accessing each pod in a cluster over the api











up vote
1
down vote

favorite












I have a deployment layout where there would be various pods (each pod dedicated for each user has a service listens on a particular port). I need to give customer access to their pod directly without revealing the specific port and other secure stuff like cluster certificate details to the user of each pod. Should I go about over vs the other or would it even work?



a) How can I do that over the api server ?

b) Can I create a custom pod access service with a custom certificate to handle all pod access requests.

c) Or do I need a CNI plugin to assign each pod a public ip hosting everything on a cloud vpc?










share|improve this question






















  • If you provide a direct access to the pod then what would stop the user from getting information about cluster ip/port and certificates? You have to limit the access to a user or an area, maybe a jail.
    – Crou
    19 hours ago















up vote
1
down vote

favorite












I have a deployment layout where there would be various pods (each pod dedicated for each user has a service listens on a particular port). I need to give customer access to their pod directly without revealing the specific port and other secure stuff like cluster certificate details to the user of each pod. Should I go about over vs the other or would it even work?



a) How can I do that over the api server ?

b) Can I create a custom pod access service with a custom certificate to handle all pod access requests.

c) Or do I need a CNI plugin to assign each pod a public ip hosting everything on a cloud vpc?










share|improve this question






















  • If you provide a direct access to the pod then what would stop the user from getting information about cluster ip/port and certificates? You have to limit the access to a user or an area, maybe a jail.
    – Crou
    19 hours ago













up vote
1
down vote

favorite









up vote
1
down vote

favorite











I have a deployment layout where there would be various pods (each pod dedicated for each user has a service listens on a particular port). I need to give customer access to their pod directly without revealing the specific port and other secure stuff like cluster certificate details to the user of each pod. Should I go about over vs the other or would it even work?



a) How can I do that over the api server ?

b) Can I create a custom pod access service with a custom certificate to handle all pod access requests.

c) Or do I need a CNI plugin to assign each pod a public ip hosting everything on a cloud vpc?










share|improve this question













I have a deployment layout where there would be various pods (each pod dedicated for each user has a service listens on a particular port). I need to give customer access to their pod directly without revealing the specific port and other secure stuff like cluster certificate details to the user of each pod. Should I go about over vs the other or would it even work?



a) How can I do that over the api server ?

b) Can I create a custom pod access service with a custom certificate to handle all pod access requests.

c) Or do I need a CNI plugin to assign each pod a public ip hosting everything on a cloud vpc?







kubernetes






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Nov 10 at 14:38









kahmed

462




462












  • If you provide a direct access to the pod then what would stop the user from getting information about cluster ip/port and certificates? You have to limit the access to a user or an area, maybe a jail.
    – Crou
    19 hours ago


















  • If you provide a direct access to the pod then what would stop the user from getting information about cluster ip/port and certificates? You have to limit the access to a user or an area, maybe a jail.
    – Crou
    19 hours ago
















If you provide a direct access to the pod then what would stop the user from getting information about cluster ip/port and certificates? You have to limit the access to a user or an area, maybe a jail.
– Crou
19 hours ago




If you provide a direct access to the pod then what would stop the user from getting information about cluster ip/port and certificates? You have to limit the access to a user or an area, maybe a jail.
– Crou
19 hours ago

















active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














 

draft saved


draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53240008%2faccessing-each-pod-in-a-cluster-over-the-api%23new-answer', 'question_page');
}
);

Post as a guest





































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes
















 

draft saved


draft discarded



















































 


draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53240008%2faccessing-each-pod-in-a-cluster-over-the-api%23new-answer', 'question_page');
}
);

Post as a guest




















































































Popular posts from this blog

Bressuire

Vorschmack

Quarantine