Lab: Enable Supervisor Service & Deploy TKG Cluster
Objectives
- Enable Supervisor on vSphere cluster, deploy TKG cluster, create namespace, deploy application with vSAN storage.
Prerequisites
VCF lab environment deployed and operational
Lab Environment
Standard VCF lab environment for vSphere Foundation 9.0 Administrator
Tasks
Task 1 Lab: Enable Supervisor Service & Deploy TKG Cluster
Enable Supervisor on vSphere cluster, deploy TKG cluster, create namespace, deploy application with vSAN storage.
In vCenter, configure Supervisor Service on vSphere cluster
Select DVS, create 3 VLAN subnets (Supervisor, Pods, Services)
Configure load balancer (Avi or HAProxy) for API
Verify Supervisor API online (3 VMs created)
Deploy TKG cluster with 3 control plane, 3 worker nodes
Wait for cluster ready status
kubectl vsphere login, access TKG cluster
Create namespace with resource quota
Deploy sample app (nginx) with vSAN persistent volume
Verify pod running, PVC bound to vSAN storage
Validation Gate
Check: After enabling Supervisor and deploying a VKS cluster: verify Supervisor health is green, kubectl can connect, and a test pod runs successfully
Expected: Supervisor shows 'Running' in vCenter. kubectl get nodes shows VKS worker nodes Ready. Test pod (nginx) deploys and responds on assigned IP.
Common Errors
Final Validation
Lab completed successfully
✓ All steps completed → No errors observed
Cleanup / Restore
• Revert to snapshot if needed
Design Reflection (VCDX)
Container platform architecture on VCF is increasingly tested in VCDX defense. Panelists want to understand why you chose VKS over standalone Kubernetes, how pod networking integrates with NSX, and your resource sizing for Supervisor.
Requirements
- Enable Supervisor with NSX networking prerequisites
- Deploy VKS cluster from content library TKR images
- Validate Kubernetes connectivity and workload deployment
Constraints
- Supervisor requires NSX overlay networking (not VLAN-backed)
- Pod/Service CIDRs must not overlap with existing networks
- Supervisor control plane consumes 12 vCPU + 48GB RAM minimum
Assumptions
- NSX T0 gateway is configured with physical network uplink
- Content library has current TKR images
- Cluster has sufficient capacity for Supervisor + workloads
Risks
- Pod CIDR exhaustion limiting Kubernetes scaling
- Supervisor control plane failure from undersized cluster