Skip to content

For Kubernetes

Kubernetes on Edge, without the platform tax

k3s, RKE2 or vanilla kubeadm on real VMs. Local NVMe for stateful pods, Velero backups in S3-compatible storage and 988 CDN locations in front of your ingress. The control plane is just another VM.

Free to sign up. No egress fees on any product.

Why Kubernetes on Edge

The primitives Kubernetes assumes, without the markup

Real VMs, private networking and object storage. Bring your own distribution and GitOps tooling.
  • Your distribution, your call

    k3s for lightweight clusters, RKE2 for hardened production, kubeadm for upstream. No proprietary control plane.
  • A private network for the cluster

    Nodes talk over a private network, so etcd and API traffic stays off the public internet. VM-to-VM bandwidth is free.
  • Volumes that persist

    Local NVMe for IOPS-hungry pods, plus S3-compatible storage for backups, snapshots and shared blob data.
  • The CDN in front of ingress

    Put Traefik, ingress-nginx or Istio behind 988 CDN locations. Automatic SSL and zero egress on the way out.
  • No control-plane fee

    Managed Kubernetes typically bills about $73 a month per cluster before a single node. Here the control plane is a VM you already pay for.
  • GitOps-ready

    Point Flux or Argo CD at the cluster and deploy from a repository. The Edge CLI builds the nodes; Git does the rest.

Reference architecture

How a cluster maps to Edge

Three control-plane VMs, three workers on the same private network, backups in object storage and the CDN handling the world.
  • Compute

    VMs for control-plane and worker nodes, sized independently.

  • Storage

    Velero backups, snapshots and shared blob data over the S3 API.

  • CDN

    Sits in front of your ingress controller for global delivery.

  • Image optimisation

    On-the-fly transforms for any media your pods serve.

  • DNS

    Anycast DNS for *.acme.io; pairs well with ExternalDNS.

  • Shield

    Scores logins, sign-ups and forms from any service in the cluster.

  • Assist

    An answer box for whatever the cluster serves, one script tag.

Deploy

A six-node k3s cluster in five steps

Two custom startup scripts do the install. Attach every VM to one private network from the Networking tab; k3s keeps retrying until the private address answers.
  1. 01

    Write the bootstrap scripts

    Startup scripts substitute ${param} values before they run. The first server starts etcd; the rest join it.

    k3s-server.sh · k3s-agent.sh
    #!/bin/bash
    # k3s-server.sh: empty join_ip starts a new cluster
    set -e
    ARGS="--cluster-init"
    [ -n "${join_ip}" ] && ARGS="--server https://${join_ip}:6443"
    curl -sfL https://get.k3s.io | K3S_TOKEN="${k3s_token}" \
      sh -s - server $ARGS
    
    #!/bin/bash
    # k3s-agent.sh
    set -e
    curl -sfL https://get.k3s.io | K3S_URL="https://${server_ip}:6443" \
      K3S_TOKEN="${k3s_token}" sh -
  2. 02

    Bring up the control plane

    Register both scripts, then create three servers. cp-1 initialises etcd and the other two join it.

    shell
    $ edge compute scripts create --name k3s-server --file k3s-server.sh
    $ edge compute scripts create --name k3s-agent --file k3s-agent.sh
    $ TOKEN=$(openssl rand -hex 32)
    
    $ edge compute create --name cp-1 --size s-2vcpu-4gb \
        --image ubuntu-24 --region london --script k3s-server \
        --script-param k3s_token=$TOKEN
    $ for n in 2 3; do edge compute create --name cp-$n \
        --size s-2vcpu-4gb --image ubuntu-24 --region london \
        --script k3s-server --script-param k3s_token=$TOKEN \
        --script-param join_ip=10.0.0.2; done
  3. 03

    Add the workers

    Performance VMs give pods 160 GB of local NVMe each. Copy the kubeconfig and swap 127.0.0.1 for cp-1's address.

    shell
    $ for n in 1 2 3; do edge compute create --name worker-$n \
        --size s-4vcpu-8gb --image ubuntu-24 --region london \
        --script k3s-agent --script-param k3s_token=$TOKEN \
        --script-param server_ip=10.0.0.2; done
    
