Accessing clusters

After your IBM Cloud® Kubernetes Service cluster is created, you can connect to it using several methods depending on your cluster type, network configuration, and use case. If you're not sure which method applies to you, start by identifying your cluster's infrastructure type and whether it has a public service endpoint (see Choosing an access method below).

Before you begin

  1. Install the required CLI tools, including the IBM Cloud CLI, Kubernetes Service plug-in (ibmcloud ks), and Kubernetes CLI (kubectl). For quick access to test features in your cluster, you can also use IBM Cloud Shell.
  2. If you haven't created a cluster yet, create one now. Otherwise, proceed to the next step.
  3. If your network is protected by a company firewall, allow access to the IBM Cloud and IBM Cloud Kubernetes Service API endpoints and ports.
  4. Check that your cluster is in a healthy state by running ibmcloud ks cluster get -c <cluster_name_or_ID>. If your cluster is not in a healthy state, review the Debugging clusters guide for help.

Choosing an access method

The right access method depends on your cluster infrastructure type, whether your cluster has a public or private service endpoint, and your network connectivity.

Not sure which type you have? In the IBM Cloud console, go to Kubernetes → Clusters, click your cluster, and check the Infrastructure field on the Overview tab — it shows VPC, Classic, or Satellite. To check whether your cluster has a public or private service endpoint, look at the Public Service Endpoint URL and Private Service Endpoint URL fields on the same page, or run ibmcloud ks cluster get -c <cluster_name_or_ID> and check those fields in the output.

Cluster access methods
Access method Cluster type Use when
Public cloud service endpoint Classic, VPC Your cluster has a public endpoint and you are connecting from outside the IBM Cloud network
Private cloud service endpoint — VPC VPC Your cluster is private-only and you are connected to the VPC network through a VPN or Direct Link connection
Private cloud service endpoint — Classic Classic Your cluster is private-only and you are connected to the classic private network
Virtual Private Endpoint (VPE) gateway VPC Your VPC cluster uses VPE for private master connectivity
API key or service ID All Automated pipelines and non-interactive scripts
Accessing private clusters by using the WireGuard VPN Classic, VPC You want to access a private-only cluster from outside IBM Cloud using a WireGuard VPN
Admission controller webhooks All You need to allow cluster access for admission controller webhooks