Prerequisites

This guide covers two steps required on an Windows Server 2022 instance before running the Nirmata enrollment script (Prepare-WindowsWorkerNode.ps1).

Run all commands in an elevated PowerShell session (Run as Administrator).

1. Install OpenSSH

Option A: Install via Windows Update (recommended)

If the instance can reach Windows Update, use the built-in capability command:

Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0

Option B: Install directly from GitHub (if Windows Update is not reachable)

In case the instance cannot reach Windows Update, download and install OpenSSH directly from GitHub.

  1. Download the OpenSSH release archive.

    Invoke-WebRequest `
      -Uri "https://github.com/PowerShell/Win32-OpenSSH/releases/download/v9.5.0.0p1-Beta/OpenSSH-Win64.zip" `
      -OutFile "$env:TEMP\openssh.zip" `
      -UseBasicParsing
    
  2. Extract the archive.

    Expand-Archive "$env:TEMP\openssh.zip" -DestinationPath "C:\Program Files\OpenSSH"
    
  3. Run the installer script.

    & "C:\Program Files\OpenSSH\OpenSSH-Win64\install-sshd.ps1"
    
  4. Start the service and set it to start automatically.

    Start-Service sshd
    Set-Service -Name sshd -StartupType Automatic
    
  5. Verify the service is running.

    Get-Service sshd
    # Expected: Status = Running
    

Note: OpenSSH is not required for the Nirmata host agent, which communicates over WebSocket. Install it only if your environment requires SSH access to the node.

2. Install and Set Up vmcompute and Hypervisor Service for Containers

Windows containers require two Windows features to be enabled: Containers (the container runtime support) and HypervisorPlatform (which provides the Hyper-V Host Compute Service, vmcompute). These may be absent even on instances launched from the same AMI.

Check current state

Before making changes, verify whether the services are already present.

Get-Service vmcompute -ErrorAction SilentlyContinue
Test-Path "C:\Windows\System32\vmcompute.dll"
Get-WindowsOptionalFeature -Online -FeatureName Containers
Get-WindowsOptionalFeature -Online -FeatureName HypervisorPlatform

If vmcompute is running, vmcompute.dll exists, and both features show State: Enabled, skip to the enrollment script. Otherwise continue with the steps below.

Enable the Windows Containers feature

  1. Enable the Containers feature.

    dism /online /enable-feature /featurename:Containers /all /norestart
    
  2. Enable the HypervisorPlatform feature.

    dism /online /enable-feature /featurename:HypervisorPlatform /all /norestart
    

    An exit code of 3010 from either command means the feature was enabled and a reboot is required.

  3. Reboot the instance.

    Restart-Computer -Force
    

Start and configure the vmcompute service

  1. After the instance restarts, start the vmcompute service and set it to start automatically.

    Start-Service vmcompute
    Set-Service -Name vmcompute -StartupType Automatic
    
  2. Verify the service and DLL are present.

    Get-Service vmcompute
    # Expected: Status = Running
    
    Test-Path "C:\Windows\System32\vmcompute.dll"
    # Expected: True
    

Note: If Start-Service vmcompute fails after reboot, confirm that HypervisorPlatform is enabled and the instance type supports nested virtualization. On AWS, use a metal or Hyper-V capable instance type (e.g., m5.metal, c5n.metal).

The instance is now ready for the Nirmata enrollment script.

3. Required Artifacts

The following binaries and container images are needed to enroll a Windows Server 2022 node into a Nirmata-managed Kubernetes cluster.

Binaries

Artifact Default Source
containerd-{version}-windows-amd64.tar.gz https://github.com/containerd/containerd/releases/download/v{version}/
kubelet.exe https://dl.k8s.io/v{version}/bin/windows/amd64/kubelet.exe
nssm.exe Served by Nirmata — no override needed
agent.exe Served by Nirmata — no override needed

Container Images

Images are pulled by containerd on the Windows node when Nirmata deploys the Windows DaemonSets.

Image Registry Tag Purpose
pause registry.k8s.io 3.9-windows-amd64 Pod sandbox (infra container for every pod)
calico/cni-windows docker.io v3.27.0 Calico CNI init container
calico/node-windows docker.io v3.27.0 Calico node DaemonSet
sigwindowstools/kube-proxy docker.io v{k8s-version}-calico-hostprocess kube-proxy HostProcess DaemonSet

Note: Replace {k8s-version} with the Kubernetes version of the cluster (e.g. v1.33.0).

Air-gap Mirror Layout

For air-gapped environments using a private registry, images must be stored flat (no vendor prefix) under the registry base path:

{PrivateRegistry}/pause:3.9-windows-amd64
{PrivateRegistry}/calico/cni-windows:v3.27.0
{PrivateRegistry}/calico/node-windows:v3.27.0
{PrivateRegistry}/sigwindowstools/kube-proxy:v1.33.0-calico-hostprocess

Component Versions

Component Version
Kubernetes 1.33.0
containerd 1.7.23
Calico v3.27.0
Pause image 3.9-windows-amd64
Host agent image tag 4.24.0