VKS – VMware vSphere Kubernetes Service

Run Kubernetes natively in your own data center

Using VMware vSphere Kubernetes Service, evoila is implementing a production-ready container platform on VCF. Data-sovereign, self-service-enabled and fully integrated into the existing infrastructure.

Enterprise Kubernetes without public cloud dependency

Kubernetes in the public cloud is simple but expensive, complex from a data protection perspective, and strategically dependent. VMware vSphere Kubernetes Service brings enterprise-grade Kubernetes natively to VCF: with Supervisor Clusters, self-service namespaces, an integrated registry, and production-ready lifecycle management—all without public cloud dependency. evoila implements VKS as a fully integrated part of the VCF stack, empowering developer and platform teams to achieve true container autonomy in their own data center.

Business benefits at a glance:

  • Capitalisation on VCF: VKS is part of VCF. By adopting VKS, you capitalize on your VCF investment and get a production-ready kubernetes runtime as part of your private-cloud
  • Data sovereignty: Container workloads remain in your own data center, without public cloud dependency and with full control over data storage
  • Self-service for development teams: VKS delivers a secure, multi-tenant container platform that enables developers to provision and manage environments independently, accelerating innovation and reducing time-to-market.
  • Cost control: No variable public cloud costs for container workloads; predictable infrastructure costs based on existing VCF infrastructure
  • Enterprise Support: the whole VCF + VKS is backed by Broadcom’s Support
  • Best possible integration: VKS has the best possible storage, network and governance integration in VCF

Kubernetes without a Strategic Foundation

Kubernetes has established itself as the standard for containerised workloads. However, for many companies, the question of where and how to deploy Kubernetes remains unresolved. Public cloud Kubernetes service are readily available but create long-term dependencies, costs that are difficult to predict, and data protection risks that exclude regulated industries and data-sensitive workloads.

At the same time, Kubernetes on on-premises infrastructure is traditionally complex: cluster provisioning, network integration, storage classes, lifecycle management, and multi-team isolation require deep expertise and operational maturity. Without a well-thought-out platform strategy, cluster silos emerge that are just as operationally complex as the public cloud alternative, but without its convenience.

The pressure to migrate from existing Kubernetes platforms such as OpenShift or Rancher to VCF-native solutions is growing: customers who have already invested in VCF want a unified platform—not yet another infrastructure silo alongside their existing stack.


Platform Strategy before Cluster Deployment

Most Kubernetes problems aren’t technical, they’re architectural. evoila brings the platform perspective that prevents cluster silos, uncontrolled costs, and compliance gaps before they form.

The Challenge

Five ways the wrong Kubernetes Strategy compounds risk

Public cloud Kubernetes solves the provisioning problem but creates a harder one: strategic dependency, unpredictable costs, and data sovereignty gaps that exclude regulated workloads by default. Self-managed Kubernetes without a platform-first approach trades one complexity for another, cluster silos that are operationally as demanding as the public cloud, but without its convenience. Neither path scales cleanly. Both demand a rethink.

Public cloud Kubernetes creates strategic dependencies, uncontrollable costs, and data protection risks

Self-managed Kubernetes without a platform strategy leads to cluster silos and operational fragmentation

Development teams wait too long for infrastructure – self-service Kubernetes is lacking

Compliance requirements rule out public cloud Kubernetes for sensitive workloads

Existing Kubernetes platforms are not integrated with VCF and prevent unified lifecycle management

Platform architecture comes before the first cluster

evoila defines multi-tenancy model, network integration, storage classes, artifact store concept, and team onboarding before any implementation begins — eliminating the technical debt that makes most on-premises Kubernetes environments hard to operate at scale.

Our Solution

VKS as a production-ready platform

Supervisor Cluster Design & Implementation

Setting up the VCF-integrated Supervisor Cluster as a Kubernetes control plane, using vSphere namespaces, resource limits, and role-based access control as the foundation for multi-team operations.

VKS-Clusters

Deployment and lifecycle management of VKS-Clusters for different teams, environments, and workload classes, versioned and reproducible via cluster templates.

Namespace-based self-service model

Establishment of a self-service framework through which development teams can independently and compliantly provision Kubernetes namespaces and workload clusters. With integrated resource limits, network policies, and approval workflows.

Harbor Registry Integration

Implementation of the VMware Harbor Container Registry as a central, private image registry. With vulnerability scanning, image signing, and replication policies for a secure container supply chain.

Network & Storage Integration

Configuration of NSX-based networking for Kubernetes workloads. With AVI as the native ingress controller and vSAN storage classes for persistent workloads.

