Back to articles
Technology Insight

High Availability on a Budget: Building a Fault-Tolerant K3s Cluster with Ingress-Nginx on Hetzner Cloud

June 1, 2026

Introduction: The Quest for Affordable High Availability

In the modern DevOps landscape, Kubernetes has become the gold standard for container orchestration. However, the perceived complexity and high cost of managed Kubernetes services often deter small-to-medium enterprises and independent developers. The challenge is clear: how can one achieve High Availability (HA) and fault tolerance without breaking the bank? The answer lies in the combination of K3s—Rancher’s lightweight Kubernetes distribution—and the robust Hetzner Cloud infrastructure.

This technical deep dive explores the implementation of a 3-node K3s cluster, integrated with Ingress-Nginx, to ensure that your applications remain online even if a virtual private server (VPS) fails. By utilizing Hetzner’s cost-effective CX series, we can build a resilient environment for a fraction of the cost of traditional cloud providers.

Why K3s and Hetzner?

K3s is specifically designed for resource-constrained environments. It packages the essential components of Kubernetes into a single binary of less than 100MB, reducing the memory footprint significantly. When paired with Hetzner’s high-performance VPS offerings, you get a powerful synergy of efficiency and speed.

  • Reduced Overhead: K3s replaces heavy components like etcd with SQLite (for single node) or embedded etcd (for HA), saving precious RAM.
  • Cost Efficiency: Three Hetzner Cloud instances provide the quorum needed for a distributed control plane at a price point lower than a single instance at other major providers.
  • Simplified Management: K3s automates complex tasks like certificate rotation and provides a streamlined installation process.

Architectural Overview of a 3-Node HA Cluster

To achieve true fault tolerance, we deploy a multi-master architecture. In this setup, all three nodes act as both the control plane and worker nodes (though in larger scales, these roles might be separated). This ensures that if any single node goes offline, the remaining two maintain the quorum and continue serving traffic.

The Role of the Load Balancer

While the nodes hold the logic, we need a way to distribute incoming traffic. Using a Hetzner Cloud Load Balancer at the front end provides a single entry point. It health-checks our nodes and routes traffic only to those that are healthy. Under the hood, we deploy Ingress-Nginx as our Ingress Controller to handle L7 routing, SSL termination, and virtual hosting.

Step 1: Preparing the Infrastructure

Before installing K3s, we must provision our resources. For this setup, we recommend three CX21 instances (or higher) located in the same data center to minimize latency. We will also utilize a Private Network to allow the nodes to communicate securely without exposing internal traffic to the public internet.

Pro Tip: Always use a Private Network (VPC) for K3s internal communication. It enhances security and ensures that node-to-node traffic does not count against your public bandwidth quota.

Step 2: Deploying the K3s High Availability Cluster

Installation begins with the first node, initialized with the --cluster-init flag to enable the embedded etcd database. Once the first node is live, the subsequent two nodes join the cluster using the shared secret token.

  1. Initialize Node 1: Run the K3s installation script with the server flag and the datastore-endpoint configuration.
  2. Join Node 2 and 3: Use the same installation script but point to the first node's internal IP as the server URL.
  3. Verification: Execute kubectl get nodes to ensure all three nodes show a Ready status.

This distributed control plane is the heart of our fault-tolerant system. Because we are using 3 nodes, the cluster can survive the loss of one node while maintaining its state and management capabilities.

Step 3: Implementing Ingress-Nginx for Traffic Routing

While K3s comes with Traefik by default, many enterprise environments prefer Ingress-Nginx due to its extensive feature set and familiar configuration syntax. To install it, we first disable the default Traefik deployment during the K3s setup or remove it post-installation.

We deploy Ingress-Nginx using Helm, configuring it to use HostPort or integrating it with the Hetzner Cloud Controller Manager (CCM). This allows the Ingress Controller to receive traffic from the external Load Balancer and route it to the correct Pod based on the Host header or path.

Example Ingress Configuration

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: web-app-ingress
  annotations:
    kubernetes.io/ingress.class: nginx
spec:
  rules:
  - host: app.yourdomain.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: web-service
            port:
              number: 80

Step 4: Ensuring Data Persistence with Longhorn

A cluster is only as fault-tolerant as its data. If a node fails, the Pods will migrate to another node, but their data must follow them. For this, we integrate Longhorn, a lightweight distributed block storage system. Longhorn replicates your volumes across all three nodes. If one node catches fire, your data remains safe on the other two, and the new Pod on a healthy node can reattach to the volume instantly.

Performance Optimization and Monitoring

Running a cluster on low-cost VPS means resources are finite. To keep the system lean, we suggest the following optimizations:

  • Resource Quotas: Define CPU and Memory limits for all deployments to prevent a single "noisy neighbor" from crashing a node.
  • Log Rotation: Use a tool like Fluentbit to ship logs off-node, preventing the local disk from filling up.
  • Monitoring: Deploy a lightweight Prometheus and Grafana stack to keep an eye on node health and cluster metrics.

Conclusion: Reliability Does Not Have to Be Expensive

By combining K3s, Ingress-Nginx, and Hetzner Cloud, we have built a professional-grade, fault-tolerant Kubernetes cluster for a monthly cost that is significantly lower than managed alternatives. This setup provides the scalability needed for growth while maintaining the resilience required for production workloads.

Whether you are hosting microservices, APIs, or web applications, this architecture ensures that your services stay online, your data remains persistent, and your infrastructure remains cost-effective. The barrier to entry for high-availability cloud computing has never been lower.

High Availability on a Budget: Building a Fault-Tolerant K3s Cluster with Ingress-Nginx on Hetzner Cloud | DPTCloud