GKE native auth #4483
Replies: 2 comments
|
This should be possible, but the important part is that Headlamp needs to execute the GKE auth plugin to obtain the credential rather than treating the gke-gcloud-auth-plugin entry as a static token. I’d first verify that the same kubeconfig works outside Headlamp: kubectl get pods --kubeconfig ~/.kube/configIf kubectl works but Headlamp returns 401, check how Headlamp is running. If it’s running in Docker or another isolated environment, it won’t automatically have access to your local gcloud credentials or the gke-gcloud-auth-plugin binary. In that case, the container needs access to the kubeconfig and the authentication mechanism/credentials referenced by the kubeconfig. Also make sure: gcloud auth application-default print-access-token
gke-gcloud-auth-plugin --versionwork in the same environment where Headlamp is running. So I’d narrow the issue down first to “does the kubeconfig + GKE auth plugin work in the Headlamp runtime?” rather than the GKE IAM permissions themselves. If kubectl succeeds locally but Headlamp gets 401, the runtime/environment difference is the first thing I’d investigate. |
|
I think this is very likely on Headlamp's exec-credential path rather than a GKE IAM/RBAC problem. GKE kubeconfigs normally use an I would first verify the exact same kubeconfig outside Headlamp: kubectl --kubeconfig /path/to/config auth can-i get pods -A
gke-gcloud-auth-plugin --versionAlso make sure On macOS/Linux I would test by launching Headlamp from the terminal with the same environment and kubeconfig: KUBECONFIG=/path/to/config /path/to/headlampIf kubectl succeeds but Headlamp still returns 401, I would not change Kubernetes RBAC yet. That strongly points to the exec-credential handling problem tracked in #5402. For an in-cluster deployment, OIDC is probably the cleaner workaround instead of trying to embed a static GKE access token. |
Uh oh!
There was an error while loading. Please reload this page.
Hi,
we'd like to use headlamp as a k8s dashboard in many of our cluster across multiple GCP projects.
To ease the authentication I thought it would be nice to use the google accounts we are already using to do the IAM and for connecting to the clusters (with the
gke-gcloud-auth-plugin).I couldn't find any specific docs for it, but by searching a found last years commit: headlamp - commit #97b35e98, which I followed, but I am still stuck with receiving 401s.
Did anyone manage to do anything like that? Have I missed anything?
All reactions