Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Marketplace / K3s Lightweight Kubernetes on Ubuntu 24.04 LTS

K3s Lightweight Kubernetes on Ubuntu 24.04 LTS

A full CNCF-certified Kubernetes cluster in a single VM. K3s bundles the control plane, kubelet, containerd, and Traefik ingress into one lightweight binary — ideal for edge workloads, CI, and teams that want Kubernetes without cluster-management overhead.

Version: K3s v1.36.5+k3s1 (Kubernetes 1.36; bundled Traefik 3.7.13 ingress, CoreDNS 1.14.7)Platform: Ubuntu 24.04 LTSPorts: 80 and 443 (the bundled Traefik ingress) are open in the VM's own firewall — open them in the Network Security Group and your Ingress routes are reachable. 6443 (Kubernetes API) is deliberately NOT opened: the kubeconfig is full cluster-admin, so the API stays on the nodeCategory: DevOps & Kubernetes
Pay-as-you-go pricing: $0.09 per vCPU per hour software fee, plus Azure infrastructure (billed by Microsoft). Example: a 4-vCPU VM runs about $263/month in software fees at 730 hours — stop the VM, stop paying.
K3s Lightweight Kubernetes on Ubuntu 24.04 LTS screenshot

What's included

  • K3s v1.36 — CNCF-certified Kubernetes distribution
  • Traefik ingress and local-path storage provisioner included
  • containerd runtime, no Docker daemon required
  • Ubuntu 24.04 LTS with automatic security updates
  • Trusted Launch: Secure Boot + vTPM supported
  • Add agent nodes later to grow into a multi-node cluster

Quick start

  1. SSH into the VM with the username and key you chose at deploy.
  2. K3s runs as the `k3s` systemd service; verify with `sudo k3s kubectl get nodes`. The VM firewall is active: 80/443 allowed for ingress, 6443 not allowed.
  3. Allow 80 and 443 in the Network Security Group, then deploy a workload and an Ingress with kubectl or Helm — Traefik 3.7 is already running as the default ingress controller, so http://<VM-IP>/ reaches your route (it answers 404 until you create one). Traefik custom resources such as IngressRoute and Middleware use `apiVersion: traefik.io/v1alpha1`; the Traefik 2 group `traefik.containo.us` is not served.
  4. Copy /etc/rancher/k3s/k3s.yaml (rewrite the server IP) to use kubectl from your workstation over a 6443 rule scoped to your own address.

Common use cases

  • Edge and branch-office Kubernetes
  • CI/CD test clusters that boot in minutes
  • Learning and certification practice (CKA/CKAD)
  • Lightweight production for containerized apps

Why our images

Freshly rebuilt against the latest security advisories, no shared default credentials, Trusted Launch support, and automatic OS security updates — everything runs in your own Azure subscription under your governance.

Deploy K3s Lightweight Kubernetes in minutes

Production-ready, hardened, and maintained. Deploy straight from the Azure Marketplace into your subscription.