Rancher is a free, open-source web dashboard for running Kubernetes. Once your services run on a Kubernetes cluster, Rancher lets you see every workload, scale it, roll out a new image, roll back and read logs from a browser instead of typing kubectl commands. This guide installs Rancher on your own Linux server or VPS, imports an existing cluster such as k3s, and covers day-to-day management of a deployed service.
Rancher and Kubernetes need root access and a server of your own. They can't run on cPanel, DirectAdmin or Webuzo shared hosting. Everything below applies to a VPS or dedicated server that you manage yourself.
For anything beyond a quick test, install Rancher with Helm onto a Kubernetes cluster (k3s works well on one VPS): add cert-manager, then install the rancher chart with your hostname and a Let's Encrypt certificate. The single docker run rancher/rancher command still exists, but Rancher supports it only for testing and development. Once Rancher is up, import your application cluster from Cluster Management → Import Existing, then scale, update and roll back deployments from the dashboard.
1. What Rancher does, and when you need it
Kubernetes runs your containers; Rancher is a management layer on top. It is most useful when:
- you look after more than one cluster, or want a team to manage deployments without handing out cluster-admin credentials;
- you want a visual view of workloads, pods, logs and events;
- you want role-based access, so a developer can redeploy one app but not touch the rest.
If you run one small k3s cluster alone, kubectl and Helm may be all you need. Rancher adds memory use and one more system to keep updated.
2. What you need
- A Linux server with root access, running a current distribution such as Ubuntu LTS, Debian, AlmaLinux or Rocky Linux. CentOS 7 and CentOS Linux 8 are end of life; don't build new servers on them.
- Enough memory. Rancher itself is memory-hungry. As a starting point, give the server running Rancher 8 GB of RAM or more, especially if your applications run on the same node. Check the current requirements in the Rancher documentation before you size production servers.
- A hostname, such as
rancher.yourbusiness.in, with an A record pointing to the server's public IP address. Rancher uses this name for its certificate and for connecting clusters. kubectland Helm on the server or on your computer.
3. Install Rancher on k3s with Helm (recommended)
This puts Rancher on a single-node k3s cluster. Rancher supports only certain Kubernetes versions, so check the Rancher support matrix first and install a matching k3s version.
- Install k3s, pinning a version Rancher supports: `curl -sfL https://get.k3s.ioINSTALL_K3S_VERSION=VERSION sh -
, replacing VERSION with a supported k3s release. Then check withsudo k3s kubectl get nodes`. - Point kubectl and Helm at the cluster:
export KUBECONFIG=/etc/rancher/k3s/k3s.yaml(as root), or copy that file to~/.kube/configfor your user. - Install cert-manager, which Rancher uses to obtain certificates.
- Install the Rancher chartwith your hostname, a bootstrap password and Let's Encrypt.
- Wait for the rollout,then open
https://rancher.yourbusiness.in.
Steps 3 and 4 as commands:
# cert-manager
helm repo add jetstack https://charts.jetstack.io
helm repo update
helm install cert-manager jetstack/cert-manager \
--namespace cert-manager --create-namespace \
--set crds.enabled=true
# Rancher
helm repo add rancher-stable https://releases.rancher.com/server-charts/stable
helm repo update
kubectl create namespace cattle-system
helm install rancher rancher-stable/rancher \
--namespace cattle-system \
--set hostname=rancher.yourbusiness.in \
--set bootstrapPassword='choose-a-long-random-password' \
--set ingress.tls.source=letsEncrypt \
--set [email protected] \
--set letsEncrypt.ingress.class=traefik
kubectl -n cattle-system rollout status deploy/rancherk3s ships with the Traefik ingress controller, which is why the ingress class is traefik. Let's Encrypt can issue the certificate only if the hostname already resolves to the server and ports 80 and 443 are open.
On first login, Rancher asks for the bootstrap password, then makes you set a new admin password and confirm the server URL. If you didn't set a bootstrap password, read the generated one with:
kubectl get secret --namespace cattle-system bootstrap-secret \
-o go-template='{{.data.bootstrapPassword|base64decode}}{{"\n"}}'4. The quick Docker install (testing only)
For a throwaway lab, Rancher still runs as a single container on a server that has Docker:
docker run -d --restart=unless-stopped \
-p 80:80 -p 443:443 --privileged \
rancher/rancher:<version>
docker logs <container-id> 2>&1 | grep "Bootstrap Password:"Rancher supports the single-container install only for testing and development. It needs --privileged, it takes ports 80 and 443 (so it clashes with the Traefik ingress if k3s runs on the same server) and it can't be moved to a proper Helm install later. Pin a version tag instead of latest.
