Rancher: one control point for many clusters
Rancher is a management plane for Kubernetes fleets. A Rancher server runs in its own cluster and provides a UI and API, central authentication and RBAC, and lifecycle management. It can provision RKE2 or k3s clusters on your infrastructure, and it can import existing clusters such as GKE and EKS so that access and policy are managed in one place while the cloud provider continues to run the control plane.
Downstream clusters connect to Rancher through an agent that makes an outbound connection to the management server. That matters for locations such as the warehouse sites: they only need outbound connectivity, with no inbound ports exposed. Reveal the downstream clusters with the right arrow.
Fleet, Rancher's GitOps engine, applies Git repositories to groups of clusters. Combined with labels (for example region=eu, role=warehouse), a single repository can deliver different configuration to different clusters. Other GitOps tools such as Argo CD are also common; the right choice depends on your team.
Important property: downstream clusters are ordinary Kubernetes clusters. kubectl works against them directly and removing Rancher does not delete them, although you lose central management. Deck 4 covers Rancher provisioning, RKE2 and k3s architecture, MetalLB and air-gapped installs in depth.