Cheat Sheets / Bare Metal & Edge

Edge Kubernetes & Zero-Touch Provisioning cheat sheet

88 commands from every lesson of Edge Kubernetes & Zero-Touch Provisioning, on one page.

01 · Why ZTP for edge

The ZTP promise

Rack, cable, power onThe only hands-on work at the site
BMC/PXE → OS → Kubernetes → workloadsEverything else automated and remote
Site definition in GitHardware inventory + cluster spec + workloads

Lifecycle

Day 0Design, inventory, images, site definition
Day 1Provision: bare metal → cluster → apps
Day 2Upgrade, scale, repair, rebuild, retire

02 · Architecture for edge ZTP

Planes

Management plane (central)Git, registries, cluster lifecycle controllers, observability
Provisioning at the siteDHCP/TFTP/HTTP boot + BMC access: needs L2 or DHCP relay
Workload clusters (per site)Run the applications; pull config and images

Site networks

BMC / OOB VLANRedfish/IPMI; isolated, no internet
Provisioning VLANPXE/iPXE, DHCP; can be the node network
Node / cluster networkKubernetes API VIP, node IPs
Workload / uplinkServices, backhaul to the centre

03 · Cluster sizing for edge

Shapes

1 nodeNo HA; cheapest; a node failure = site outage
3 nodes, compact (CP + workloads on all)Tolerates 1 node failure; common edge default
3 CP + N workersMore isolation and capacity; more hardware
2 nodesNo etcd fault tolerance without an external witness

Settings

kubectl taint nodes <n> node-role.kubernetes.io/control-plane:NoSchedule-Allow workloads on control-plane nodes (compact)
kubelet: systemReserved / kubeReserved / evictionHardProtect the OS and kubelet from workloads
etcd quorum = floor(n/2) + 13 members → survives 1 failure

04 · Bare-metal provisioning

Redfish (curl)

curl -sku user:pass https://<bmc>/redfish/v1/SystemsList systems (IDs vary by vendor: 1, System.Embedded.1, …)
PATCH …/Systems/<id> {"Boot":{"BootSourceOverrideTarget":"Pxe","BootSourceOverrideEnabled":"Once"}}Boot from network once
POST …/Systems/<id>/Actions/ComputerSystem.Reset {"ResetType":"ForceRestart"}Power cycle
POST …/Managers/<id>/VirtualMedia/<cd>/Actions/VirtualMedia.InsertMedia {"Image":"http://…/boot.iso"}Mount an ISO remotely

IPMI & PXE

ipmitool -I lanplus -H <bmc> -U user -P pass chassis bootdev pxe options=efibootLegacy: boot from network (UEFI)
ipmitool -I lanplus -H <bmc> -U user -P pass power cycleLegacy: power cycle
DHCP option 93 (client arch) → ipxe.efi vs undionly.kpxeServe the right iPXE binary

05 · Tinkerbell & Metal3

Tinkerbell

SmeeDHCP, TFTP and iPXE scripts (formerly Boots)
HookOSIn-memory OS that runs workflow actions (formerly Hook)
Tink server/controller + workerWorkflow engine; workers run actions as containers
TootlesMetadata service for cloud-init (formerly Hegel)
RufioBMC control as Kubernetes resources (Machine, Job, Task)
kubectl get hardware,templates,workflows -AInspect provisioning state

Metal3

Bare Metal Operator + IronicManage hosts through BareMetalHost resources
kubectl get baremetalhosts -AStates: registering → inspecting → available → provisioning → provisioned
bmc.address: redfish-virtualmedia://<bmc>/redfish/v1/Systems/1BMC driver + address
CAPM3Cluster API provider for Metal3

06 · OS image creation

Formats

RAW (.raw.gz / .raw.xz)Streamed straight onto the disk (e.g. image2disk); bare metal
QCOW2VMs, and Ironic can convert/write it
ISOInstaller or live boot via virtual media/USB
qemu-img convert -f qcow2 -O raw in.qcow2 out.rawConvert between formats

Build & first boot

image-builder (kubernetes-sigs) / PackerReproducible node images with Kubernetes components
cloud-init NoCloud: user-data, meta-data, network-configFirst-boot configuration
Ignition (Flatcar, Fedora CoreOS)First-boot provisioning for those OSes
sha256sum image.raw.gz > image.raw.gz.sha256; cosign sign-blob …Checksum and sign images

