Review parameters, recommended settings, and cloud resources for creating an ACK managed cluster in the console.
-
In the Modifiable column, ✓ = modifiable after creation; ✗ = not modifiable, plan carefully.
-
Cloud resource icons such as
ECS instance indicate that the configuration creates or uses other Alibaba Cloud resources. Click a resource name for billing details.
Cluster configuration
Define the cluster's global properties, including version and network configuration. Plan carefully — some options cannot be changed after creation.
Basic configuration
|
Parameter |
Description |
Modifiable |
|
Cluster Name |
Enter a custom name for the cluster. |
✓ |
|
Cluster Specification |
For comparison, see Cluster. |
✓ Only upgrades from Basic Edition to Pro Edition are supported. |
|
Region |
The region where the cluster resources, such as ECS instances and cloud disks, are located. The closer the region is to your users and resource deployment region, the lower the network latency. |
✗ |
|
Kubernetes Version |
You can only create clusters with the three most recent minor versions. We recommend using the latest version. For more information about the versions supported by ACK, see ACK version support overview. |
✓ Supports both manual cluster upgrades and automatic cluster upgrades. |
|
Automatic Update |
Enable automatic cluster upgrades to keep the cluster control plane and node pools periodically updated. For more information about the auto-upgrade policy and instructions, see Automatically upgrade clusters. |
✓ |
|
Maintenance Window |
ACK performs automated O&M tasks, such as automatic cluster upgrades and automatic OS CVE vulnerability fixes, only during the defined maintenance window. |
✓ |
The parameter order in the tables below may differ slightly from the console.
Network boundary and high availability
Configure the VPC, vSwitches, and security group to establish the cluster's network boundary, high availability, and security policies.
|
Parameter |
Description |
Modifiable |
|
VPC |
The virtual private cloud (VPC) for the cluster. For high availability, select two or more different zones.
We recommend using standard private CIDR blocks for the cluster VPC, such as 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. If you have special requirements, go to Quota Center to apply for permission to use a public CIDR block to create a cluster. Cloud resources and billing: |
✗ |
|
Security Group |
When using an existing VPC, you can choose to Select Existing Security Group This security group is applied to the cluster control plane, the default node pool, and any node pools that do not have a custom security group specified. Compared to basic security groups, advanced security groups can contain more private IP addresses but do not support intra-group connectivity. For more information, see Security group classification.
|
✓ |
Network model and Pod address planning
Configure the network plugin (CNI), which affects network performance, feature availability (like NetworkPolicy), and IP address management. Plan the address ranges for Pods and Services.
Plan CIDR blocks in advance. See Plan CIDR blocks for an ACK managed cluster.
|
Parameter |
Description |
Modifiable |
|
Network Plug-in |
The network plugin is the foundation for network communication between pods in a cluster. For a detailed comparison of the two plugins, see Comparison of Terway and Flannel.
|
✗ |
|
Container CIDR Block |
This parameter is required only for Flannel The address pool that assigns IP addresses to pods. This CIDR block cannot overlap with the VPC's CIDR block, the CIDR blocks used by existing ACK clusters in the VPC, or the Service CIDR. |
✗ |
|
Number of Pods per Node |
You only need to configure Flannel. Defines the maximum number of pods that a single node can accommodate. |
✗ |
|
Pod vSwitch |
This parameter is required only when you select Terway. The vSwitch that assigns IP addresses to pods. Each pod vSwitch corresponds to a worker node's vSwitch. The pod vSwitch and the worker node's vSwitch must be in the same zone. Important The subnet mask for the pod vSwitch should not exceed 19, and the maximum is 25. Otherwise, the number of available pod IP addresses in the cluster network will be very limited, which will affect the normal use of the cluster. |
✓ |
|
Service CIDR |
Also known as Service CIDR. This is the address pool that assigns IP addresses to services within the cluster. This CIDR block cannot overlap with the VPC's CIDR block, the CIDR blocks used by existing clusters in the VPC, or the Container CIDR Block. |
✗ |
|
IPv6 Dual-stack |
This feature is only available for Kubernetes 1.22 and later and only supports Terway. It cannot be used with the elastic Remote Direct Memory Access (eRDMA) feature The cluster supports both IPv4 and IPv6 protocols. However, communication between worker nodes and the control plane still uses IPv4 addresses. Make sure that:
|
✗ |
|
IPv6 Service CIDR Block |
Requires IPv6 Dual-Stack to be enabled Configure an IPv6 address range for the service CIDR block. You must use a Unique Local Address (ULA) (within the |
✗ |
|
Forwarding Mode |
Select the kube-proxy proxy mode, which determines how cluster services distribute requests to backend pods.
