3 ms·
Has anyone had success using WireGuard to VPN into their cluster and have local access to pods via K8s DNS?
by erikcw 5y ago
Has anyone had success using WireGuard to VPN into their cluster and have local access to pods via K8s DNS?
- hobofan 5y agoNot plain Wireguard, but I've set up Tailscale with a proxy container + their MagicDNS pointed towards the kube-dns pod (running on GKE Autopilot). It works like a dream and was dirt simple to set up, but would probably require some additional work once you go beyond one cluster (which I think is true for cross-cluster service discovery regardless in Kubernetes).
- craftkiller 5y agoYes, at my startup we run https://github.com/Place1/wg-access-server https://github.com/Place1/wg-access-server inside our kubernetes clusters to give engineers access to local pods vs the k8s DNS (*.svc.cluster.local). It works relatively well but we've had to make a couple modifications: 1. I had to deploy CoreDNS to our cluster and set up DNS query rewriting to redirect queries from *.cluster.mystartup to *.svc.cluster.local because docker on OS X has issues resolving hostnames that end in .local 2. I had to modify the code to support a non-standard MTU to deal with a networking issue related to google cloud.