← All platforms
install
Connect a self-managed cluster
kubeadm, RKE2, k3s or any cluster with Cilium as the CNI.
Requirements
- Cilium
- The cluster CNI, with Hubble and Hubble Relay enabled.
- Network
- Outbound HTTPS (443) from the cluster to api.cilera.io and ingest.cilera.io.
- Tools
- kubectl and Helm 3.8+ with access to create a namespace.
- Footprint
- One pod. No privileged access, no host mounts, read-only RBAC.
Steps
- Run Cilium with Hubble enabled. Start the cluster with no default CNI, then install Cilium. If Cilium is already installed, check that cilium status shows "Hubble Relay: OK" and continue to step 2.
# k3s: --flannel-backend=none --disable-network-policy # RKE2: set "cni: cilium" in /etc/rancher/rke2/config.yaml cilium install cilium hubble enable cilium status --wait
On RKE2, enable Hubble Relay in the rke2-cilium HelmChartConfig instead of running cilium install.
- Add the cluster in the Cilera console. Open Clusters → Add cluster, name the cluster, and copy the install command. The command includes a one-time onboarding token that expires.
- Run the command. It installs the operator with Helm into the cilera-system namespace. The cluster appears in the Cilera console within about a minute.
$ kubectl -n cilera-system get pods NAME READY STATUS cilera-operator-7c9d8b6f5d-x2kqp 1/1 Running
For platform-specific Cilium options, see the Cilium installation guide.