4 ms·
It's handy to allow my teammate onto my kubernetes cluster without having to ask him for his public key.
by MathMonkeyMan 4y ago
It's handy to allow my teammate onto my kubernetes cluster without having to ask him for his public key.
- ofrzeta 4y agoWhere's the ssh server running in the cluster?
- MathMonkeyMan 4y agoon each node
- ofrzeta 4y agoOk, and then the users have root permissions to interact with the containers? Forgive me for asking but I am thinking about solving similar problems (access to containers via ssh) .. or maybe I should use Teleport instead.
- mschuster91 4y agoYou usually only need this to do extremely low-level debugging in k8s, or to do generic system maintenance (e.g. OS upgrade). Your average devops person? They will be happy when given a kubeconfig file linked to a role allowing them "kubectl exec" access to the workloads.
- MathMonkeyMan 4y agoGood point. These are test clusters that we use to reproduce customer issues. They usually have three or even just one node. It is in no way a production environment.