How do managed Kubernetes providers hide the master nodes?

Tho*_*ell 5 digital-ocean kubernetes google-kubernetes-engine

If I run kubectl get nodes on GKE, EKS, or DigitalOcean Kubernetes, I only see the worker nodes. How are these systems architected at the network or application level to create this separation between workers and masters?

Luk*_*ler 5

只要工作节点具有对控制平面的网络访问权限,您就可以在 Kubernetes 外部运行 Kubernetes 控制平面。大多数托管 Kubernetes 解决方案都使用这种方法。