|
✗ |
Public network ingress and egress
Configure public ingress for cluster management (via the API server) and public egress for nodes and applications to access external resources such as public images.
|
Parameter |
Description |
Modifiable |
|
Configure SNAT for VPC |
Do not select this option when using a shared VPC Select this option if nodes need to access the public network (for example, to pull public images or access external services). ACK will automatically configure a NAT Gateway and SNAT rules to ensure that resources within the cluster can access the public network.
If you do not select this option, you can configure the NAT Gateway and SNAT rules yourself after creating the cluster. For more information, see Public NAT Gateway. Cloud resources and billing: |
✓ |
|
Access to API Server |
ACK automatically creates a pay-as-you-go private-facing Classic Load Balancer (CLB) instance as the internal endpoint for the API Server. This CLB instance cannot be reused or deleted. If deleted, the API Server will become inaccessible and cannot be recovered. To use an existing CLB instance, submit a ticket. After you select Use Existing Gateway for VPC, you can set SLB Source to Use Existing Gateway. You can choose to enable Expose API server with EIP.
To enable this later, see Access the API server over the internet. Starting from December 1, 2024, new CLB instances will incur an instance fee. For more information, see Billing item adjustment for Classic Load Balancer (CLB). |
✗ |
Advanced configuration
Expand Advanced Options (Optional) to configure cluster deletion protection, resource groups, and other settings.
|
Parameter |
Description |
Modifiable |
|
Cluster Deletion Protection |
We recommend enabling this feature to prevent accidental deletion of the cluster through the console or OpenAPI. |
✓ |
|
Resource Group |
Assign the cluster to the selected resource group for easier permission management and cost allocation. A resource can belong to only one resource group. |
✓ |
|
Label |
Bind key-value tags to the cluster to identify cloud resources. |
✓ |
|
Time Zone |
The time zone used by the cluster. By default, this is the time zone configured in your browser. |
✓ |
|
Cluster local domain |
The top-level domain (standard suffix) used by services within the cluster. The default is For example, a service named my-service in the default namespace has the DNS name |
✗ |
|
Custom Certificate SANs |
The Subject Alternative Name (SAN) field in the API Server certificate includes the cluster-local domain name, private IP address, and public EIP by default. To access the cluster through a proxy server, custom domain, or special network environment, add these access addresses to the SAN field. To enable this later, see Customize the SAN of the cluster API Server certificate. |
✓ |
|
Service Account Token Volume Projection |
In the traditional model, a pod's identity credentials are permanent and shared among multiple pods, which poses a security risk. When enabled, each pod gets its own temporary identity credentials, which support automatic expiration and permission restrictions. To enable this later, see Use ServiceAccount token volume projection. |
✗ |
|
Secret Encryption |
This feature is available only for Pro Edition clusters Use a key created in Alibaba Cloud KMS to provide professional-grade encryption for Secret keys, enhancing data security. To enable this later, see Use Alibaba Cloud KMS to encrypt Secrets at rest. Cloud resources and billing: |
✓ |
|
RRSA OIDC |
The cluster will create an OpenID Connect (OIDC) Provider. Using the temporary OIDC token of its ServiceAccount, application pods can call the Alibaba Cloud RAM service and assume a specified RAM role. This allows them to securely obtain temporary authorization to access cloud resources, achieving pod-level least-privilege management. To enable this later, see Use RRSA to configure RAM permissions for a ServiceAccount and achieve pod-level permission isolation. |
✗ |
Node pool configuration
A node pool is a group of identically configured ECS instances for running workloads. Some parameters are immutable after creation, but you can create additional node pools with different configurations.
You can skip this step. After creation, create more node pools with different configurations, such as operating systems, CPU architectures, billing methods, or instance types. See Create and manage a node pool. You can also add existing ECS instances to the cluster. See Add existing nodes.
