If your workloads run in an on-premises data center or a third-party public cloud Kubernetes cluster, you can use ACK One multi-cluster gateways to build a hybrid or cross-cloud disaster recovery system with automatic smooth failover. This topic explains how to quickly build a same-city active-active hybrid disaster recovery system with ACK One.
Architecture
Three core components: a Fleet instance (with optional GitOps), a cloud ACK cluster, and a registered cluster connected to your on-premises environment.
How the components connect:
-
All Alibaba Cloud resources share a single VPC. An ACK cluster runs in availability zone (AZ) 1; a registered cluster sits in AZ 2.
-
Your on-premises cluster (or third-party platform cluster) connects to the registered cluster via a leased line between the data center and the VPC.
-
Both clusters are associated with the Fleet instance. ACK One GitOps distributes the application to both.
-
On the Fleet instance, an AlbConfig creates an ALB multi-cluster gateway. A Fleet-level Ingress defines routing rules for north-south traffic and zone-disaster recovery.
Prerequisites
Before you begin:
-
A Fleet instance, ACK cluster, and registered cluster in the same VPC but different availability zones
-
Non-overlapping node and pod CIDR blocks between the ACK cluster and the on-premises Kubernetes cluster (Network design for Fleet management)
-
A leased line connecting your on-premises data center to the VPC
-
The on-premises cluster's container network type (underlay or overlay) is determined — this affects the required Service type
| Network type | Required Service type | When to use |
|---|---|---|
| Underlay | ClusterIP | Pod IPs are directly routable from the on-premises network |
| Overlay | NodePort | Pod IPs are not routable; traffic must enter through node ports |
Design the network and create clusters
-
Create a Fleet instance, an ACK cluster, and a registered cluster in the same VPC but different availability zones.
-
Verify that node and pod CIDR blocks do not overlap between the ACK cluster and the on-premises Kubernetes cluster.
Connect to Alibaba Cloud
-
Connect the on-premises Kubernetes cluster to the registered cluster (Create a registered cluster).
To migrate workloads to Alibaba Cloud with elastic resources: Build a hybrid cloud cluster and add ECS instances to the cluster and Schedule pods to elastic container instances that are deployed as virtual nodes. To improve availability against traffic spikes: Create ECIs across zones.
-
Connect the on-premises network to the VPC. See Network connectivity and Overview of hybrid networks.
-
Associate the registered cluster and ACK cluster with the Fleet instance (Manage associated clusters).
Distribute the application to multiple clusters
These ApplicationSet examples use the web-demo app. Create a multi-cluster application covers advanced options.
Underlay network
All clusters use ClusterIP Services. Apply the following ApplicationSet:
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: appset-web-demo-undelay
namespace: argocd
spec:
template:
metadata:
name: '{{.metadata.annotations.cluster_id}}-web-demo'
namespace: argocd
spec:
destination:
name: '{{.name}}'
namespace: gateway-demo
project: default
source:
repoURL: https://github.com/AliyunContainerService/gitops-demo.git
path: manifests/helm/web-demo
targetRevision: main
helm:
valueFiles:
- values.yaml
parameters:
- name: envCluster
value: '{{.metadata.annotations.cluster_name}}'
syncPolicy:
automated: {}
syncOptions:
- CreateNamespace=true
generators:
- clusters:
selector:
matchExpressions:
- values:
- cluster
key: argocd.argoproj.io/secret-type
operator: In
- values:
- in-cluster
key: name
operator: NotIn
goTemplateOptions:
- missingkey=error
syncPolicy:
preserveResourcesOnDeletion: false
goTemplate: true
Overlay network
The on-premises cluster uses NodePort Services; the ACK cluster uses ClusterIP Services. Label each cluster before applying the ApplicationSet.
-
In Argo CD, go to Settings > Clusters and add these labels:
-
On-premises cluster:
cluster: idc -
ACK cluster:
cluster: ack
-
-
Apply the following ApplicationSet:
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: appset-web-demo-overlay
namespace: argocd
spec:
template:
metadata:
name: '{{.metadata.annotations.cluster_id}}-web-demo-overlay'
namespace: argocd
spec:
destination:
name: '{{.name}}'
namespace: gateway-demo
project: default
source:
repoURL: https://github.com/AliyunContainerService/gitops-demo.git
path: manifests/helm/web-demo
targetRevision: main
helm:
valueFiles:
- values.yaml
parameters:
- name: isNodePort
value: "{{.values.isNodePort}}"
- name: envCluster
value: '{{.metadata.annotations.cluster_name}}'
syncPolicy:
automated: {}
syncOptions:
- CreateNamespace=true
generators:
- clusters:
selector:
matchLabels:
cluster: 'idc'
# A key-value map for arbitrary parameters
values:
isNodePort: "true"
- clusters:
selector:
matchLabels:
cluster: 'ack'
values:
isNodePort: "false"
goTemplateOptions:
- missingkey=error
syncPolicy:
preserveResourcesOnDeletion: false
goTemplate: true
Configure the ALB multi-cluster gateway
After deploying the application to both clusters:
-
On the Fleet instance, create an AlbConfig to provision the ALB multi-cluster gateway and add both clusters to it.
-
Create routing rules and Ingresses on the Fleet instance for active zone-redundancy.
Build a zone-disaster recovery system covers the full configuration walkthrough.
Next steps
-
Build a zone-disaster recovery system — AlbConfig and Ingress configuration for routing and failover
-
Network design for Fleet management — CIDR planning and network topology guidance
-
Create a multi-cluster application — advanced ApplicationSet configuration options