.

Storage

The vSphere CSI Driver provides the integration between Kubernetes and vSphere storage.

This allows Kubernetes workloads to use persistent volumes backed by vSphere storage such as vSAN and VMFS.

For stateful applications, this integration is particularly important because applications can request persistent storage using standard Kubernetes mechanisms.

Networking

VKS supports Kubernetes networking through CNI implementations such as Antrea and Calico.

These components provide pod networking and network policy capabilities.

Antrea is also required when using Istio Service Mesh in VKS. 

Cloud Provider Integration

The vSphere Cloud Provider Interface (CPI) provides integration between Kubernetes and the underlying vSphere infrastructure.

Among other capabilities, it provides infrastructure information to Kubernetes nodes and supports functionality such as load balancer provisioning.

Package and Secret Management

VKS also includes components such as kapp-controller and secretgen-controller.

These provide capabilities for managing packages and secrets in a declarative way.

Together, these Core Packages provide the basic building blocks that allow Kubernetes to operate as an integrated part of the VCF platform.

Standard Packages: Extending VKS

Core Packages provide the foundation, but not every Kubernetes environment has the same requirements.

This is where Standard Packages come in.

Standard Packages are optional packages that administrators can deploy depending on their operational requirements.

They cover areas such as:

  • Networking
  • Security and identity
  • Observability
  • DevOps
  • Scaling
  • Resilience

Unlike Core Packages, Standard Packages have an independent release lifecycle and are managed separately from the Kubernetes upgrade process. Broadcom provides installation and upgrade support, with runtime support available for selected packages such as Istio.

Networking

Contour

Contour is an Envoy-based ingress controller.

It can be used to manage HTTP and HTTPS traffic entering Kubernetes applications.

ExternalDNS

ExternalDNS automates DNS record management for Kubernetes services and ingresses.

This can reduce the amount of manual DNS configuration required when applications are deployed or changed.

Istio Service Mesh

Istio provides service mesh capabilities for Kubernetes applications.

It can provide:

  • Secure service-to-service communication
  • Mutual TLS (mTLS)
  • Traffic management
  • Load balancing
  • Observability
  • Policy capabilities

Istio was introduced as a VKS Standard Package with VKS 3.4, with runtime support beyond the installation and upgrade support normally provided for Standard Packages. 

Security and Identity

Cert-Manager

Cert-Manager automates the provisioning and renewal of TLS certificates.

This is useful for applications and services that need certificates without requiring administrators to manage the complete certificate lifecycle manually.

Windows gMSA

Windows Group Managed Service Accounts (gMSA) allow Windows containers running in Kubernetes to use Active Directory service accounts.

This is particularly useful in environments where Windows and Linux workloads need to run on the same Kubernetes platform.

Observability

Running Kubernetes in production requires good visibility into the environment.

VKS Standard Packages include several components that can help with this.

Fluent Bit

Fluent Bit is used to collect, process and forward container logs.

Telegraf

Telegraf is a plugin-based agent that can collect and forward metrics.

Prometheus and Alertmanager

Prometheus provides a time-series monitoring database, while Alertmanager provides alerting capabilities.

Together, these components can provide the monitoring foundation required for Kubernetes workloads and infrastructure.

DevOps Tooling

Harbor

Harbor provides a container registry for storing and managing container images.

It also provides capabilities such as vulnerability scanning and image signing.

For organizations running multiple Kubernetes clusters, having a controlled container registry can be an important part of the overall software supply chain.

caling and Resilience

Kubernetes environments also need to handle changing workloads and recover from failures.

VKS includes Standard Packages for both of these requirements.

Cluster Autoscaler

Cluster Autoscaler can automatically adjust Kubernetes node pools based on workload requirements.

When additional capacity is required, nodes can be added. When capacity is no longer needed, nodes can be removed.

Velero

Velero provides backup and recovery capabilities for Kubernetes resources and persistent volumes.

This can be used as part of a broader backup and disaster recovery strategy for Kubernetes workloads.

Why the Difference Between Core and Standard Matters

At first, the distinction between Core and Standard Packages might look like a simple categorization.

There is actually an important operational difference.

Core Packages are tightly connected to the VKr lifecycle. They are bundled with the Kubernetes release and are lifecycle-managed as part of the platform.

Standard Packages, on the other hand, can evolve independently.

This gives administrators more flexibility. A package such as Prometheus, Harbor or Velero does not necessarily need to wait for the next Kubernetes cluster upgrade before receiving a new package release.

At the same time, the packages are validated for compatibility with the supported VKr versions.

This is particularly useful because Kubernetes environments can quickly become complex when administrators have to manage compatibility between many different open-source components.

A Simple Comparison

Core PackagesStandard Packages
DeploymentInstalled by defaultOptional
LifecycleManaged with VKrIndependent lifecycle
Version alignmentBundled with VKrValidated against VKr versions
Runtime supportFull runtime supportInstallation & upgrade support; selected packages have runtime support
NetworkingAntrea / CalicoContour / ExternalDNS / Istio
StoragevSphere CSI—
AuthenticationPinniped / Auth Service—
Security—Cert-Manager / Windows gMSA
Observability—Fluent Bit / Telegraf / Prometheus
Container Registry—Harbor
Backup—Velero
Scaling—Cluster Autoscale

The Bigger Picture

One of the main benefits of this model is that Kubernetes does not have to be treated as a completely separate platform from the infrastructure underneath it.

VKS brings Kubernetes into the VCF environment while providing integrations for infrastructure services such as compute, storage and networking.

The Core Packages provide the foundation required for the cluster to operate.

Standard Packages then add capabilities that many production environments need, such as ingress, service mesh, monitoring, certificate management, container registries, backup and autoscaling.

This creates a layered approach:

VCF infrastructure → VKS → Core Packages → Standard Packages → Applications

Each layer provides a different part of the overall platform.

Final Thoughts

For me, the important thing to understand about VKS is not simply the list of packages.

It is how the packages are managed.

Core Packages are part of the VKS foundation and follow the VKr lifecycle. Standard Packages provide additional capabilities while giving administrators more flexibility around when and how those components are consumed.

This separation makes it easier to understand what is fundamental to the Kubernetes platform and what can be added based on the requirements of a particular environment.

For organizations already using VMware Cloud Foundation, VKS provides a way to run Kubernetes while keeping the Kubernetes platform closely integrated with the existing infrastructure and management

Leave a comment