Skip to main content
Version: main 🚧

What happens during control plane outages?

vCluster Platform is the management plane for projects, access, templates, lifecycle operations, and connected cluster visibility. Clusters have their own control planes. Those control planes might run on the same Kubernetes cluster as Platform or on separate connected clusters.

Because these layers are separate, an outage affects different capabilities depending on what is unavailable.

Platform outage​

If vCluster Platform is unavailable but the connected clusters and cluster control planes remain healthy, clusters do not automatically stop. Existing workloads are not intentionally deleted because Platform is unavailable.

CapabilityStatusImpact
Platform UI and APIUnavailableUsers and automation cannot reliably use Platform while it is down.
Lifecycle operationsUnavailableCreating, deleting, sleeping, waking, updating, or restoring clusters fail or wait.
Access, audit, and integrationsLimitedPlatform-provided access features, audit, integrations, and automation are unavailable or delayed.
Cluster runtimeAvailableClusters do not automatically stop if their own control planes and connected clusters remain healthy.
External deployment toolsAvailableExternally deployed clusters continue to be managed by their original deployment tool.

Platform high availability protects the management plane by running multiple Platform replicas. It doesn't replace high availability for cluster control planes or for the control plane clusters they run on. See High Availability Installation.

Connected control plane cluster outage​

A connected control plane cluster is a Kubernetes cluster where Platform can deploy or manage clusters. If a connected control plane cluster is unavailable, Platform can't complete operations that require access to that cluster.

CapabilityStatusImpact
Platform UI and APIAvailablePlatform remains reachable and continues managing other healthy connected clusters.
Connected cluster visibilityLimitedPlatform marks the connected cluster or its network peer as offline until connectivity returns.
Lifecycle operations on that clusterUnavailablePlatform can't create, update, delete, sleep, wake, or inspect clusters hosted there.
Cluster reconciliationUnavailablePlatform-managed reconciliation pauses or fails for clusters on the unavailable cluster.
Tenant workloadsLimitedAvailability depends on whether their control planes and worker nodes are still running and reachable.

If cluster control planes are hosted on the unavailable control plane cluster, tenant users can't reliably use those cluster APIs until the control plane cluster recovers. For the cluster view of this behavior, see What happens during control plane outages?.

Cluster control plane outage​

If an individual cluster control plane is unavailable but Platform remains healthy, Platform can still be reachable, but operations against that cluster are limited. Platform may report the cluster's phase as pending or failed, and its status conditions can further indicate that it isn't ready or is offline, depending on the deployment model and connectivity path.

CapabilityStatusImpact
Platform UI and APIAvailablePlatform can remain reachable and continue managing other healthy clusters.
Operations for this clusterLimitedOperations that require the unavailable cluster API can fail or remain pending.
Cluster statusLimitedPlatform may report the cluster's phase as pending or failed, with status conditions indicating it isn't ready or is offline.
Existing tenant workloadsLimitedPlatform does not intentionally delete them for clusters connected through an agent on a connected cluster.
Other clustersAvailableHealthy clusters can continue to be managed independently.

For externally deployed clusters connected directly through a network peer, such as vCluster Standalone, using their own backing store, Platform deletes the instance if it stays disconnected for more than 7 days. Clusters connected through an agent are not affected by this cleanup.

Recovery resumes after the cluster control plane becomes reachable again.

For production environments, plan availability at each layer: Platform, the connected control plane clusters, and the cluster control planes.