5. Import your application cluster
If your services run on a separate cluster, for example the one from Deploying the user service with Kubernetes, bring it into Rancher:
- Open Cluster Managementfrom the menu (☰) in Rancher.
- Click Import Existingand choose Generic.
- Name the clusterand click Create.
- Copy the registration commandRancher shows. It is a
kubectl apply -f https://…line containing a one-time token. - Run it against the cluster you are importing, with a kubeconfig that has cluster-admin rights. If Rancher's certificate isn't publicly trusted yet, Rancher shows an alternative `curl --insecure …kubectl apply -f -` command; use it only on a network you trust.
- Wait for Active.The cluster appears in Cluster Management and turns Active once its agent connects.
The imported cluster's agent connects out to Rancher over HTTPS, so the Rancher hostname must be reachable from that cluster.
6. Manage your deployments
Open the cluster, then Workloads → Deployments, and choose the namespace your service runs in.
| Task | In Rancher | kubectl equivalent |
|---|---|---|
| Check health | Deployment shows ready pods, restarts and events | kubectl get deploy,pods -n NAMESPACE |
| Scale | Change the replica count with the + and − controls | kubectl scale deploy/NAME --replicas=3 |
| Update the image | Edit Config, change the container image tag, Save | kubectl set image deploy/NAME CONTAINER=IMAGE:TAG |
| Roll back | Open the deployment's menu and roll back to an earlier revision | kubectl rollout undo deploy/NAME |
| Read logs | Pod menu, View Logs | kubectl logs deploy/NAME |
| Open a shell | Pod menu, Execute Shell | kubectl exec -it POD -- sh |
Rolling updates replace pods gradually, so a service with at least two replicas and a readiness probe stays online during an update. Always deploy a new, specific image tag (user-service:1.2) rather than overwriting latest, so a rollback returns to a known version.
7. Secure and maintain your Rancher server
- Protect the Kubernetes API. Don't expose port 6443 to the whole internet. Allow it only from addresses that need it, using your server's firewall.
- Use strong admin credentials and create separate Rancher users with limited roles for your team.
- Back up Rancher. The Rancher Backups app can back up its configuration; on k3s, also back up the cluster datastore. Snapshots of the VPS are a useful extra layer, not a replacement.
- Upgrade in order. Upgrade Rancher with
helm upgrade, one supported version at a time, and keep Kubernetes within the support matrix.
8. Running Rancher on a Domain India VPS
Domain India VPS plans are KVM virtual servers with full root access, and are self-managed: you install and look after Kubernetes, Rancher and your applications yourself. A VPS can run Docker and Kubernetes. For a Rancher server with a small application cluster on the same node, choose a plan with 8 GB of RAM or more. A 4 GB plan suits k3s with a few services if you manage it with kubectl alone.
- 4 vCPU
- 8 GB DDR4 RAM
- 256 GB NVMe SSD Storage
- 5 TB Monthly Bandwidth
- 2 vCPU
- 4 GB DDR4 RAM
- 128 GB NVMe SSD Storage
- 3 TB Monthly Bandwidth
If you don't want to run Kubernetes at all, the App Platform builds and runs your app from GitHub or a deploy token, with no servers to manage. For a lighter Kubernetes setup on one VPS, read Lightweight Kubernetes with k3s and Helm charts for beginners.
Frequently asked questions
Is Rancher free?
Yes. Rancher is open-source software you can install at no cost on your own server. Paid support subscriptions are sold separately by its vendor, SUSE.
Can I install Rancher on shared hosting?
No. Rancher and Kubernetes need root access and a server of your own. Use a VPS or a dedicated server.
Should I install Rancher with Docker or with Helm?
Use Helm on a Kubernetes cluster such as k3s for anything you rely on. The single Docker container install is supported only for testing and development and can't be upgraded into a production install.
How much RAM does Rancher need?
Rancher is memory-hungry. Plan for 8 GB of RAM or more on the server that runs it, more if your applications share that node, and check the current Rancher documentation for production sizing.
How do I add an existing Kubernetes cluster to Rancher?
In Rancher open Cluster Management, click Import Existing, choose Generic, name the cluster and click Create. Then run the kubectl command Rancher shows against the cluster you are importing.
Does Domain India manage Rancher or Kubernetes for me?
No. Domain India VPS plans are self-managed, so you install, secure and update Rancher and Kubernetes yourself. If you would rather not manage servers, the App Platform runs your app for you.
Ready to run your own cluster? Compare VPS plans, or open a support ticket if you're unsure which size fits your workload.
KVM virtual servers with full root access, NVMe storage and your choice of Linux.
See VPS plans