Introduction: The Need for LB Categories
Managing Kubernetes® workloads in hybrid or static environments especially when deploying clusters via Cluster API (CAPI) presents persistent operational challenges:
- Manual Endpoint Maintenance: As worker nodes scale out or fail over, updating target groups and mapping node ports to backend IPs manually requires constant maintenance and introduces room for configuration drift.
- Control Plane VIP Complexity: Bootstrapping High Availability (HA) Kubernetes control planes traditionally relies on running in-guest software (like kube-vip) directly inside the control plane VM templates. This ties networking logic directly into node images and adds unnecessary plumbing to cluster lifecycle management.
- Friction in Infrastructure Automation: Without metadata-driven network abstraction, infrastructure controllers must constantly track individual IP address allocations, preventing a seamless, cloud-like experience on-premises.
There needs to be a mechanism that decouples load balancer routing from hardcoded IP addresses, allowing network policies to dynamically adjust as virtual machines are created or destroyed.
What Are Nutanix Categories?
In the Nutanix ecosystem, Categories are user-defined key-value tags used to logically group and classify entities (such as VMs, hosts, or storage groups) across your environment.
- Logical Grouping: Rather than managing infrastructure using individual IP addresses or hostnames, entities are assigned key-value pairs (e.g., AppTier: WorkerNode or Role: ControlPlane). This is conceptually similar to how labels are used to organize and select Kubernetes resources, although the supported Nutanix Category and Kubernetes label behaviors are distinct.
- Policy Application: Categories drive automated behaviors across Nutanix Flow Security, backup rules, storage policies, and networking.
- Potentially Simplified Operations: When a new VM is tagged with a category, applicable configured policies can be applied automatically.
Using Nutanix Categories as Flow Load Balancer targets extends this metadata-based approach to network load balancing. Instead of defining static backends, you configure your load balancer to target a Category letting the underlying network can use group membership to help maintain the configured target set.
Why LB Categories Are a Game-Changer for Kubernetes Load Balancing?
By combining Nutanix Categories with Flow Load Balancer (Flow LB), you can reduce reliance on manually maintained static target definitions for application and control-plane traffic.
Eliminating Manual Target Management for Worker Nodes
When deploying NodePort or LoadBalancer services across a cluster of worker nodes, LB Categories simplify the backend setup:
- Dynamic Service Mapping: Instead of manually entering individual node IPs, the supported configuration can identify Flow LB targets by category and port, such as
<category>:<nodeport>. - Category-based Traffic Distribution: After a worker-node VM receives the target category and the configured health checks pass, Flow LB can include it in the target group and route traffic to it. This can avoid manually entering individual backend IP addresses in the load balancer; the relevant NodePort and health-check configuration must still be defined and available on the targets.
- Clean Layering: Flow LB manages external IP allocation, advertisement, and top-level traffic distribution. Once traffic reaches a node, depending on the service configuration, kube-proxy or the selected Kubernetes networking implementation routes traffic from the node toward the appropriate pod replicas.
Streamlining Control Plane & Cluster API (CAPI) Deployment
When deploying Kubernetes clusters using CAPI and CAPX (Nutanix provider for Cluster API), LB Categories simplify API server high availability:
- No In-Guest Plumbing: Depending on the supported bootstrap configuration and Flow LB capabilities, this design may avoid embedding kube-vip or similar software inside the control-plane VM templates.
- Pre-Provisioned Routing: Simply create a Flow LB instance pointing to your control plane category before kicking off the CAPI deployment.
- Transparent Scaling: As new control plane VMs launch, they automatically join the target group of the LB. The CAPI controller can communicate with the API server through the configured load-balancing path, subject to the bootstrap sequence, health checks, and supported deployment configuration.
Unlocking Fully Automated, Cloud-Native Workflows
By reducing dependence on manually maintained static IP target lists:
- LB creation can be embedded directly into controllers (like CAPX)
- Cluster API & CAPX Controller Automation: When using Cluster API with the Nutanix provider, category tagging may be handled by the provider or by an accompanying provisioning workflow, depending on the supported release and integration. As CAPI scales out worker node pools, CAPX dynamically assigns the required load balancer category tags to every newly spawned VM.
