BKE Bahriya Kubernetes Engine Start a 14-day trial

What's included

Every component, named. And what BKE deliberately leaves out.

A distribution is a set of promises about which versions work together. This page is the list of what BKE promises about, and — just as plainly — what it does not.

The base

Upstream Kubernetes, and the fabric under it.

Every cluster gets upstream Kubernetes — no fork, no proprietary CRDs — with Calico as the network fabric, WireGuard encryption for pod traffic, and containerd as the runtime, each pinned to an exact patch tested together. These are the two decisions BKE makes, fixed for the life of the cluster.

Which exact versions a release pins is stated in that release's notes, in the console.

The components

Seven components, each opt-in, one line each.

Kubernetes alone runs containers. It does not give you storage, a way in for outside traffic, certificates, logs or monitoring. BKE installs those as components — each a well-known open-source project, pinned to versions tested together, enabled per cluster in one file. Enable what you need and leave out what you do not.

Component What it does for you
LonghornReplicated block storage — persistent volumes for applications that keep data, with backups to an object store you name.
KongIngress and API gateway — routes HTTP traffic from outside the cluster, with rate limiting, caching and access control as declared plugins.
cert-managerObtains and renews TLS certificates.
KumaService mesh — optional traffic control between applications; installing it changes nothing until a namespace opts in.
Fluent BitCollects logs from every node and ships them to a destination you choose.
NetdataPer-node monitoring with per-second resolution — metrics and dashboards.
metrics-serverResource figures — makes kubectl top and autoscaling work.

There are no editions and no feature flags. The licence gates BKE, not parts of it — there is no per-component entitlement anywhere in the product, and no upsell waiting behind a setting.

Deliberately not included

Three things BKE will not decide for you.

Your load balancer.

The addresses in front of a cluster are your infrastructure. The reference architecture gives working configurations to start from.

Your certificate issuer.

An issuer names things that are yours — your domains, your DNS provider, your registration email. You create one once; the docs show how.

Your log destination.

BKE decides what is collected; you decide where it goes. Until you do, nothing is shipped. Worked examples cover OpenSearch, Loki and object stores.

The full detail is in the documentation.