Orchestrator control plane

The control plane can schedule any workload on any node, which makes it the most powerful component in the platform.

Reaching it means being able to run code wherever you like with whatever permissions you choose. It should be isolated from the workloads it manages, which is the same principle as separating any control plane from what it controls, and it is frequently reachable from inside the cluster.

Checked against the primary source.

More on Containers & Kubernetes