- Automated CI/CD Pipeline Hooks: In automated deployment pipelines (such as GitHub Actions workflows, GitLab CI/CD pipelines, or Jenkins automation pipelines), post-provisioning steps can invoke Nutanix Prism APIs to dynamically assign or validate category tags on new node instances before they join the cluster.
- Automated Target Group Expansion: Since Flow Load Balancers actively monitor category memberships, any newly categorized worker-node VM automatically begins receiving traffic as soon as its NodePort and health checks pass, completely eliminating manual load balancer reconfigurations.
- On-premises Kubernetes deployments can support a more declarative, cloud-like operational workflow.
How to create Categories in Prism Central?
Setting up a Category in Nutanix Prism Central is straightforward. The following workflow is based on the linked Nutanix documentation and should be verified against the target Prism Central and Flow Virtual Networking releases:
- Access Admin Center: Log in to your Prism Central instance. From the Application Switcher menu in the upper-left corner, select Admin Center.
- Navigate to Categories: In the left navigation bar, select Categories to open the Categories List page, which displays all existing system-defined and user-defined categories.
- Initiate Category Creation: Click the New Category button in the top corner to open the Create Category drawer or form.
- Define Key, Values, and Purpose.
- Save and Assign: Click Save. Once created, navigate to your target VMs (such as Kubernetes worker or control plane nodes), select Manage Categories from the Actions dropdown, and assign the newly created category value.
Configuring Flow Load Balancer Targets Using LB Categories
Once your VPC subnet and Load Balancer listener (e.g., TCP:443) are configured, follow these steps to dynamically attach your newly provisioned node pool VMs to the load balancer session using Nutanix Categories:
- Select Category-Based Target Selection
- Under the Targets step of the Create Load Balancer Session wizard, set the VM NIC Selection Method dropdown to Select VM NICs from VMs in Categories.
- Click the + Add Categories button to launch the category selection overlay.
- Select and Verify the Kubernetes Cluster Category
- In the Add Category modal, search for your cluster's category tag (e.g., search for kuber or your specific cluster name).
- Locate the row corresponding to the example cluster category, such as
KubernetesClusterName: nkp5; category names and values will vary by environment - (Optional) Click View VMs next to the category to verify that your newly added worker node VMs are properly detected:
- In the example environment shown below, clicking View VMs displays the two active nodes (nkp5-worker-0) with IPs 172.x.x.106 and 172.x.x.161 assigned to the cris1 target subnet inside the cris-vpc.
- Complete Target Assignment
- Check the box next to
KubernetesClusterName: nkp5. - Click Add to attach all VM NICs carrying this category to the Load Balancer target group.
- Complete the health check settings and proceed to the Preview step to finalize creating the Load Balancer session.
- Check the box next to
- Why This Approach Works Best: By targeting the
KubernetesClusterName: nkp5category instead of explicitly selecting static VM IPs:- Dynamic Scaling: Any future worker nodes added to the nkp5 pool will automatically join the load balancer target group as soon as they receive the category tag,no manual load balancer reconfiguration is required.
- Resilience: If a worker VM is deleted or replaced, Flow LB dynamically updates its active backends without downtime.
Conclusion
LB Categories bridge the gap between static enterprise infrastructure and dynamic, cloud-native Kubernetes workloads. By shifting from IP-based routing to tag-based dynamic target selection, you can reduce manual networking configuration, simplify Cluster API deployments, and build a resilient infrastructure layer that scales automatically alongside your applications.
©2026 Nutanix, Inc. All rights reserved. Nutanix, the Nutanix logo and all Nutanix product and service names mentioned are registered trademarks or trademarks of Nutanix, Inc. in the United States and other countries. Kubernetes is a registered trademark of The Linux Foundation in the United States and other countries. All other brand names mentioned are for identification purposes only and may be the trademarks of their respective holder(s).