> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to create and modify Managed Service for Kubernetes® clusters

Managed Service for Kubernetes clusters manage and run containerized applications, providing automatic scaling, load balancing and streamlined deployment and management. In this guide, you will learn how to create, modify and delete clusters in Managed Service for Kubernetes.

For more information on managing node groups and adding them to clusters, see [Creating and modifying Managed Service for Kubernetes® node groups](/kubernetes/node-groups/manage).

## How to create clusters

<Tabs group="interfaces">
  <Tab title="Web console">
    1. In the sidebar, go to <Icon icon="https://mintcdn.com/nebius-ai-cloud/rOlLZ_MFvrheaI-h/_assets/sidebar/compute.svg?fit=max&auto=format&n=rOlLZ_MFvrheaI-h&q=85&s=8d3eda9b92f5a626a81d01268852f482" width="16" height="16" data-path="_assets/sidebar/compute.svg" /> **Compute** → **Kubernetes**.

    2. Click <Icon icon="https://mintcdn.com/nebius-ai-cloud/1Ha0sWR6e1mnIaHS/_assets/plus.svg?fit=max&auto=format&n=1Ha0sWR6e1mnIaHS&q=85&s=7c9efc69d65fc58db0eb73702fd81aa1" width="16" height="16" data-path="_assets/plus.svg" /> **Create cluster**.

    3. On the **Cluster** step, configure the cluster:

       1. In the **General** section:

          * Enter the cluster name.
          * (Optional) Enter labels in the `key:value` format.

       2. In the **Network** section, review the network and subnet. They are selected by default.

       3. In the **Control plane** section:

          * The Kubernetes version is set by default. For supported versions, see [Kubernetes® versions in Managed Service for Kubernetes](/kubernetes/versions).
          * A public endpoint is allocated by default. As a result, the cluster is available from the internet, you can connect to it from any machine. If you want to prevent access to the cluster from the internet, disable the public endpoint option. Then, you can connect to the cluster only from a virtual machine (VM) located in the same subnet as the cluster.

                <Tip>
                  To only allow certain addresses to connect to the cluster, enable the public endpoint and [configure an allowlist of IP addresses](/kubernetes/networking/limit-access-to-public-endpoint) for the cluster.
                </Tip>

       4. (Optional) In the **Observability** section, enable **Audit logs** to record metadata about operations that modify the cluster. For details, see [Logs in Managed Service for Kubernetes](/kubernetes/logs).

       5. Click **Next**.

    4. On the **Node groups** step, optionally configure one or more node groups.

       You can create a cluster without node groups and add them later. For more information, see [Creating and modifying Managed Service for Kubernetes® node groups](/kubernetes/node-groups/manage).

       To add a node group during cluster creation:

       1. Click **Add node group**.

       2. Configure the node group. If you have [capacity block groups](/overview/limits/capacity-block-groups), the **Reservations** step is also shown between **General** and **Compute resources**.

          1. On the **General** step:

             * Enter the node group name.

             * (Optional) Enable **Assign public IPv4 addresses** if you want the nodes to be accessible from the internet.

             * Under **Size**:

               * (Optional) Enable **Autoscaling** if you want to let the node group scale up or down depending on the workload.
               * Specify the initial **Number of nodes**.

             * Under **Advanced**:

               * **Auto-repair** is enabled by default. When enabled, Managed Kubernetes automatically replaces unhealthy nodes.
               * (Optional) Specify **Max pods per node** to limit how many Pods can run on each node in the group.

          2. If the **Reservations** step is shown, select **Reservation usage**:

             * **With reservations**: Resources are allocated from reservations ([capacity block groups](/overview/limits/capacity-block-groups)). This ensures that resources are always available, even if VMs in the node group are stopped (for example, by you or a [maintenance event](/kubernetes/maintenance/index)).

               In the **Reservation** section, you can configure the following options:

               * **Any (existing and future)** (default): Compute selects among your matching capacity block groups automatically.
               * **Specific capacity block groups**: Select one or more capacity block groups. Each option shows the capacity block group ID, reservation period and GPU usage. Make sure the selected groups have enough capacity and do not expire soon.
               * **Switch to PAYG**: Choose whether the VM can start after you create or restart it without active intervals in selected capacity block groups:

                 * **When reservation is exhausted** (default): The VM can start as a pay-as-you-go VM when no capacity is available in the selected capacity block groups.
                 * **Never**: The VM cannot start without available capacity in the selected capacity block groups.

                 This does not affect the VM when it is running. If an interval in a selected capacity block group expires while the VM is running, the VM always continues as a pay-as-you-go VM, regardless of this setting.

               If you have capacity block groups in multiple regions, select a **Region** first.

