Skip to content

Kubernetes Migration Guides

Migration · Updated Jun 2026

Coming from another cloud?

▸AWS·Amazon EKS Cluster

Amazon EKS Clusterhigh

  • EKS control plane fully AWS-managed, single-tenant, across 3 AZs with auto scale/replace; on Quake AI you run the control plane on Nova instances, provisioned through Magnum or self-managed with OpenTofu, and you operate it.
  • EKS regional API endpoint with SLA; Quake AI exposes the kube API via Neutron LB with floating IP.
  • EKS charges a per-hour cluster platform fee on top of the underlying compute; Quake AI charges only for underlying Nova/Neutron/Cinder resources with no K8s platform fee.
  • EKS managed nodes auto AMI updates, Spot integration; Quake AI self-managed nodes require manual OS image selection and update management.
AWS docs ↗
▸Azure·AKS Cluster

AKS Clusterhigh

  • Azure automatically provisions and manages the control plane at no additional cost (Free tier) or fixed fee (Standard tier with SLA), offloading health monitoring and upgrades; on Quake AI you provision a cluster through Magnum (openstack coe cluster create) or self-managed Kubernetes on Nova instances (OpenTofu plus kubeadm, k3s, or RKE2), and you operate the cluster after creation.
  • No OpenStack integration; uses Azure Resource Manager for cluster lifecycle.
  • Pre-configured with Azure-specific defaults and add-ons like application routing.
  • Managed via Azure Virtual Machine Scale Sets (VMSS) with auto-scaling and upgrades; Quake AI uses Nova instances provisioned via OpenTofu with user-managed scaling and upgrades.
Azure docs ↗
▸DigitalOcean·Kubernetes

This Quake AI feature maps to DigitalOcean’s Kubernetes.

▸Google Cloud·GKE Cluster

GKE Clusterhigh

  • GKE provides Autopilot mode with fully managed node provisioning and scaling by Google; on Quake AI you provision clusters through Magnum or self-managed Kubernetes on Nova instances and manage node scaling yourself.
  • Control plane is fully managed with automatic upgrades through release channels; Quake AI requires user-provisioned and user-managed control plane nodes.
  • Cluster creation uses gcloud CLI vs OpenStack CLI (openstack coe cluster create).
  • Custom machine types, spot VMs, accelerators in node pools; Quake AI K8s nodes use standard Nova flavors.
Google Cloud docs ↗
▸Hetzner·Kubernetes

This Quake AI feature maps to Hetzner’s Kubernetes.

▸Linode·Kubernetes Engine (LKE) Cluster

Linode Kubernetes Engine (LKE) Clusterhigh

  • LKE provides a fully managed control plane (free Standard tier or paid Enterprise tier with HA and SLA); on Quake AI you provision the cluster through Magnum or self-managed Kubernetes on Nova instances (OpenTofu plus kubeadm, k3s, or RKE2) and operate it yourself.
  • LKE clusters are created and managed through the Linode API or Cloud Manager with a single cluster object. Quake AI offers Magnum as a managed-cluster API, or you can compose a cluster from compute instances, a private network, a CNI, and a self-managed control-plane endpoint.
  • LKE ships an integrated linode-cloud-controller-manager and linode-blockstorage CSI driver out of the box; on Quake AI you install openstack-cloud-controller-manager and the Cinder CSI driver yourself.
  • LKE node pools auto-recycle when you upgrade the Kubernetes version; Quake AI node lifecycle is managed by you (OpenTofu replace, manual drain, or cluster API operator).
Linode docs ↗
▸Vultr·Kubernetes Engine (VKE) Cluster

Vultr Kubernetes Engine (VKE) Clusterhigh

  • VKE provides a free managed control plane with optional HA upgrades; on Quake AI you provision the cluster through Magnum or self-managed Kubernetes on Nova instances (OpenTofu plus kubeadm, k3s, or RKE2) and operate it yourself.
  • VKE clusters are created and managed through the Vultr API or Customer Portal with a single cluster object. Quake AI offers Magnum as a managed-cluster API, or you can compose a cluster from compute instances, a private network, a CNI, and a self-managed control-plane endpoint.
  • VKE ships an integrated Vultr cloud controller manager and Vultr CSI driver for Block Storage out of the box; on Quake AI you install openstack-cloud-controller-manager and the Cinder CSI driver yourself.
  • VKE node pools auto-recycle when you upgrade the Kubernetes version; Quake AI node lifecycle is managed by you (OpenTofu replace, manual drain, or cluster API operator).
Vultr docs ↗

Kubernetes migration guides

Move your Kubernetes workloads to Quake AI from a managed Kubernetes provider or from a self-managed setup on another cloud. The core shift in most migrations is from a provider-operated control plane (EKS, GKE, AKS, DOKS) to one you operate yourself. On Quake AI you provision Kubernetes two ways: through Magnum, which builds a cluster from a curated template, or self-managed on Nova instances that you install and maintain. Coming from a self-managed source such as Kubernetes on Hetzner Cloud, you keep the self-managed model and move the underlying infrastructure to Nova instances. Either way, you gain control over the cluster, no provider lock-in on networking or storage drivers, and Quake AI's bandwidth-inclusive pricing.

Two paths to Kubernetes on Quake AI#

Quake AI provisions Kubernetes two ways. Both are supported; the right choice depends on how much control you need over the cluster's Kubernetes version, CNI, and CRI.

Magnum#

Magnum, the Container Infrastructure Management service, provisions a control plane and worker nodes from a curated cluster template (openstack coe cluster create). Platform templates ship pre-wired with Calico CNI, the OpenStack cloud-provider stack (CCM + Cinder CSI), and a load-balanced API endpoint, so a cluster is fast to stand up. You operate the cluster after creation: upgrades, node-pool sizing, and etcd backups. The Kubernetes version comes from the template catalog, so run openstack coe cluster template list to see the versions your region offers.

