Two Kubernetes clusters for disaster recovery shouldn't cost twice as much
Most multi-cluster HA setups run active/active, which means paying for full workloads on both clusters around the clock. For our production workloads, I wanted automatic disaster recovery without the standby cluster burning money every day. So I built an active/passive multi-cluster setup with Karmada ๐ ๐น ๐ข๐ป๐ฒ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น ๐ฝ๐น๐ฎ๐ป๐ฒ, ๐๐๐ผ ๐๐๐ฏ๐ฒ๐ฟ๐ป๐ฒ๐๐ฒ๐ ๐ฐ๐น๐๐๐๐ฒ๐ฟ๐ Karmadaโฆ
The article discusses the challenges of running two Kubernetes clusters for disaster recovery, which can be costly due to the need to pay for full workloads on both clusters around the clock. The author built an active/passive multi-cluster setup using Karmada, a lightweight K3s host that manages both member clusters. Deployments, Services, Ingresses, ConfigMaps, and Secrets are propagated using a single PropagationPolicy.
The primary cluster remains on standby until it becomes unavailable, at which point the secondary cluster automatically takes over without manual intervention. However, once the primary cluster recovers, the workloads remain on the secondary cluster, consuming resources unnecessarily. The author addressed this issue by implementing a small CronJob-based fail-back mechanism that waits for the primary cluster to remain healthy for 15 minutes, clears the schedulers affinity pin, triggers a reschedule, and moves the workloads back to the primary cluster.
This allows the secondary cluster to return to its standby role automatically. The author also replaced self-hosted HAProxy setup for traffic management with Cloudflare Load Balancer, which simplifies the configuration and removes the need for an additional HAProxy layer. The author concludes that an active/passive architecture with automated failover and fail-back can provide disaster recovery while avoiding the cost of continuously running full production capacity on both clusters.
Brief written by urgent.news from Dev.to's own syndicated text. Machine-written โ may contain errors; check the original before relying on it.