             * **Without reservations**: Resources are allocated from a common pool, and no reservations are used for the node group.

          3. On the **Compute resources** step:

             * Select whether the node group should have GPUs.

             * Select a regular or preemptible VM type.

               VMs without GPUs only support the regular type. For information about preemptible node groups, see [Creating and modifying Managed Service for Kubernetes® node groups — Preemptible node groups](/kubernetes/node-groups/manage#preemptible-node-groups).

             * If you create the node group with reservations, specify a **Reservation ID**.

             * Select an available [platform and preset](/compute/virtual-machines/types) (a combination of GPUs, vCPUs and RAM) that fits your workload requirements.

             * (Optional) If you create a node group with 8 GPUs (for example, for training models), use a GPU cluster for the node group. InfiniBand™ in the cluster allows you to accelerate tasks that require high-performance computing (HPC) power. To use a GPU cluster, select an existing one or click <Icon icon="https://mintcdn.com/nebius-ai-cloud/1Ha0sWR6e1mnIaHS/_assets/plus.svg?fit=max&auto=format&n=1Ha0sWR6e1mnIaHS&q=85&s=7c9efc69d65fc58db0eb73702fd81aa1" width="16" height="16" data-path="_assets/plus.svg" /> **Create** in the **GPU cluster** field and specify the cluster name and InfiniBand fabric. To select the fabric, see [InfiniBand fabrics](/compute/clusters/gpu#infiniband-fabrics).

             * (Optional) Enable or disable **GPU settings**. They are enabled by default, and they allow Managed Kubernetes to pre-install NVIDIA drivers and the [Container Toolkit](https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/index.html). You can also select a specific NVIDIA CUDA driver version.

             * Select an operating system for the nodes (for example, `Ubuntu 24.04 LTS`).

          4. On the **Storage** step, select the disk type and specify the size in GiB. Supported [disk types](/compute/storage/types#disk-types) are **SSD**, **SSD NRD** and **SSD IO**.

             (Optional) To attach a shared filesystem, click <Icon icon="https://mintcdn.com/nebius-ai-cloud/1Ha0sWR6e1mnIaHS/_assets/plus.svg?fit=max&auto=format&n=1Ha0sWR6e1mnIaHS&q=85&s=7c9efc69d65fc58db0eb73702fd81aa1" width="16" height="16" data-path="_assets/plus.svg" /> **Attach shared filesystem**, select an existing filesystem or create a new one, and specify a mount tag.

          5. On the **Additional** step:

             * (Optional) In the **Username and SSH key** field, add credentials, so you can [connect to the node group](/compute/virtual-machines/connect):

               1. Generate an [SSH key pair](/compute/virtual-machines/ssh-keys).
               2. In the **Username and SSH key** field, select an existing key or click <Icon icon="https://mintcdn.com/nebius-ai-cloud/1Ha0sWR6e1mnIaHS/_assets/plus.svg?fit=max&auto=format&n=1Ha0sWR6e1mnIaHS&q=85&s=7c9efc69d65fc58db0eb73702fd81aa1" width="16" height="16" data-path="_assets/plus.svg" /> **Create** to add a new one.

             * (Optional) Select or create a [service account](/iam/overview) that will perform actions on behalf of the nodes.

       3. To add another node group with a different configuration, click **Add node group**.

       4. To remove a node group, click <Icon icon="https://mintcdn.com/nebius-ai-cloud/1Ha0sWR6e1mnIaHS/_assets/button-vellipsis.svg?fit=max&auto=format&n=1Ha0sWR6e1mnIaHS&q=85&s=e80b8e57c43bfd117679262e6a1334ad" width="12" height="24" data-path="_assets/button-vellipsis.svg" /> → <Icon icon="https://mintcdn.com/nebius-ai-cloud/1Ha0sWR6e1mnIaHS/_assets/trash-bin.svg?fit=max&auto=format&n=1Ha0sWR6e1mnIaHS&q=85&s=b9b80db3d011e608480c36552df703a0" width="16" height="16" data-path="_assets/trash-bin.svg" /> **Delete** next to its name.

       5. Click **Next**.

    5. (Optional) On the **Applications** step, select applications to deploy to the cluster. Each application requires at least one node group. For more information, see [Deploying and deleting applications for Managed Service for Kubernetes®](/kubernetes/manage-applications).

