Back to articles
Technology Insight

Maximizing Enterprise Value: Building a Production-Ready K3s Kubernetes Cluster on Oracle Cloud Infrastructure's Free Tier

June 4, 2026

Introduction to Cost-Optimized Cloud Architecture

In the modern enterprise landscape, balancing innovation with infrastructure costs remains a primary challenge for technology leaders. Containerization and orchestration via Kubernetes have become industry standards for deploying scalable applications. However, the operational overhead and cloud consumption costs associated with managed Kubernetes services can be prohibitive for testing, staging, or small-scale production environments.

Oracle Cloud Infrastructure (OCI) offers a highly disruptive solution through its Always Free Tier, providing generous compute resources that outclass competing cloud providers. By pairing OCI's infrastructure with K3s—a lightweight, highly optimized Kubernetes distribution developed by Rancher—organizations can build a fully functional, highly available Kubernetes cluster entirely free of charge. This article provides a comprehensive, step-by-step guide to architecting and deploying this solution.

Why OCI Free Tier and K3s?

Before diving into the technical implementation, it is crucial to understand the strategic advantages of combining these two technologies.

The Power of OCI Always Free Tier

Unlike traditional free tiers that expire after a year or offer minimal computing power, OCI provides robust, permanent resources. Most notably, Oracle offers Ampere Altra ARM-based compute instances. The free tier allows users to allocate up to 4 OCPUs (cores) and 24 GB of RAM, which can be split across up to 4 distinct virtual machines (VMs). This allocation provides ample compute power to host a multi-node enterprise-grade cluster.

The Efficiency of K3s

Standard Kubernetes (K8s) is resource-heavy, often consuming significant memory just to run core control plane components. K3s solves this by being packaged as a single binary under 100MB. It reduces memory usage by replacing embedded cloud providers with lightweight alternatives and optimizing the storage backend, making it the perfect match for resource-constrained or cost-optimized environments without sacrificing standard Kubernetes API compatibility.

Architecting the Cluster Topology

To maximize the 4 OCPUs and 24 GB RAM provided by OCI, we will design a highly stable, multi-node architecture:

  • 1 x Control Plane Node (Master): 2 OCPUs, 12 GB RAM (Handles API server, scheduler, and cluster state).
  • 2 x Worker Nodes (Agents): 1 OCPU, 6 GB RAM per node (Executes containerized workloads).

This topology ensures adequate separation of concerns, ensuring that high workload demands on worker nodes do not destabilize the cluster management plane.

Step 1: Preparing the OCI Networking Infrastructure

A secure networking foundation is mandatory before provisioning instances. Follow these steps within the OCI Console:

1. Create a Virtual Cloud Network (VCN)

Navigate to Networking > Virtual Cloud Networks and utilize the VCN Wizard to create a VCN with Internet Connectivity. This automatically configures public subnets, internet gateways, and NAT gateways.

2. Configure Security Lists (Firewall Rules)

K3s requires specific ports to be accessible for node communication and external traffic. Modify your VCN's Default Security List to allow the following Ingress Rules:

  • Port 6443: Kubernetes API Server (Required for kubectl access and node registration).
  • Ports 2379-2380: Required if utilizing embedded etcd for high availability.
  • Port 8472: Flannel VXLAN overlay networking traffic.
  • Ports 80 and 443: Standard HTTP/HTTPS traffic for your application Ingress Controller.
Note: For production-grade security, restrict port 6443 access to your corporate or development IP addresses rather than opening it to the public internet (0.0.0.0/0).

Step 2: Provisioning the Compute Instances

Navigate to Compute > Instances and select Create Instance. Configure your instances with the following specific settings:

  1. Image and Shape: Select Canonical Ubuntu (22.04 or 24.04 LTS). Change the shape to Ampere (VM.Standard.A1.Flex).
  2. Resource Allocation: Allocate resources according to the planned topology (2 OCPUs/12GB for Master, 1 OCPU/6GB for Workers).
  3. Networking: Assign each instance to the public subnet generated by your VCN wizard and ensure a public IP address is assigned.
  4. SSH Keys: Generate or upload your public SSH key to ensure secure administrative access.

Step 3: Deploying the K3s Control Plane

Once your VMs are running, connect to the primary master VM via SSH to initiate the K3s installation. K3s provides a streamlined installation script that handles dependencies automatically.

Execute the following command on the master node:

curl -sfL [https://get.k3s.io](https://get.k3s.io) | sh -s - server --node-external-ip 

This script downloads, installs, and starts the K3s system service. Once complete, verify that the master node is active by running:

sudo kubectl get nodes

To connect the worker nodes, you must retrieve the cluster's secure access token. Extract it from the master node using:

sudo cat /var/lib/rancher/k3s/server/node-token

Step 4: Joining Worker Nodes to the Cluster

SSH into each of your worker node instances. Run the installation script, specifying that these instances should act as agents and point directly to your master node:

curl -sfL [https://get.k3s.io](https://get.k3s.io) | K3S_URL=https://:6443 K3S_TOKEN= sh -

After the script finishes execution on all workers, return to your master node and execute sudo kubectl get nodes. You should see a cohesive, multi-node cluster displaying a Ready status across all members.

Step 5: Configuring Local Administration and Ingress

To safely manage the cluster from your local workstation, copy the configuration file located at /etc/rancher/k3s/k3s.yaml from the master node to your local machine's ~/.kube/config directory. Ensure you edit the file to change the server address from 127.0.0.1 to your master node's public IP address.

By default, K3s installs the Traefik Ingress Controller. This allows you to immediately route external web traffic directly to your containers. You can deploy a sample Nginx deployment and expose it via a Traefik Ingress resource to verify end-to-end functionality.

Conclusion and Operational Best Practices

By leveraging Oracle Cloud Infrastructure’s generous Free Tier alongside Rancher's highly efficient K3s, IT professionals can establish a highly capable, enterprise-grade Kubernetes environment at zero financial cost. This setup serves as an exceptional framework for continuous integration pipelines, application prototyping, and hosting lightweight enterprise tools.

As a best practice, ensure you set up proactive monitoring using lightweight tools like Prometheus and Grafana, and implement routine backups of your cluster configurations. Operating on a free cloud tier removes infrastructure costs, but executing strict operational maintenance ensures your cloud architecture remains highly reliable and performant.