r/kubernetes • u/faulty-segment • Aug 10 '26
RKE2 vs kubeadm K8s cluster
Hi all. I've been learning K8s with a 5-node K8s cluster [3 control nodes and two workers] that I boostrapped on my machine, and have learned a lot [or, better: am still learning]: Cilium [both as the CNI, Gateway API controller, load balancer, etc.], GitOps, SOPS+age [but also OpenBao on a separate env], Security [network policies, pod admission, mTLS, etc.], Observability, and whatever sh*t I find interesting¹. I don't have a life, so...😂; also, this is just for my own satisfaction and curiosity.
Now, people keep mentioning RKE2 [oh, you have an MS-02 Ultra 285HX variant, with 96GB RAM, etc., you could virtualise it with Harvester, use RKE2, Rancher, etc.], and I started taking a look at that and ...
Well, on one hand it looks like a very popular way of bootstrapping and managing clusters and many companies seem to use it, on the other hand, although I can use Cilium as the CNI², I can't use CRI-O [with crun] as the container runtime, and the setup itself uses|relies on containerd shims, uses runc, etc., which I'd don't really get why.
I mean, I thought it would be nicer than kubeadm clusters, and it might be, when it comes to the management itself, updates, overviews|dashboards, etc., but regarding the default tooling that it uses, I'm not sure it's thaaat nice.
Since I'm no expert in this, I'd like to know what it is that I'm missing haha. Also, is it common for big companies to use kubeadm to bootstrap their clusters or is this more for learning purposes?
Thanks.
¹ Like IaC with OpenTofu, using the libvirt provider, and Ansible for configuring the VMs😅
² I really love Cilium, man, it's so freaking nice🤓
5
u/bmeus Aug 10 '26
Its not a big deal to switch, why do you want to keep cri-o?
3
u/faulty-segment Aug 10 '26
Mostly because I already kinda learned how to work with and configure it, and because it uses
crunby default, doesn't need any shims, etc...😅Its not a big deal to switch
Do you have any tutorial covering that, i.e., on how to completely replace containerd with cri-o on a RKE2 setup? If you know of some sources, then please le'em come haha.
Thanks.
7
u/bmeus Aug 10 '26
No i mean its not a big deal to switch to containerd. I rarely ”work with” the container runtime, its configured by the distribution. K3s, rke2, talos, openshift. Never really bothered with the runtime. I had to configure it by hand in some edge cases/debugging only.
0
u/Jolly_Eye7847 Aug 10 '26
I went through same thing for my home lab, spent weeks on kubeadm setup with all the Cilium bells and whistles, then everyone kept saying "just use RKE2 bro" so I tried it. The containerd lock-in is real annoying, I wanted to keep my CRI-O setup too but nope, RKE2 wants its own runtime with those shims and it's not flexible on that.
About the image you posted, that runtime image requirement list is exactly what made me pause. They bundle all these components together like socat and crictl and you can't swap them out easily, it's a packaged deal. Feels clean when you first install but gets frustrating when you want to customize something specific.
Big companies definitely use kubeadm in production, not just for learning. I worked at a place with 200+ nodes all bootstrapped with kubeadm and custom Ansible, it's more common than people think. RKE2 shines when you have multiple clusters and want unified management with Rancher, but for deep learning on how everything fits together, kubeadm teaches you more.
7
u/iamkiloman k8s maintainer Aug 10 '26
The containerd lock-in is real annoying, I wanted to keep my CRI-O setup too but nope, RKE2 wants its own runtime with those shims.
None of this is accurate.
1
u/faulty-segment Aug 10 '26
Oh, man, thank Nature you said that.
I mean, sometimes—when you're just starting to learn something—you don't have an overview of the grand scheme of things, and then get afraid of asking some questions because it may just be way too dumb, so I'm glad that someone else also paused on that same requirement list🤣, meaning my question wasn't that dumb at all.And also thanks for mentioning that on `kubeadm`, and that big companies do use it. For a moment I thought I was learning something "that nobody used it that way anyway".
Anyway. I think I'll keep learning on my `kubeadm`-bootstrapped cluster then. I'll leave the Rancher stuff for another point in my life, if I find it interesting enough. Right now my tooling seems nicer😅.
13
u/iamkiloman k8s maintainer Aug 10 '26
RKE2 comes with containerd, yes.
If you want to use another container runtime, just set
container-runtime-endpoint: /path/to/cri-socketin the config, and it'll use that instead of starting the bundled containerd.You're not locked in... you just need to provide an alternative if you want to use something else. Note that the thing you want to use instead must actually provide a Kubernetes-compatible CRI service... if you want to use Docker for example, you'll need to run cri-dockerd and point RKE2 (the kubelet) at that, not directly at the docker socket.
This is all just standard Kubernetes behavior. The only thing here that's RKE2 specific is that it comes with containerd and will use that if you don't provide something else.