    $ scp root@<cp-1-ip>:/etc/rancher/k3s/k3s.yaml ~/.kube/config
    $ kubectl get nodes
  4. 04

    Lock it down and front the ingress

    Only HTTPS is public; the API server answers on the private range. The CDN caches what it can and passes the rest to Traefik.

    shell
    $ edge compute groups create --name k8s-nodes
    $ edge compute groups add-rule grp-abc123 --port 443 \
        --protocol tcp --source 0.0.0.0/0
    $ edge compute groups add-rule grp-abc123 --port 6443 \
        --protocol tcp --source 10.0.0.0/8
    
    $ edge cdn create --name acme-cluster
    $ edge cdn domains add cdn-a1b2c3 \
        --domain app.acme.io --origin https://<worker-ip>
  5. 05

    Back up the cluster to Edge Storage

    Velero's AWS plugin speaks to any S3 endpoint. Schedule nightly backups and test a restore before you need one.

    shell
    $ edge storage create k8s-backups
    $ S3=https://storage.edge.network
    $ velero install --provider aws --bucket k8s-backups \
        --plugins velero/velero-plugin-for-aws:v1.12.0 \
        --secret-file ./edge-credentials \
        --use-volume-snapshots=false \
        --backup-location-config \
          region=us-east-1,s3ForcePathStyle=true,s3Url=$S3
    $ velero schedule create nightly --schedule="0 3 * * *"

Prefer to hand it off? Give the job to your AI agent or have our engineers do it.

What it costs

A production cluster, itemised

Six VMs, a CDN deployment and a backup bucket. No control-plane fee, no per-load-balancer hours and no egress line.
  • No control-plane or cluster-management fee
  • ~2 TB of egress costs $0
  • 200 GB of volumes on included local NVMe
  • Hourly billing with optional hard caps
See compute pricing

Estimated monthly bill on Edge

3 control-plane + 3 worker nodes · 200 GB persistent storage · ~2 TB egress

USD
  • Control plane$57.723 × Standard VM (2 vCPU · 4 GiB) at $19.24
  • Workers$115.413 × Performance VM (4 vCPU · 8 GiB · 160 GB NVMe) at $38.47
  • CDN$2.5010.5M requests: 500k free, then 10M × $0.25 per million
  • Storage$3.00205 GB of Velero backups: 5 GB free, then 200 GB × $0.015
  • DNS$0.00Wildcard zone for *.acme.io
  • Egress$0.00
Total$178.63

Indicative monthly cost · modest production cluster

  • EKS + EC2 + EBS + NLB + egress~$700–1,400
  • GKE Standard + nodes + LB~$600–1,200
  • Edge (6 VMs + CDN + Storage)~$120–280

Indicative figures. On the hyperscalers, egress alone often dwarfs the control-plane fee.

FAQ

Kubernetes on Edge, answered

Something else? Ask an engineer.
Which distribution should I use?
For most teams, k3s: a single binary that runs happily on small nodes and supports almost all of upstream Kubernetes. Choose RKE2 for FIPS or CIS hardening, and kubeadm if you need to pin to upstream.
How does this compare to EKS, GKE or AKS?
Cheaper, with no control-plane fee, no per-load-balancer hours and zero egress. More portable too: vanilla Kubernetes, no cloud-specific CRDs, and root on every node. The trade-off is that you run upgrades, or our Expert Services team does.
Local volumes or S3?
Local NVMe for databases and anything IOPS-sensitive. An S3 CSI driver such as geesefs for shared assets and bulk data. Velero on Edge Storage covers cluster-wide backup and disaster recovery.
Can a cluster span regions?
Private networks are per region, so keep each cluster's nodes in one region. For multi-region, run a cluster per region and route between them with geo DNS and the CDN.
How do upgrades work?
With k3s, the system-upgrade-controller rolls new versions across nodes from a plan in Git. Snapshot the VMs and take a Velero backup first, then upgrade servers before agents.

Run Kubernetes the cheap way

Start free and stand up a cluster in minutes, or have our Expert Services team design and run it for you.

Free tiers hard-cap. Nothing bills until you add a card.