Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For K3s high availability, choose either three or more server nodes with embedded etcd or two or more server nodes backed by an external datastore. Embedded etcd needs an odd number of servers to maintain quorum. In either design, K3s server nodes can run workloads by default, so dedicated agent nodes are optional. High availability depends on the datastore, network, failure domains, and workload—not just the number of servers.

Choose an HA topology

K3s documents two HA patterns. Embedded etcd keeps the datastore within the K3s server cluster; the external-database pattern uses a separate datastore. The operational trade-off is whether you want K3s to manage the embedded datastore or already have the expertise and controls to operate an external one.

Consideration Embedded etcd External datastore
Minimum K3s servers Three or more; use an odd number for etcd quorum. Two or more, plus the external datastore.
Datastore operations and backups The datastore is embedded in the K3s server cluster. The cited K3s HA guidance does not specify a universal backup procedure. The external datastore needs its own HA, backup, monitoring, and operational controls.
Network and firewall In addition to server access to the K3s API endpoint on port 6443, embedded-etcd servers must reach one another on TCP 2379 and 2380. Protect VXLAN port 8472 from public exposure. Servers need access to the K3s API endpoint and to the external datastore. The cited K3s guidance does not give one datastore port, since it depends on the selected database.
Storage Use reliable, low-latency storage. K3s recommends SSDs; slower media, including Raspberry Pi SD cards, can affect performance. Storage performance and durability depend on the external datastore. K3s states that cluster performance depends on database performance.
Failure domains Place servers so a single site or infrastructure failure does not remove the quorum needed by etcd. K3s does not prescribe a universal placement plan. Plan placement for both the K3s servers and the external datastore. The datastore’s own HA design determines its failure behavior.
Upgrade and recovery procedures Not stated as a universal procedure in the cited K3s HA guidance; plan and validate for your K3s version and environment. Not stated as a universal procedure in the cited K3s HA guidance; plan and validate for your K3s version, database, and environment.
Dedicated agents Optional; K3s servers are schedulable by default. Optional; K3s servers are schedulable by default.

Choose embedded etcd when you want the documented in-cluster datastore pattern and can provide an odd server count and suitable storage. Consider an external database when you can operate its availability, backups, monitoring, and recovery as part of the cluster design. K3s lists MySQL, PostgreSQL, MariaDB, and etcd among supported datastore families for the external-database pattern.

Plan server size, storage, and network access

Use sizing as a starting point, not an availability promise

K3s Requirements gives the following broad database sizing guidance. These are documentation guidelines, not a guarantee of availability or a substitute for sizing against your workload.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized
Deployment size Node count guidance CPU guidance Memory guidance
Small Up to 10 1 vCPU 2 GB RAM
Medium Up to 100 2 vCPUs 8 GB RAM
Large Up to 250 4 vCPUs 16 GB RAM
X-large Up to 500 8 vCPUs 32 GB RAM
XX-large 500+ in the listed guidance 16 vCPUs 64 GB RAM

The node-count bands describe broad deployment sizes; they do not establish a universal server count, resource profile, uptime percentage, or recovery-time objective. Workload characteristics and database performance still matter. K3s recommends SSD disks, and warns that slower storage such as Raspberry Pi SD cards can cause performance issues with embedded etcd.

Allow only the traffic the design needs

  • TCP 2379 and 2380: allow embedded-etcd servers to reach one another.
  • TCP 6443: use this K3s server API endpoint when joining servers or agents.
  • Port 10250: node access on this port is required for metrics-server use.
  • UDP 8472: K3s uses this port for VXLAN; do not expose it to the public internet.

Keep cluster nodes behind firewall or security-group controls and permit the required traffic between the relevant nodes. The external-database design also needs server-to-datastore connectivity; its database port depends on the datastore you choose.

Rank #2
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
  • Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

Initialize and join an embedded-etcd cluster

Prepare three or more servers with unique hostnames, reliable low-latency storage, and private network connectivity before installing K3s. Keep the critical cluster settings consistent across all servers: cluster and service CIDRs, cluster DNS and domain, component-disable flags, egress selector mode, and secrets-encryption configuration. Mismatched values can prevent servers from joining the same cluster correctly.

  1. Initialize the first server. On server 1, install K3s with --cluster-init and a shared token. Replace the placeholders; use a fixed IP in --tls-san only if you intend to use that address as a stable registration or client endpoint.
    curl -sfL https://get.k3s.io | K3S_TOKEN=SECRET sh -s - server --cluster-init --tls-san=<FIXED_IP>
  2. Join the other server nodes. Install K3s in server mode on each additional server, using the same token and the first server’s API endpoint. If clients or joining nodes will use a fixed registration address, include that address as a TLS SAN as well.
    curl -sfL https://get.k3s.io | K3S_TOKEN=SECRET sh -s - server --server https://<server1>:6443 --tls-san=<FIXED_IP>

    For a setup without a fixed address, omit the --tls-san option.

