Implement user kubeconfig server with Espejote and Caddy - #10
Merged
Merged
Conversation
simu
commented
Sep 10, 2026
simu
force-pushed
the
feat/user-kubeconfig
branch
7 times, most recently
from
September 10, 2026 12:57
57bbbe8 to
4a633ff
Compare
simu
commented
Sep 10, 2026
Member
Author
|
Note for reviewers: the new test case's |
HappyTetrahedron
approved these changes
Sep 14, 2026
simu
force-pushed
the
feat/user-kubeconfig
branch
from
September 14, 2026 09:56
4a633ff to
943f770
Compare
We use Espejote to render a ConfigMap which contains an index page (`component/assets/user-kubeconfig-index.html`), the cluster's kubeconfig and CA certificate, and a Caddy config. We implement the serving with Caddy because we found that Cilium's ingress implementation doesn't support `http.paths.backend.resource`. As mentioned above, the data and config for Caddy is managed via Espejote. The Caddy config itself is statically defined in `component/user-kubeconfig.jsonnet` and passed to the Espejote ManagedResource. The ManagedResource extracts the cluster's CA certificate and kubeconfig from the cluster API `<cluster name>-kubeconfig` secret.
The commit adds a "copy" button to the kubeconfig shown in the page which is inspired by https://picostitch.com/blog/2025/05/allow2copy/. Additionally, the kubeconfig download link is restyled to look the same as the "copy" button.
Rendered from template version: main (37002ce)
simu
force-pushed
the
feat/user-kubeconfig
branch
from
September 14, 2026 10:00
943f770 to
65fa10b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
We use Espejote to render a ConfigMap which contains an index page (
component/assets/user-kubeconfig-index.html), the cluster's kubeconfig and CA certificate, and a Caddy config.We implement the serving with Caddy because we found that Cilium's ingress implementation doesn't support
http.paths.backend.resource.As mentioned above, the data and config for Caddy is managed via Espejote. The Caddy config itself is statically defined in
component/user-kubeconfig.jsonnetand passed to the Espejote ManagedResource.The ManagedResource extracts the cluster's CA certificate and kubeconfig from the cluster API
<cluster name>-kubeconfigsecret.Adapted from projectsyn/component-talos-capi-cluster-cloudscale#2 (note that we've omitted the cluster CA dynamic fact rendering for this PR).
TODO
Checklist
changelog.
The PR has a meaningful description that sums up the change. It will be
linked in the changelog.
bug,enhancement,documentation,change,breaking,dependencyas they show up in the changelog.