       1. Click **Next**.

    6. On the **Review** step, check the cluster configuration and click **Create cluster**.
  </Tab>

  <Tab title="CLI">
    1. [Install and configure](/cli/install) the Nebius AI Cloud CLI.
    2. Create a cluster:

       ```bash theme={null}
       nebius mk8s cluster create \
         --name <cluster_name> \
         --labels <key1=value1,key2=value2,...> \
         --control-plane-endpoints-public-endpoint=<true|false> \
         --control-plane-endpoints-public-endpoint-allowed-cidrs <allowed_CIDR_blocks> \
         --control-plane-version 1.35 \
         --control-plane-subnet-id <subnet_ID> \
         --control-plane-etcd-cluster-size <number_of_etcd_stores>
       ```

       The command contains the following parameters:

       * `--name`: The cluster name.

       * `--labels`: Labels in the `key=value` format.

       - `--control-plane-endpoints-public-endpoint`: Enables a public endpoint. As a result, the cluster is available from the internet, one can connect to it from any machine.

         If you want to disable access to the cluster from the internet, set the parameter to `false`. Then, one can connect to the cluster only from a virtual machine located in the same subnet with the cluster.

       - `--control-plane-endpoints-public-endpoint-allowed-cidrs` (optional): Allowed CIDR blocks for the public endpoint. Only the IP addresses of these CIDR blocks are allowed to connect to the cluster.

         Specify the CIDR blocks in the IPv4 format with bits for hosts equal to zero. For example, `192.168.0.0/24` or `8.8.8.64/26`.

         Pass over each CIDR block as a separate `--control-plane-endpoints-public-endpoint-allowed-cidrs` parameter.

         For more information, see [Access restriction for a public endpoint of a Managed Service for Kubernetes® cluster](/kubernetes/networking/limit-access-to-public-endpoint).

       * `--control-plane-version`: The Kubernetes version. The default and recommended version is 1.35. For supported versions, see [Kubernetes® versions in Managed Service for Kubernetes](/kubernetes/versions).
       * `--control-plane-subnet-id`: The [subnet ID](/vpc/networking/resources#how-to-get-a-subnet-id).
       * `--control-plane-etcd-cluster-size`: Number or [etcd stores](/kubernetes/components#etcd). If you do not specify the number, the cluster is created with three etcd stores. This ensures high availability and makes the cluster more reliable; data stored in etcd is accessible even in case of failures.

         You can specify a lower number. However, the enabled high availability does not affect the cost of the cluster.
  </Tab>

  <Tab title="Terraform">
    1. [Install and configure](/terraform-provider/install) the Nebius AI Cloud provider for Terraform.

    2. Create the following configuration file:

       ```hcl theme={null}
       resource "nebius_mk8s_v1_cluster" "<cluster_name>" {
         name = "<cluster_name>"
         parent_id = "<project_ID>"
         labels = {
           <key1> = "<value1>"
           <key2> = "<value2>"
           ...
           <keyN> = "<valueN>"
         }
         control_plane = {
           endpoints = {
             public_endpoint = {}
           }
           version           = "1.35"
           subnet_id         = "<subnet_ID>"
           etcd_cluster_size = <number_of_etcd_stores>
         }
       }
       ```

       The file contains the following parameters:

       * `name`: The cluster name.
       * `parent_id`: [Project ID](/iam/manage-projects#terraform-3).
       * `labels`: Labels in the `key=value` format.
       * `control_plane`: Settings of the cluster's [control plane](/kubernetes/components#control-plane-components):

         * `endpoints.public_endpoint`: Its value `{}` enables a public endpoint. As a result, the cluster is available from the internet, you can connect to it from any machine.

           If you want to limit access to the cluster, delete the parameter. Then, one can connect to the cluster only from a virtual machine located in the same subnet with the cluster.
         * `version`: The Kubernetes version. The default and recommended version is 1.35. For supported versions, see [Kubernetes® versions in Managed Service for Kubernetes](/kubernetes/versions).
         * `subnet-id`: The [subnet ID](/vpc/networking/resources#how-to-get-a-subnet-id).
         * `etcd_cluster_size`: Number or [etcd stores](/kubernetes/components#etcd). If you do not specify the number, the cluster is created with three etcd stores. This ensures high availability and makes the cluster more reliable; data stored in etcd is accessible even in case of failures.

           You can specify a lower number. However, the enabled high availability does not affect the cost of the cluster.

    3. Check that the configuration is correct:
       ```bash theme={null}
       terraform validate
       ```

    4. Apply the changes:
       ```bash theme={null}
       terraform apply
       ```
  </Tab>
</Tabs>

## How to modify clusters

<Tabs group="interfaces">
  <Tab title="CLI">
    1. Get the ID of the cluster via its name:

       ```bash theme={null}
       export K8S_CLUSTER_ID=$(nebius mk8s cluster get-by-name \
         --name <cluster_name> --format jsonpath='{.metadata.id}')
       ```

       Alternatively, you can use the listing command: <code>nebius mk8s cluster list</code>.

