This guide covers two steps required on an Windows Server 2022 instance before running the Nirmata enrollment script (Prepare-WindowsWorkerNode.ps1).
Run all commands in an elevated PowerShell session (Run as Administrator).
1. Install OpenSSH
Option A: Install via Windows Update (recommended)
If the instance can reach Windows Update, use the built-in capability command:
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0
Option B: Install directly from GitHub (if Windows Update is not reachable)
In case the instance cannot reach Windows Update, download and install OpenSSH directly from GitHub.
-
Download the OpenSSH release archive.
Invoke-WebRequest ` -Uri "https://github.com/PowerShell/Win32-OpenSSH/releases/download/v9.5.0.0p1-Beta/OpenSSH-Win64.zip" ` -OutFile "$env:TEMP\openssh.zip" ` -UseBasicParsing -
Extract the archive.
Expand-Archive "$env:TEMP\openssh.zip" -DestinationPath "C:\Program Files\OpenSSH" -
Run the installer script.
& "C:\Program Files\OpenSSH\OpenSSH-Win64\install-sshd.ps1" -
Start the service and set it to start automatically.
Start-Service sshd Set-Service -Name sshd -StartupType Automatic -
Verify the service is running.
Get-Service sshd # Expected: Status = Running
Note: OpenSSH is not required for the Nirmata host agent, which communicates over WebSocket. Install it only if your environment requires SSH access to the node.
2. Install and Set Up vmcompute and Hypervisor Service for Containers
Windows containers require two Windows features to be enabled: Containers (the container runtime support) and HypervisorPlatform (which provides the Hyper-V Host Compute Service, vmcompute). These may be absent even on instances launched from the same AMI.
Check current state
Before making changes, verify whether the services are already present.
Get-Service vmcompute -ErrorAction SilentlyContinue
Test-Path "C:\Windows\System32\vmcompute.dll"
Get-WindowsOptionalFeature -Online -FeatureName Containers
Get-WindowsOptionalFeature -Online -FeatureName HypervisorPlatform
If vmcompute is running, vmcompute.dll exists, and both features show State: Enabled, skip to the enrollment script. Otherwise continue with the steps below.
Enable the Windows Containers feature
-
Enable the
Containersfeature.dism /online /enable-feature /featurename:Containers /all /norestart -
Enable the
HypervisorPlatformfeature.dism /online /enable-feature /featurename:HypervisorPlatform /all /norestartAn exit code of
3010from either command means the feature was enabled and a reboot is required. -
Reboot the instance.
Restart-Computer -Force
Start and configure the vmcompute service
-
After the instance restarts, start the
vmcomputeservice and set it to start automatically.Start-Service vmcompute Set-Service -Name vmcompute -StartupType Automatic -
Verify the service and DLL are present.
Get-Service vmcompute # Expected: Status = Running Test-Path "C:\Windows\System32\vmcompute.dll" # Expected: True
Note: If
Start-Service vmcomputefails after reboot, confirm thatHypervisorPlatformis enabled and the instance type supports nested virtualization. On AWS, use a metal or Hyper-V capable instance type (e.g.,m5.metal,c5n.metal).
The instance is now ready for the Nirmata enrollment script.
3. Required Artifacts
The following binaries and container images are needed to enroll a Windows Server 2022 node into a Nirmata-managed Kubernetes cluster.
Binaries
| Artifact | Default Source |
|---|---|
containerd-{version}-windows-amd64.tar.gz |
https://github.com/containerd/containerd/releases/download/v{version}/ |
kubelet.exe |
https://dl.k8s.io/v{version}/bin/windows/amd64/kubelet.exe |
nssm.exe |
Served by Nirmata — no override needed |
agent.exe |
Served by Nirmata — no override needed |
Container Images
Images are pulled by containerd on the Windows node when Nirmata deploys the Windows DaemonSets.
| Image | Registry | Tag | Purpose |
|---|---|---|---|
pause |
registry.k8s.io |
3.9-windows-amd64 |
Pod sandbox (infra container for every pod) |
calico/cni-windows |
docker.io |
v3.27.0 |
Calico CNI init container |
calico/node-windows |
docker.io |
v3.27.0 |
Calico node DaemonSet |
sigwindowstools/kube-proxy |
docker.io |
v{k8s-version}-calico-hostprocess |
kube-proxy HostProcess DaemonSet |
Note: Replace
{k8s-version}with the Kubernetes version of the cluster (e.g.v1.33.0).
Air-gap Mirror Layout
For air-gapped environments using a private registry, images must be stored flat (no vendor prefix) under the registry base path:
{PrivateRegistry}/pause:3.9-windows-amd64
{PrivateRegistry}/calico/cni-windows:v3.27.0
{PrivateRegistry}/calico/node-windows:v3.27.0
{PrivateRegistry}/sigwindowstools/kube-proxy:v1.33.0-calico-hostprocess
Component Versions
| Component | Version |
|---|---|
| Kubernetes | 1.33.0 |
| containerd | 1.7.23 |
| Calico | v3.27.0 |
| Pause image | 3.9-windows-amd64 |
| Host agent image tag | 4.24.0 |