16 ms·
It's really not that hard if you got proper users. But doing proper users on k8s is hard. I suspect they just run with admin credentials and no real way to gen
by ongy 3y ago
It's really not that hard if you got proper users.
But doing proper users on k8s is hard. I suspect they just run with admin credentials and no real way to generate users.
- vbezhenar 3y agoFor small cluster you can just create service account for a user, create token for it and write it in the kubeconfig. Then assign role to this service account and that's about it. The main issue with this approach is that you can't organize those "users" into a groups. But for a small number of users you can just create all rolebindings and be done with it.
- ongy 3y agoYes. I was thinking of that for a moment as well. But it requires some understanding and is annoying in various ways. I should look into how to provision users at some point. but OTOH GKE takes care of it for our prod, and other clusters can be run with just admin.