# rancher/rke2

Repository: https://github.com/rancher/rke2
Canonical: https://ross.abutalabs.com/products/rke2
Homepage: https://docs.rke2.io/
Language: Go
License: Apache-2.0
License Family: permissive
Last push: 2026-08-26T18:35:25+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 84, longevity 100
- inputs: {"age_days": 2339, "days_push": 7, "days_rel": 29, "gap_med": 0, "n_releases_24m": 100}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2325, forks 353 (observed 2026-08-28T04:06:37.420286+00:00)

## What it is
RKE2 (RKE Government) is Rancher's fully conformant, next-generation Kubernetes distribution focused on security and compliance, particularly for the U.S. Federal Government sector. It combines K3s's ease of deployment with RKE1's upstream alignment, using containerd as the embedded runtime and offering CIS Benchmark defaults, FIPS 140-2 compliance, and SELinux/MCS support.

## Use cases
- deploy a secure kubernetes cluster on linux servers
- run kubernetes that passes the CIS benchmark with minimal configuration
- set up a FIPS 140-2 compliant kubernetes distribution
- install kubernetes as a systemd service with a simple script
- provision kubernetes clusters managed by Rancher
- harden container images with CVE scanning in the build pipeline
- replace RKE1 or K3s for datacenter kubernetes deployments

## When to choose
- you need a fully conformant kubernetes distribution with strong security and compliance defaults (CIS, FIPS, SELinux)
- you want kubernetes that stays closely aligned with upstream rather than edge-optimized like K3s
- you operate in government or regulated sectors with heightened security requirements
- you want simple systemd-based installation and operation with Rancher integration

## When to avoid
- you need a lightweight edge or IoT kubernetes where K3s is more appropriate
- you require FIPS compliance on Windows or s390x architectures
- you want to run control plane components via Docker as in RKE1
- you need a managed kubernetes service rather than self-hosted infrastructure

## Facets
- artifact type: application
- maturity: active
- function: container-orchestration, security, deployment, self-hosted
- domain: cloud-computing, security, infrastructure-as-code
- platform: go, self-hosted
- tags: kubernetes-distribution, rke2, rancher, cis-benchmark, fips, selinux, containerd, government-compliance, devops, containers, linux, docker

## Member repositories
- rancher/rke2 (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:37.420286+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:38:24.691089+00:00, confidence not recorded.
  - readme: https://github.com/rancher/rke2 (fetched 2026-08-28T04:06:37.420286+00:00, sha 0a04420ad581)
  - homepage: https://docs.rke2.io/ (fetched 2026-08-29T10:18:45.525154+00:00, sha 80b39a495308)
  - site_page: https://docs.rke2.io/install/quickstart (fetched 2026-08-29T10:18:45.534659+00:00, sha cea4b74bb878)
  - site_page: https://docs.rke2.io/security/about_hardened_images (fetched 2026-08-29T10:18:45.536773+00:00, sha b35f57ccb544)
- Data as of 2026-08-30T08:39:29.467469+00:00.