  3. Check node membership. Run kubectl get nodes. In K3s’s example output, server nodes have control-plane, etcd, and master roles. Confirm that every expected server appears before relying on the cluster.
  4. Add agents if needed. Agents are useful when you want separate worker capacity, but they are not mandatory. Join one with the same shared token and a reachable server endpoint:
    curl -sfL https://get.k3s.io | K3S_TOKEN=SECRET sh -s - agent --server https://<server>:6443

Use an external datastore instead

The external-database pattern starts with two or more K3s servers connected to an external datastore, rather than relying on embedded SQLite. K3s lists MySQL, PostgreSQL, MariaDB, and etcd among the supported database families. This approach shifts datastore availability, backups, monitoring, and operational controls to the system that runs that database; it does not remove the need to make the K3s servers and their network paths resilient.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
  • CanaKit Raspberry Pi 5 Essentials Starter Kit

Because K3s server nodes are schedulable by default, you do not need separate agents simply to make an external-database cluster highly available. You may still add agents to separate worker capacity from server nodes. Keep the critical configuration values consistent across servers, and make sure each can reach both the API endpoint used by the cluster and the chosen datastore.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What HA does—and does not—guarantee

A multi-server topology is only one part of availability. The datastore must retain quorum or remain reachable, network paths must work, and storage and workloads must tolerate the failures your design is meant to handle. The K3s guidance cited here does not publish a universal uptime percentage, guaranteed recovery-time objective, or hardware profile that guarantees application availability. Decide on placement, backups, and recovery procedures for your chosen datastore and environment, then validate them under the failure conditions that matter to your service.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 2
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$419.99
Bestseller No. 3
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit
$189.99
Best Value
RasTech Raspberry Pi 5 8GB Kit with Active Cooler and Pi5 Case
  • 【What you Get】You will get 1*Pi 5 8GB Single Board,1*RasTech Case,1*Active Cooler,1*Screwdriver,1*Installation instructions,12-month free warranty, lifetime service, 24-hour prompt and friendly response.
  • 【More Connectors】There are two USB 3.0 ports(5Gbps simultaneously) and two USB 2.0 ports, which triple total bandwidth ,support any combination of up to two cameras or displays. Peak SD card performance is doubled through support for the SDR104 high-speed mode. It provides a smooth desktop experience for you. Offer Gigabit Ethernet and a PCIe interface, along with dual-band Wi-Fi and Bluetooth 5.0/BLE wireless capability. The RasTech Pi 5 Kit use the new 27W 5.1V 5A USB-C power connector.
  • 【 Support Dual 4Kp60 Display 】Each of the two microHDMI sockets can control a 4K display at 60 Hertz, now support HDR, offering super HD video for media streaming projects. RPi 5 is the first RPi model that comes with a PCI Express port (PCIe 2.0 x1 with 500 MB/s) to attach SSDs (requires separate M.2 HAT).
  • 【 Excellent Chips And Applications】Pi 5 is a full-size Pi computer using silicon built in-house at Pi. The RP1 “southbridge” provides the bulk of the I/O capabilities for Pi 5. Pi 5 is more friendly and convenient in the development of Internet of Things, Web development, machine identification, automatic control and other electronic equipment applications and network.
  • 【 Faster CPU, Better GPU 】 Pi 5 features a Broadcom BCM2712 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz, it delivers a 2–3× increase in CPU performance relative to RaspberryPi 4. The 800MHz VideoCore VII GPU is compatible to OpenGL ES 3.1 and Vulkan 1.2, substantial uplift in graphics performance. Pi 5 Offers lightning-fast CPU speed, a PCI Express interface, a Real Time Clock (RTC) and a power button and runs significantly cooler than Pi 4.
Rank #4
SANOOV Raspberry Pi 5 4GB Kit, 4GB RAM Single Board Computer with Active Cooler and ABS Case, Complete Raspberry Pi 5 Starter Kit for IoT Robotics Retro Gaming
  • All-in-One Complete Kit: This SANOOV RPi 5 bundle comes with Raspberry Pi 5 4GB RAM single board, active cooler, durable ABS case and screwdriver. No extra parts needed, ready to use right out of the box for beginners and hobbyists
  • Powerful Single Board Computer: Equipped with 4GB RAM and high-performance processor, delivers fast running speed for 4K playback, AI projects, programming and daily computing tasks. SANOOV for raspberry pi 5 4GB is equipped with broadcom 64 quad-core Arm Cortex A76 processor with gigabit ethernet and upgraded with IEEE 802.11ac Wi-Fi, Bluetooth 5.0 dual-band 2.4Ghz and 5Ghz and Power Over Ethernet (POE). Upgrading delivers 2-3 x speed vs Pi 4, redefining the experience
  • Efficient Active Cooler: Effectively lowers operating temperature and prevents performance throttling. Runs quietly even under long-time heavy load, ensures stable operation all day long. SANOOV RPi 5 4GB kit offer an active cooler, which combines an aluminium heatsink with a high-performance PWM fan. Active cooler is fully compatible with the Pi OS, which can effectively reduce the temperature of RPi5 and ensure its good performance during long-term high load operation
  • Sturdy ABS Protective Case: Well-fitted for Raspberry Pi 5 board, can be secured with 4 screws to effectively protect the Pi 5 motherboard from damage, reserves full access to all ports and buttons. SANOOV uses ABS material to produce the case, which has a softer texture and feel. Meanwhile, SANOOV case adopts a layered design for easy disassembly and installation. (Tip: The Case cannot install M.2 HAT Add on Board and Solid State Drive!)
  • Wide Application & Full Compatibility: Seamlessly compatible with official OS and mainstream peripheral accessories for Raspberry Pi 5. Whether you are a beginner, student, electronics hobbyist or professional developer, this all-in-one kit meets your diverse needs. It excels in IoT projects, robotics design, retro gaming devices, home media servers and other DIY creations. Backed by a large global community, you can easily find guides, technical support and shared projects online

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.