Basic configuration
Configure basic information and automated O&M features for the node pool. Enable automated O&M in production to reduce operational overhead and improve stability.
|
Parameter |
Description |
Modifiable |
|
|
Node Pool Name |
Enter a custom name for the node pool. |
✓ |
|
|
Container Runtime |
For information on how to choose, see Comparison of containerd, sandboxed containers, and Docker runtimes.
|
✗ |
|
|
Managed node pool configuration |
Managed Node Pool |
Enable managed node pools to use the automated O&M capabilities provided by ACK. If your business is sensitive to changes in underlying nodes and cannot tolerate node restarts or application pod migrations, we do not recommend enabling this feature. To enable this later, you can edit the node pool to enable it. |
✓ |
|
Auto Repair |
ACK automatically monitors node status and performs self-recovery tasks when a node becomes abnormal. If you select Restart Faulty Node, the self-recovery process may involve operations such as draining the node and replacing disks. For information on trigger conditions and related events, see Enable node self-recovery. |
✓ |
|
|
Auto CVE Patching |
Fix OS CVE vulnerabilities in the node pool. You can configure the security vulnerability fix level. Cloud resources and billing: |
✓ |
|
|
Maintenance Window |
ACK performs automated O&M operations on managed node pools only during the defined maintenance window. |
✓ |
|
Instance and image configuration
Configure ECS instance types and operating system for nodes based on performance and cost requirements.
|
Parameter |
Description |
Modifiable |
|
|
Billing Method |
The default billing method for nodes scaled out by the node pool.
To ensure node pool uniformity, you cannot change a Pay-As-You-Go or Subscription node pool to a Preemptible Instance node pool, or vice versa. |
✓ |
|
|
Instance-related configuration items |
When a node pool scales out, it allocates instances from the configured ECS instance family. To improve the success rate of scale-outs, select multiple instance types across multiple zones to avoid unavailability or stock shortages. The specific instance type for scale-out is determined by the configured Scaling Policy. To ensure business stability and accurate resource scheduling, do not mix GPU and non-GPU instance types in the same node pool. You can configure the instance types used for scale-out in the following two ways:
You can refer to the elasticity strength recommendations in the console or view the node pool elasticity strength after the node pool is created. For information about unsupported instance types and node configuration recommendations, see ECS instance type configuration recommendations. Cloud resources and billing: |
✓ |
|
|
Operating System |
Marketplace Image is in phased release. The default OS image used when the node pool scales out nodes.
To upgrade or change the OS later, see Change the operating system. Alibaba Cloud Linux 2 and CentOS 7 are no longer maintained and are not supported in clusters of version 1.30 or later. Use a supported operating system. We recommend Alibaba Cloud Linux 3 Container-Optimized Edition or ContainerOS. |
✓ |
|
|
Security Hardening |
When creating a node, ACK applies the selected security baseline policy.
|
✗ |
|
|
Logon Type |
When you select MLPS Security Hardening, only Password is supported. ContainerOS only supports Key Pair or Later. If you want to use a key pair, you must start an administrative container after configuring the key pair. For specific operations, see O&M for ContainerOS nodes. When creating a node, ACK pre-installs the specified key pair or password into the instance.
|
✓ |
|
Storage configuration
Configure storage for nodes: the system disk for the operating system and data disks for container runtime data.
|
Parameter |
Description |
Modifiable |
|
|
System Disk |
Select a cloud disk type based on your business needs, including ESSD AutoPL, enterprise SSD (ESSD), ESSD Entry, and previous-generation cloud disks (standard SSD and ultra disk). Configure the capacity and IOPS. The available system disk types depend on the selected instance family. Disk types that are not displayed are not supported. You can select More Disk Categories to configure disk types different from the System Disk to improve the success rate of scale-outs. When creating a node, ACK selects the first matching type in the specified order of disk types. Cloud resources and billing: |
✓ |
|
|
Data Disk |
Select a cloud disk type based on your business needs, including ESSD AutoPL, enterprise SSD (ESSD), ESSD Entry, and previous-generation cloud disks (standard SSD and ultra disk). Configure the capacity and IOPS. The available data disk types depend on the selected instance family. Disk types that are not displayed are not supported.
