Available in editions: Open/CE, BE, SE, SE+, Ultimate/EE, Core
Included in extensions: On-prem IaaS
The module lifecycle stage: General Availability
The module is automatically enabled for all cloud clusters deployed in DVP.
The credentials for accessing the parent cluster API are not stored in the module settings. The platform reads them from the d8-credentials Secret, whose format is covered in the Credentials Secret section.
The module has 1 alert.
Conversions
The module is configured using the ModuleConfig resource, the schema of which contains a version number. When you apply an old version of the ModuleConfig schema in a cluster, automatic transformations are performed. To manually update the ModuleConfig schema version, the following steps must be completed sequentially for each version :
- Updates from version 1 to 2:
- Move
provider.namespacetoprovider.parameters.namespace. - Move
zonestonodes.parameters.zones. - Delete
provider.kubeconfigDataBase64. The kubeconfig is stored in a Secret of typecloud-provider.deckhouse.io/credentials. - Set
nodes.parameters.layout(defaults toStandard). - Replace the placeholder in
nodes.parameters.sshPublicKeywith a real SSH public key.
- Move
Parameters
Schema version: 2
- objectsettings
- objectsettings.ccm
Cloud Controller Manager (CCM) subsystem settings.
CCM integrates the cluster with the cloud provider — for example, it manages load balancers. You can enable or disable CCM independently of other subsystems. For instance, leave CCM enabled if you only need load balancer management in the cluster.
- booleansettings.ccm.disabled
Disables the Cloud Controller Manager.
Set to
trueif CCM is not required. Leave enabled (false) when you need cloud load balancer management.Default:
false
- objectsettings.nodes
Required value
Nodes subsystem settings.
Controls node management in the cluster.
- booleansettings.nodes.disabled
Disables the node management subsystem.
Default:
false - objectsettings.nodes.parameters
Required value
Parameters of the nodes subsystem.
- objectsettings.nodes.parameters.ipAddresses
A map of static IP addresses for CloudPermanent NodeGroups.
The map key is the NodeGroup name, the value is a list of IP addresses assigned to nodes of that group. The number of addresses must match the number of replicas — each IP address is assigned to a specific replica.
Example:
ipAddresses: master: - 10.66.30.100 - 10.66.30.101 - 10.66.30.102 worker: - 10.66.30.200 - 10.66.30.201These addresses must belong to the address range specified in the virtualization module configuration in the
virtualMachineCIDRsparameter. - stringsettings.nodes.parameters.layout
Required value
Layout name.
Allowed values:
Standard - stringsettings.nodes.parameters.region
Region name.
To use this setting, the
topology.kubernetes.io/regionlabel must be set on DVP nodes. Read more about topological labels.To set the required label for a DVP node, follow the NodeGroup documentation.
- stringsettings.nodes.parameters.sshPublicKey
Required value
A public key for accessing nodes.
- array of stringssettings.nodes.parameters.zones
A set of zones in which nodes can be created.
To use this setting, the
topology.kubernetes.io/zonelabel must be set on DVP nodes. Read more about topological labels.To set the required label for a DVP node, follow the NodeGroup documentation.
- objectsettings.provider
Required value
Settings for connecting to the parent Deckhouse Virtualization Platform (DVP).
- objectsettings.provider.parameters
Required value
Contains settings to connect to the Deckhouse Platform API.
- stringsettings.provider.parameters.namespace
Required value
Namespace in which DP cluster resources will be created.
If not explicitly specified, the default namespace for kubeconfig will be used.
- stringsettings.provider.parameters.networkPolicy
Control rules for network traffic to and from workloads running in the Project resource.
Isolated: Applies a restrictive NetworkPolicy that allows only network traffic required for platform system components to function. All other traffic is denied.None: The cluster does not request any network policies. Existing project-level restrictions still apply.
Allowed values:
Isolated,None
- objectsettings.storage
Storage subsystem settings.
Controls disk provisioning in the cluster.
- booleansettings.storage.disabled
Disables the storage subsystem.
When set to
true, disk provisioning in the cluster is unavailable.Default:
false - objectsettings.storage.parameters
Required value
Parameters of the storage subsystem.
- array of stringssettings.storage.parameters.excludedStorageClasses
A list of StorageClass names (or regex expressions for names) to exclude from creation in the cluster.