    2. Update the cluster settings:

       ```bash theme={null}
       nebius mk8s cluster update \
         --id $K8S_CLUSTER_ID \
         --labels <key1=value1,key2=value2,...> \
         --control-plane-endpoints-public-endpoint=<true|false> \
         --control-plane-endpoints-public-endpoint-allowed-cidrs <allowed_CIDR_blocks> \
         --control-plane-etcd-cluster-size <number_of_etcd_stores>
       ```

       The command contains the following parameters:

       * `--labels`: Labels in the `key=value` format.

       - `--control-plane-endpoints-public-endpoint`: Enables a public endpoint. As a result, the cluster is available from the internet, one can connect to it from any machine.

         If you want to disable access to the cluster from the internet, set the parameter to `false`. Then, one can connect to the cluster only from a virtual machine located in the same subnet with the cluster.

       - `--control-plane-endpoints-public-endpoint-allowed-cidrs` (optional): Allowed CIDR blocks for the public endpoint. Only the IP addresses of these CIDR blocks are allowed to connect to the cluster.

         Specify the CIDR blocks in the IPv4 format with bits for hosts equal to zero. For example, `192.168.0.0/24` or `8.8.8.64/26`.

         Pass over each CIDR block as a separate `--control-plane-endpoints-public-endpoint-allowed-cidrs` parameter.

         For more information, see [Access restriction for a public endpoint of a Managed Service for Kubernetes® cluster](/kubernetes/networking/limit-access-to-public-endpoint).

       * `--control-plane-etcd-cluster-size`: Number or [etcd stores](/kubernetes/components#etcd). Three of them ensure high availability of the cluster.

       Only the parameters from the command above can be changed. To perform a full cluster update, add `--full` to the command. This will update all parameters with the default values or the values specified in the `--full` command.
  </Tab>

  <Tab title="Terraform">
    1. Modify the manifest with the deployed infrastructure:

       ```hcl theme={null}
       resource "nebius_mk8s_v1_cluster" "<cluster_name>" {
         name = "<cluster_name>"
         labels = {
           <key1> = "<value1>"
           <key2> = "<value2>"
           ...
           <keyN> = "<valueN>"
         }
         control_plane = {
           endpoints = {
             public_endpoint = {}
           }
           etcd_cluster_size = <number_of_etcd_stores>
         }
       }
       ```

       You can change the following parameters:

       * `name`: The cluster name.
       * `labels`: Labels in the `key=value` format.
       * `control_plane`: Settings of the cluster's [control plane](/kubernetes/components#control-plane-components):

         * `endpoints.public_endpoint`: Its value `{}` enables a public endpoint. As a result, the cluster is available from the internet, you can connect to it from any machine.

           If you want to limit access to the cluster, delete the parameter. Then, one can connect to the cluster only from a virtual machine located in the same subnet with the cluster.
         * `etcd_cluster_size`: Number or [etcd stores](/kubernetes/components#etcd). If you do not specify the number, the cluster is created with three etcd stores. This ensures high availability and makes the cluster more reliable; data stored in etcd is accessible even in case of failures.

           You can specify a lower number. However, the enabled high availability does not affect the cost of the cluster.

    2. Check that the configuration is correct:
       ```bash theme={null}
       terraform validate
       ```

    3. Apply the changes:
       ```bash theme={null}
       terraform apply
       ```
  </Tab>
</Tabs>

## How to delete clusters

<Tabs group="interfaces">
  <Tab title="CLI">
    Get the cluster ID as shown in [How to modify clusters](#how-to-modify-clusters) and delete the cluster:

    ```bash theme={null}
    nebius mk8s cluster delete --id $K8S_CLUSTER_ID
    ```
  </Tab>

  <Tab title="Terraform">
    1. If you manage node groups in the cluster with Terraform, first [delete the node groups](/kubernetes/node-groups/manage#how-to-delete-node-groups).
    2. Remove the corresponding `nebius_mk8s_v1_cluster` resource from the configuration file.
    3. Check that the configuration is correct:
       ```bash theme={null}
       terraform validate
       ```
    4. Apply the changes:
       ```bash theme={null}
       terraform apply
       ```
  </Tab>
</Tabs>

## Examples

Creating a cluster with the Kubernetes version 1.35 and a public endpoint for the control plane:

```bash theme={null}
nebius mk8s cluster create \
  --name cluster-example \
  --control-plane-version 1.35 \
  --control-plane-subnet-id \
    $(nebius vpc subnet list --format jsonpath='{.items[0].metadata.id}') \
  --control-plane-endpoints-public-endpoint=true
```