You can select Add Data Disk Type to configure disk types different from the Data Disk to improve the success rate of scale-outs. When creating a node, ACK selects the first matching type in the specified order of disk types. An ECS instance can have up to 64 data disks attached. The specific limit varies by instance type. You can call the DescribeInstanceTypes operation to query the cloud disk quantity limit (Cloud resources and billing: |
✓ |
|
Instance quantity configuration
Set the initial number of nodes in the node pool.
|
Parameter |
Description |
Modifiable |
|
Expected Number of Nodes |
The total number of nodes that the node pool should maintain. We recommend configuring at least two nodes to ensure that cluster components run properly. You can adjust the desired node count to scale the node pool in or out. For more information, see Scale a node pool. If you do not need to create nodes, you can set this to 0 and then manually adjust it or add existing nodes later. |
✓ |
Advanced node pool configuration
Expand Advanced Options (Optional) to configure scaling policies, ECS tags, taints, and other settings.
|
Parameter |
Description |
Modifiable |
|
Scaling Policy |
Configure how the node pool selects instances during node scaling.
|
✓ |
|
Use Pay-as-you-go Instances When Spot Instances Are Insufficient |
This requires the billing method to be set to Spot Instance. When enabled, if not enough spot instances can be created due to price, inventory, or other reasons, ACK will automatically try to create on-demand instances as a supplement. Cloud resources and billing: |
✓ |
|
Enable Supplemental Spot Instance |
This requires the billing method to be set to Spot Instance. When enabled, upon receiving a system message that a spot instance is about to be reclaimed (5 minutes before reclamation), ACK will attempt to scale out a new instance as compensation.
The proactive release of spot instances can cause business disruptions. To improve the compensation success rate, we recommend also enabling Use Pay-as-you-go Instances When Spot Instances Are Insufficient. Cloud resources and billing: |
✓ |
|
ECS Tags |
Add tags to the ECS instances automatically created by ACK to identify cloud resources. Each ECS instance can be bound with up to 20 tags. To increase this limit, submit a request on the Quota Center platform. Because ACK and Auto Scaling (ESS) occupy some tags, you can specify up to 17 custom tags for an instance. |
✓ |
|
Taints |
Add key-value taints to the node. A valid taint key consists of an optional prefix and a name. If a prefix is present, it is separated from the name by a forward slash (/). |
✓ |
|
Node Labels |
Add key-value labels to the node. A valid Key consists of an optional prefix and a name. If a prefix is present, the prefix and name are separated by a forward slash (/). |
✓ |
|
Set to Unschedulable |
Newly added nodes will be set as unschedulable by default when they are registered with the cluster. You need to manually adjust the node scheduling status in the node list. This configuration only takes effect for clusters of versions earlier than 1.34. For more information, see Kubernetes 1.34 version guide. |
✓ |
|
Container Image Acceleration |
This feature is only supported for containerd runtimes of version 1.6.34 and later. Newly added nodes will automatically detect if a container image supports on-demand loading. If it does, it will use on-demand loading by default to accelerate container startup, reducing application startup time. For more information, see Use on-demand loading of container images to accelerate container startup. |
✓ |
|
[Deprecated] CPU policy |
Specify the kubelet's CPU management policy for the node.
We recommend using custom kubelet configurations for node pools. We recommend that you use custom node pool kubelet configuration. |
✗ |
|
Custom Node Name |
By default, node names are automatically generated. If you need a unified naming convention for easier node management and O&M identification, you can enable this configuration. When enabled, the node name, ECS instance name, and hostname will all change. Method 3 is only applicable to Lingjun node pools, and Lingjun node pools only support Method 3. |
✗ |
|
Worker RAM Role |
Supported only for ACK managed clusters. Can only be specified when creating a new node pool Specify a Worker RAM role at the node pool level to reduce the security risks associated with all nodes sharing a single Worker RAM role.
|
✗ |
|
Instance Metadata Access Mode |
Only supported for clusters of version 1.28 and later Configure the metadata access mode for ECS instances. You can access the Metadata Service from within an ECS instance to retrieve instance metadata, including instance ID, VPC information, NIC information, and other instance attributes. For more information, see Instance metadata.
