Install the prerequisite applications on each Tanzu Kubernetes cluster where you plan to install one or more TKG Extensions v1.3.1.

TKG Extensions v1.3.1 require two prerequisite components: Kapp Controller and Cert Manager.
Note: As an alternative to Cert Manager you can use your own TLS certificates. See Use Your Own TLS Certificate for TKG Extensions.



  1. Download the TKG Extensions v1.3.1 Bundle.
  2. Change directory to the directory where kapp-controler.yaml is available.
    cd /tkg-extensions/extensions
  3. Install Kapp Controller on the cluster.
    kubectl apply -f kapp-controller.yaml
    Note: The spec.containers.image path points to the public VMware registry for kapp-controller. For air-gapped installations, update this path to point to your private registry.
    This operation creates the tkg-system namespace, kapp-controller, and role objects.
  4. Install Cert Manager on the cluster.
    Cert Manager includes several components. There are three YAML files to install all the components. These files are in the /tkg-extensions/cert-manager folder. Install Cert Manager components with a single command by specifying the root directory.
    cd /tkg-extensions
    kubectl apply -f cert-manager/
    This operation creates the cert-manager namespace, components, certificates, and associated objects.
  5. Verify installation of the prerequisites.
    Run the command kubectl get pods -A. You should see each are running.
    cert-manager       cert-manager-cainjector-...    1/1     Running    0      7h54m
    cert-manager       cert-manager-...               1/1     Running    0      7h54m
    cert-manager       cert-manager-webhook-...       1/1     Running    0      7h54m
    tkg-system         kapp-controller-...            1/1     Running    0      16m