Academy/vSphere Foundation 9.0 Administrator (2V0-16.25)/Lab: Enable Supervisor Service & Deploy TKG Cluster
This lab targets VCF 9.0

Lab: Enable Supervisor Service & Deploy TKG Cluster

VCF 9.0Intermediatevcp-foundation⏱ 150 min

Objectives

  • Enable Supervisor on vSphere cluster, deploy TKG cluster, create namespace, deploy application with vSAN storage.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for vSphere Foundation 9.0 Administrator

Tasks

Task 1 Lab: Enable Supervisor Service & Deploy TKG Cluster

Supervisor and VKS (formerly TKG) deployment on VCF is a multi-step process involving NSX networking, storage policies, and content libraries. Understanding the prerequisites and configuration sequence prevents deployment failures.

Enable Supervisor on vSphere cluster, deploy TKG cluster, create namespace, deploy application with vSAN storage.

Step 1

In vCenter, configure Supervisor Service on vSphere cluster

Step 2

Select DVS, create 3 VLAN subnets (Supervisor, Pods, Services)

Step 3

Configure load balancer (Avi or HAProxy) for API

Step 4

Verify Supervisor API online (3 VMs created)

Step 5

Deploy TKG cluster with 3 control plane, 3 worker nodes

Step 6

Wait for cluster ready status

Step 7

kubectl vsphere login, access TKG cluster

Step 8

Create namespace with resource quota

Step 9

Deploy sample app (nginx) with vSAN persistent volume

Step 10

Verify pod running, PVC bound to vSAN storage

Validation Gate

Check: After enabling Supervisor and deploying a VKS cluster: verify Supervisor health is green, kubectl can connect, and a test pod runs successfully

Expected: Supervisor shows 'Running' in vCenter. kubectl get nodes shows VKS worker nodes Ready. Test pod (nginx) deploys and responds on assigned IP.

Common Errors

Enabling Supervisor without configuring NSX networking prerequisites
Fix: Supervisor requires: NSX overlay transport zone, T0 gateway with uplink to physical network, ingress/egress CIDR ranges, pod networking CIDR, service CIDR. Missing any of these causes Supervisor enablement to fail with cryptic networking errors. Validate all NSX prerequisites before starting.
Allocating insufficient IP ranges for pod and service CIDRs
Fix: Pod CIDR (/16 minimum recommended) and Service CIDR (/24 minimum) must be large enough for anticipated workload scale. A /24 pod CIDR allows only 254 pods — insufficient for most deployments. Plan for 10× current requirements: if you expect 500 pods, allocate a /16 (65K addresses).
Not configuring a content library with TKR (Tanzu Kubernetes Release) images
Fix: VKS clusters deploy from TKR images stored in a content library. If the content library is empty or has outdated TKR images, cluster creation fails. Subscribe to the VMware content library for automatic TKR updates, or manually download and import TKR OVAs.
Deploying Supervisor on a cluster with insufficient resources
Fix: Supervisor deploys 3 control plane VMs (each: 4 vCPU, 16GB RAM, 30GB disk). The cluster must have capacity for these VMs plus headroom for workloads. On a 3-host cluster, Supervisor control plane alone consumes 12 vCPU and 48GB RAM — plan accordingly.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

Container platform architecture on VCF is increasingly tested in VCDX defense. Panelists want to understand why you chose VKS over standalone Kubernetes, how pod networking integrates with NSX, and your resource sizing for Supervisor.

Requirements

  • Enable Supervisor with NSX networking prerequisites
  • Deploy VKS cluster from content library TKR images
  • Validate Kubernetes connectivity and workload deployment

Constraints

  • Supervisor requires NSX overlay networking (not VLAN-backed)
  • Pod/Service CIDRs must not overlap with existing networks
  • Supervisor control plane consumes 12 vCPU + 48GB RAM minimum

Assumptions

  • NSX T0 gateway is configured with physical network uplink
  • Content library has current TKR images
  • Cluster has sufficient capacity for Supervisor + workloads

Risks

  • Pod CIDR exhaustion limiting Kubernetes scaling
  • Supervisor control plane failure from undersized cluster

⚠ Known Pitfalls (from Community KB)

Allocating a /24 for pod CIDR — this limits the cluster to 254 pods. Use /16 or larger for production Supervisor deployments.
Forgetting that Supervisor requires 3 control plane VMs that consume significant resources on the host cluster.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.