|
✗ |
|
Pre-defined Custom Data |
Before a node joins the cluster, the specified pre-customization User-Data script will be run. For example, if you specify the pre-customization data as For information on how this configuration takes effect during node initialization, see Node initialization process overview. |
✓ |
|
User Data |
After a node joins the cluster, the specified instance User-Data script will be run. For example, if you specify the instance user data as For information on how this configuration takes effect during node initialization, see Node initialization process overview. Successful cluster creation or node scale-out does not guarantee that the instance user data script executed successfully. You can log on to the node and run |
✓ |
|
CloudMonitor Agent |
You can view and monitor the running status of nodes and applications in the Cloud Monitor console. This configuration only applies to new nodes in the node pool, not existing ones. To enable it for existing nodes, install it through the Cloud Monitor console. Cloud resources and billing: |
✓ |
|
Public IP |
ACK will assign an IPv4 public IP address to the node. This configuration only applies to new nodes in the node pool, not existing ones. If existing nodes need to access the public network, you need to configure and bind an EIP. For more information, see Associate an EIP with a cloud resource. Cloud resources and billing: |
✓ |
|
Custom Security Group |
Specify a basic or advanced security group for the node pool. ACK does not configure additional access rules for the security group by default. You must manage the security group rules yourself to avoid access issues. For more information, see Configure cluster security groups. Each ECS instance has a limit on the number of security groups it can join. Ensure you have a sufficient security group quota. |
✗ |
|
RDS Whitelist |
Add the node IP addresses to the whitelist of an RDS instance. |
✓ |
|
Deployment Set |
After creating a deployment set in the ECS console, assign it to the node pool. This ensures that the nodes scaled out by the node pool are distributed across different physical servers, improving high availability. A deployment set supports a maximum of To enable this later, see Best practices for node pool deployment sets. |
✓ |
|
Resource Pool Policy |
The resource pool policy used when adding new nodes (only supported when Instance Configuration Mode is set to Specify Instance Type). Resource pools include private pools generated after Elastic Assurance or Capacity Reservation (Immediate or Timed) services take effect, along with public pools, for node startup selection.
|
✓ |
|
[Deprecated] Private Pool Type |
This configuration item is deprecated. Switch to using Resource Pool Policy to specify a private pool. The private pool resources available for the currently selected zone and instance type. Types include the following:
|
✓ |
Component configuration
ACK installs recommended components by default. After creation, you can install, uninstall, or upgrade components. See Manage components.
Basic configuration
|
Parameter |
Description |
||||||
|
Ingress |
Ingress manages how external traffic accesses services within the cluster. It needs to be installed if you want to expose applications or APIs in the cluster to the public network. Three types of instances are currently available to serve as the cluster's Ingress gateway.
For a detailed comparison of the three, see Ingress management. |
||||||
|
Service Discovery |
Install NodeLocal DNSCache to cache DNS query results on nodes. This improves domain name resolution performance and stability, and accelerates service-to-service calls within the cluster. |
||||||
|
Volume Plug-in |
Implements persistent data storage based on the CSI storage plugin. You can use Alibaba Cloud cloud disks, NAS, OSS, CPFS, and other persistent volume (PV) resources. If you choose to create NAS and CNFS by default, ACK will create a General-purpose NAS file system and manage it using Container Network File System (CNFS). To create CNFS later, see Manage NAS file systems with CNFS. Cloud resources and billing: |
||||||
|
Container Monitoring |
Monitor cluster health, resource usage, application performance, and more through the container cluster monitoring service, and trigger relevant alerts when anomalies occur.
To enable this later, see Connect to and configure Alibaba Cloud Prometheus monitoring. Cloud resources and billing: |
||||||
|
Cost Suite |
Provides cost and resource usage analysis for clusters, namespaces, node pools, and workloads to improve cluster resource utilization and save costs. To enable this later, see Cost Insight. |
||||||
|
Log Service |
Use an existing SLS Project or create a new one to collect cluster application logs. This will also enable the cluster API Server audit feature to collect requests to the Kubernetes API and their results. To enable this later, see Collect container logs from an ACK cluster and Use the cluster API Server audit feature.
Cloud resources and billing: |
||||||
|
Alerts |
Enable Container Service Alert Management. Based on SLS, Managed Service for Prometheus, and Cloud Monitor data sources, it sends alert notifications to alert contact groups when cluster anomalies occur. |
||||||
|
Control Plane Logs |
Collect control plane component logs into an SLS Project for in-depth troubleshooting and root cause analysis. To enable this later, see Collect control plane component logs for an ACK managed cluster. Cloud resources and billing: |
||||||
|
Cluster Inspections |
Enable the cluster inspection feature of artificial intelligence for IT operations to periodically scan cluster quotas, resource usage, component versions, and more. This ensures that the cluster configuration follows best practices and exposes potential risks in advance. |
Advanced configuration
Expand Advanced Options (Optional) to select additional components for application management, log monitoring, storage, networking, and security.