

Kubeconfig Operator
This controller implements a Kubeconfig custom resource to generate a kubeconfig file with a specified set of permissions.
The following example creates a kubeconfig limited to
- read access for namespaces
- read access for configmaps in namespace: kube-system
- read/write access for configmaps in namespace: default
Quickstart
Install the operator:
kubectl apply -k "github.com/klaudworks/kubeconfig-operator/manifests/base?ref=v1.0.12"
Then, apply the following Kubeconfig:
apiVersion: klaud.works/v1alpha1
kind: Kubeconfig
metadata:
name: restricted-access
spec:
clusterName: local-kind-cluster
# specify external endpoint to your kubernetes API.
# You can copy this from your other kubeconfig.
server: https://127.0.0.1:52856
clusterPermissions:
rules:
- apiGroups:
- ""
resources:
- namespaces
verbs:
- get
- list
- watch
namespacedPermissions:
- namespace: default
rules:
- apiGroups:
- ""
resources:
- configmaps
verbs:
- '*'
- namespace: kube-system
rules:
- apiGroups:
- ""
resources:
- configmaps
verbs:
- get
- list
- watch
After applying the Kubeconfig custom resource, you can find the actual kubeconfig yaml in a secret restricted-access-kubeconfig.
Extract and store the kubeconfig as follows:
kubectl get secret restricted-access-kubeconfig -o jsonpath="{.data.kubeconfig}" | base64 --decode > restricted-access-kubeconfig.yaml
Use cases
- limit access for different users e.g. to a dev namespace
- protect yourself (and others) from accidentally performing destructive actions by using a restricted (e.g. readonly) Kubeconfig for day to day operations.
Local Development
- Clone the repository:
git clone github.com:klaudworks/kubeconfig-operator.git
- Ensure you install kind or you have another Kubernetes distribution installed.
- Install the CRDs
kubectl apply -f manifests/crd
- Create the namespace for the controller
kubectl create namespace kubeconfig-operator
- Test the controller with the
Kubeconfig yaml manifest from above.
- Run the actual controller locally via:
go run cmd/main.go --kubeconfig ~/.kube/kind.yaml --kubecontext kind-kind
- Download the kubeconfig
kubectl get secret restricted-access-kubeconfig -o jsonpath="{.data.kubeconfig}" | base64 --decode
Achilles SDK
This operator is based on Achilles SDK developed by reddit. It allows us to specify the operator's behavior as a finite state machine.