Are you  thinking about migrating to VKS from another solution (i.e. Rancher , Openshift, Vanilla K8s)? 

We have developed a structured migration process from existing Kubernetes solutions to VKS. With a detailed workload assessment, migration analysis, end-to-end functional testing and an exhaustive handover documentation, we can help you through the whole migration process.

Tech-Deep-Dive

The architecture behind IT

Supervisor Cluster as the Kubernetes control plane

The Supervisor Cluster is the heart of VKS: It runs directly on the ESXi hypervisor and natively integrates Kubernetes into VCF without requiring separate virtual machines for the control plane. vSphere Namespaces provide the isolation and governance layer for teams and projects: Each namespace is assigned defined CPU, memory, and storage limits, as well as role-based access controls. evoila designs the namespace model based on specific organisational and compliance requirements.

VKS: Production-ready workload clusters

Workload clusters are deployed via VKS as fully managed Kubernetes clusters, versioned, template-based, and orchestrated via the Supervisor Cluster. VKS provides a consistent Kubernetes experience: standardised cluster configurations, integrated lifecycle management, and automatic node reprovisioning in the event of failures. evoila develops cluster templates for different workload classes—from development clusters with reduced resources to production-ready multi-node clusters with anti-affinity rules.

Network Integration: Antrea as standard CNI

Kubernetes networking runs via Antrea as Container Network Interface, per default. VKS also supports Calico and routable pods via the Antrea NSX Routed CNI. AVI acts as an AKO integration, serving as the ingress controller and load balancer for external service exposure. The result is a network architecture fully integrated into VCF without any media breaks.

Harbor Registry: Secure container supply chain

Harbor serves as a central private container registry with an integrated vulnerability scanner, image signing via Notary, and configurable replication policies for georedundant registry deployments. evoila implements Harbor as a production-ready registry platform with defined promotion policies. Images undergo vulnerability scanning and signing processes before being admitted to production namespaces.

Technical Advantages

Built into VCF, not bolted on

Native VCF integration

The Supervisor cluster runs directly on ESXi without separate control plane VMs, fully integrated into VCF lifecycle management

Consistent Kubernetes

VKS provides standardised, versioned cluster configurations with automatic lifecycle management and node reprovisioning

NSX-native networking integration

when using Antrea as Kubernetes CNI, you will get full integration in NSX and into your whole VCF architecture

Secure container supply chain

Harbor with vulnerability scanning, image signing, and promotion policies prevents insecure images from entering production environments

Self-service with governance

Namespace-based model gives teams autonomy with integrated resource limits and network policies

Your partner of choice

Platform Engineering that spans design, build & operations

Running Kubernetes platforms on your own infrastructure requires more than just technical knowledge.

It requires a platform-centric mindset: the ability to conceptualise Kubernetes architecture, VCF integration, network design, storage strategy, and team onboarding processes as a unified whole. evoila brings exactly this holistic perspective to the table: evoila has already implemented VKS in production environments. From mid-sized development platforms to complex multi-team production environments.

evoila’s strength lies in the depth of integration: VKS is not viewed in isolation, but is designed in conjunction with NSX network architecture, AVI Ingress, vSAN Storage Classes, and VCF-Automation—as a coherent platform, not as a collection of individual products.

For customers with existing OpenShift or Rancher environments, evoila brings specific migration expertise, including workload analysis, network mapping, and a structured migration path without production downtime.

Platform-First Architecture

Structured OpenShift & Rancher Migration

Native NSX, AVI & vSAN Integration

Same-Team Continuity

Partnership

Technology & Partner

VKS
Broadcom

Through our Broadcom partnership, evoila brings deep VMware Cloud Foundation expertise to the design and delivery of VKS environments. We help organisations extend their existing VCF investment with a production-ready Kubernetes runtime built into the networking, storage and governance capabilities of their private cloud.

Introductory Offer

VKS platform assessment

The structured onboarding process begins with an analysis of the existing container strategy and infrastructure. In the evoila VKS Platform Assessment, we analyse:

Existing container workloads and platform strategy

Potential migration from other Kubernetes solutions or hyperscalers 

Namespace model and team onboarding requirements

Integration points into existing VCF, NSX, and vSAN environments

The result is a concrete platform design with a prioritised implementation plan.

Tell us about your Challenge

Tell us about your infrastructure setup and the goals you want to achieve. Whether you need an independent second opinion on your current vSphere architecture or want to evaluate how to bring your operations and development teams onto a single platform, we are here to map out a solution together.

FAQs

Commonly asked questions about VKS – VMware vSphere Kubernetes Service