16 ms·
It's a pain because kubernetes is designed to run multiple workloads on multiple servers. So if you want to access the VPN from some kubernetes containers you'r
by beeboobaa3 2y ago
It's a pain because kubernetes is designed to run multiple workloads on multiple servers. So if you want to access the VPN from some kubernetes containers you're going to have to figure something out.
But nothing is stopping you from just joining all your hosts into the VPN, just like a traditional deployment. Or set it up on your network gateway. This would make it available to all of your containers. Great. You're done.
But if that's not what you want, you'll need to figure something out.
- Etheryte 2y agoI'm not sure if I follow. You said Kubernetes is great for building any kind of a platform, but then when someone wants controlled access to a VPN it suddenly turns into a no, not like that? Giving only certain parts of your architecture access to certain capabilities is far from a niche use case.
- themgt 2y agoGiving only certain parts of your architecture access to certain capabilities is far from a niche use case What is the "normal" best practice here then? I would just spin up multiple single-node k3s VM clusters and hook the AI k3s VM to the VPN and the others not.
- beeboobaa3 2y ago> You said Kubernetes is great for building any kind of a platform I didn't, that was someone else. I wouldn't say any kind of platform, but it is a great foundation for many platforms. > it suddenly turns into a no, not like that Not at all. Read my post and the OP again! Several valid solutions have been offered, some that work out of the box, some that require a little tinkering. If you want to do a traditional VM deployment you'd segment your workloads per hosts and put some hosts in the VPN. Sure. Cool. You can do exactly the same with kubernetes with node pools. Only when you want to have some workloads that have access and some that don't running on the same host machine you might need to do some tinkering. Just like you'd have to do otherwise. Kubernetes really changes nothing, other than giving you ways to deal with it. Of course there's plenty of ready built solutions for this you can just plug in, too. Search for Service Mesh.