Self-managed on Nova instances#

Provision Nova VMs with OpenTofu, install Kubernetes using kubeadm, k3s, or RKE2, and add the OpenStack cloud-provider stack (CCM + Cinder CSI). This path gives you full control over the Kubernetes version, CNI, CRI, and upgrade cadence, which helps when you need to match a source cluster exactly or run a version outside the template catalog.

OpenTofu (openstack provider)
  -> Nova VMs (control plane x3 + worker nodes)
  -> Neutron private network
  -> stable endpoint for the K8s API
  -> kubeadm init / k3s install / rke2 install
  -> openstack-cloud-controller-manager
  -> Cinder CSI driver
  -> CNI (Calico / Cilium)

Choose your source provider#

What's portable and what's not#

Fully portable (no changes required)#

Deployments, StatefulSets, DaemonSets, ConfigMaps, Secrets (values), Namespaces, ServiceAccounts (minus cloud IAM annotations), all RBAC resources, NetworkPolicy, HPA, VPA, PodDisruptionBudget, CronJobs, and Jobs migrate without modification. Helm charts using standard Kubernetes resources deploy cleanly with updated values.

Portable with adaptation#

ResourceWhat changes
IngressingressClassName and provider-specific annotations must change
Service (LoadBalancer)Works through the cloud controller; remove provider-specific annotations
PersistentVolumeClaimstorageClassName must reference the Cinder StorageClass

Provider-specific (must be replaced)#

ComponentAll providersQuake AI replacement
Block storage CSI driverProvider-specific CSIcinder.csi.openstack.org (Cinder CSI)
Cloud controller managerProvider-specific CCMopenstack-cloud-controller-manager
Ingress controllerALB (EKS), GCLB (GKE), AGIC (AKS)ingress-nginx or Traefik with a LoadBalancer Service
Pod identity (IAM)IRSA (EKS), Workload ID (GKE/AKS)OpenStack app credentials in K8s Secrets
CNIVPC CNI (EKS), Azure CNI / Azure CNI Overlay (AKS), GKE Dataplane V2 (Cilium, default on Autopilot)Calico (VXLAN) or Cilium
Node autoscalerKarpenter (EKS standalone or EKS Auto Mode), AKS Node Auto-Provisioning (NAP), GKE NAP or managed Cluster AutoscalerCluster Autoscaler with OpenStack provider, or manual scaling
MonitoringCloudWatch, Cloud Operations, Azure MonitorPrometheus + Grafana + Loki (self-managed)
Secret storeAWS Secrets Manager, Azure Key Vault CSIK8s Secrets or HashiCorp Vault

Each provider guide documents additional provider-specific resources you must remove. Notable examples: GKE Config Connector CRDs (cnrm.cloud.google.com), the AKS Azure Policy pod, the AKS omsagent and ama-logs DaemonSets, and EKS Security Group Policies for Pods.

Operators and Helm charts that are fully portable#

cert-manager, external-dns, prometheus-operator (kube-prometheus-stack), Loki, Grafana, Velero, Istio, Linkerd, ArgoCD, Flux, ingress-nginx, Traefik, Metrics Server, and HashiCorp Vault all deploy on Quake AI without modification. Only configuration values (endpoints, credentials) change.

If you provision Kubernetes yourself on Nova instances, this stack is a solid starting point.

ComponentRecommendation
Infrastructure provisioningOpenTofu with openstack provider
K8s installerRKE2 (production) or k3s (lightweight)
Cloud controlleropenstack-cloud-controller-manager
Block storageCinder CSI (cinder.csi.openstack.org) with cinder-flash StorageClass
CNICalico (VXLAN) or Cilium
Ingressingress-nginx
TLS certificatescert-manager + Let's Encrypt
DNS managementexternal-dns (Cloudflare, NS1, or other provider)
Observabilitykube-prometheus-stack + Loki + Grafana
Backup and migrationVelero with Swift/S3 backend

Each migration guide documents both provisioning paths. Some lead with Magnum and others with the self-managed path, depending on the source platform and how closely you need to match its Kubernetes version and CNI. See Two paths to Kubernetes on Quake AI for the trade-offs.

Data migration with Velero#

Velero is the primary tool for migrating K8s resources and persistent volume data between clusters. It backs up all API objects to object storage and uses filesystem-level backup (via node-agent) to copy PVC data independent of the source CSI driver.

For cross-provider migration, use --default-volumes-to-fs-backup so PVC data is captured at the filesystem level instead of through cloud-native snapshots.

Velero supports StorageClass remapping at restore time via a ConfigMap, so it maps source StorageClass names (like gp2, do-block-storage, hcloud-volumes) to cinder-flash on Quake AI automatically.

Migration complexity by provider#

ProviderComplexityPrimary driversEstimated timeline
DigitalOcean DOKSLowMinimal lock-in, simple CSI/CCM swap1-2 weeks
Kubernetes on Hetzner CloudLow-MediumSimilar architecture, IaC rewrite1-2 weeks
AWS EKSMedium-HighIRSA, EBS data, ALB, VPC CNI, Fargate4-8 weeks
GCP GKEMedium-HighWorkload Identity, Config Connector, Autopilot3-6 weeks
Azure AKSHighEntra ID, Key Vault CSI, Azure CNI, AGIC6-12 weeks

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

Comparisons to third-party providers in this material reflect publicly documented behavior as of the validation date below. Pricing, quotas, service limits, and feature availability change frequently on every cloud. Verify provider-specific claims against the provider's own current documentation before relying on them for a procurement, architecture, or migration decision.

For the full policy, see Usage Guidelines.

Last validated: 22.06.2026

Quick answers

Was this page helpful?