07 · Air-gapped delivery

Moving artifacts

skopeo copy --all docker://registry.k8s.io/pause:3.10 docker://harbor.local/mirror/pause:3.10Copy an image (all architectures)
skopeo copy --all docker://… oci-archive:bundle/pause.tarImage to a file for transfer
helm pull oci://… --version X && helm push chart-X.tgz oci://harbor.local/chartsMirror a Helm chart
oras copy <src> <dst>Copy any OCI artifact (SBOMs, signatures, files)

Pointing nodes at mirrors

/etc/rancher/rke2/registries.yaml (mirrors + configs)RKE2/K3s mirror configuration
registryMirrorConfiguration (EKS Anywhere cluster spec)EKS-A mirror + CA
containerd: /etc/containerd/certs.d/<registry>/hosts.tomlPlain containerd mirror config

08 · EKS Anywhere on bare metal

Create

eksctl anywhere generate clusterconfig site042 --provider tinkerbell > site042.yamlStart a cluster spec
hardware.csv: hostname,bmc_ip,bmc_username,bmc_password,mac,ip_address,netmask,gateway,nameservers,labels,diskHardware inventory (labels like type=cp)
eksctl anywhere create cluster --hardware-csv hardware.csv -f site042.yamlProvision machines and form the cluster

Day 2

eksctl anywhere upgrade plan cluster -f site042.yamlSee available component upgrades
eksctl anywhere upgrade cluster -f site042.yamlUpgrade (Kubernetes version and components)
eksctl anywhere generate hardware -z hardware.csv > hardware.yamlHardware objects for adding machines later
kubectl get clusters.anywhere.eks.amazonaws.com,machines -ACluster and CAPI machine status

09 · Rancher + RKE2 provisioning

RKE2

curl -sfL https://get.rke2.io | sh - && systemctl enable --now rke2-serverInstall and start a server (online)
/etc/rancher/rke2/config.yamlNode configuration (token, tls-san, profile, server…)
server: https://<vip-or-first-server>:9345Join an existing cluster (supervisor port)
/etc/rancher/rke2/rke2.yaml + /var/lib/rancher/rke2/bin/kubectlAdmin kubeconfig and bundled kubectl
rke2 etcd-snapshot save --name pre-upgradeManual etcd snapshot

Rancher & Elemental

Cluster Management → Create → CustomRegister existing machines with a registration command
MachineRegistration / MachineInventory / SeedImage (Elemental)Onboard and manage edge OS + nodes
Fleet: GitRepo + cluster labelsGitOps across many clusters (built into Rancher)

10 · GitOps fleet management

Targeting

Cluster labels: site=042, size=s, region=eu, wave=canaryDescribe clusters; select by label
Fleet: GitRepo targets[].clusterSelectorRancher Fleet targeting
Argo CD: ApplicationSet cluster generator selectorArgo CD targeting
Flux: a Kustomization per cluster from its own pathFlux per-cluster entry point

Rollout

wave=lab → canary → early → allStaged rollout by label
Pin revisions per wave (tags/branches)Promote by moving a pointer
Fleet/Argo status per clusterWhich revision each site runs

11 · Edge networking, storage & security

Networking

kube-vip (ARP/BGP)API server VIP and/or Service LoadBalancer IPs
MetalLB (L2 or BGP)LoadBalancer Services on bare metal
Local DNS forwarder + NTP server (or GPS/PTP clock)Sites keep working offline
Multus + SR-IOV device pluginExtra, high-performance pod interfaces (telecom)

Storage & security

local-path / TopoLVM (LVM-backed local PVs)Single-node or node-local storage
Longhorn (3 nodes)Replicated block storage for small clusters
LUKS + TPM2 (e.g. systemd-cryptenroll / Clevis)Encrypted disks that unlock only on the original hardware
Secure Boot + measured bootOnly signed boot chains; tampering is detectable

12 · DR & compliance at scale

Backups

rke2 etcd-snapshot save / automatic snapshots (+ S3 upload)RKE2 etcd backups
etcdctl snapshot save (kubeadm-based clusters, e.g. EKS-A control plane)Generic etcd snapshot
velero backup create site042-daily --include-namespaces shopKubernetes objects + volume data

Compliance

kube-bench run --targets master,nodeCIS Kubernetes Benchmark checks
Policy engine reports (Kyverno/Gatekeeper)Continuous config compliance
Per-site inventory: OS image, K8s, bundle, firmware, Secure Boot, encryptionEvidence and drift detection