Skip to content

Implement user kubeconfig server with Espejote and Caddy - #10

Merged
simu merged 7 commits into
masterfrom
feat/user-kubeconfig
Sep 14, 2026
Merged

simu merged 7 commits into
masterfrom
feat/user-kubeconfig

Conversation

@simu

@simu simu commented Sep 10, 2026 •

Copy link
Copy Markdown
Member

We use Espejote to render a ConfigMap which contains an index page (component/assets/user-kubeconfig-index.html), the cluster's kubeconfig and CA certificate, and a Caddy config.

We implement the serving with Caddy because we found that Cilium's ingress implementation doesn't support http.paths.backend.resource.

As mentioned above, the data and config for Caddy is managed via Espejote. The Caddy config itself is statically defined in component/user-kubeconfig.jsonnet and passed to the Espejote ManagedResource.

The ManagedResource extracts the cluster's CA certificate and kubeconfig from the cluster API <cluster name>-kubeconfig secret.

Adapted from projectsyn/component-talos-capi-cluster-cloudscale#2 (note that we've omitted the cluster CA dynamic fact rendering for this PR).

TODO

  • Decide if we want to add an enable/disable flag.
  • Add config validation for user-supplied configs.

Checklist

  • The PR has a meaningful title. It will be used to auto-generate the
    changelog.
    The PR has a meaningful description that sums up the change. It will be
    linked in the changelog.
  • PR contains a single logical change (to build a better changelog).
  • Update the documentation.
  • Categorize the PR by adding one of the labels:
    bug, enhancement, documentation, change, breaking, dependency
    as they show up in the changelog.
  • Link this PR to related issues or PRs.

@simu simu added the enhancement New feature or request label Sep 10, 2026
Comment thread component/user-kubeconfig.jsonnet Outdated
Base automatically changed from feat/enable-clusterctl to master September 10, 2026 10:04
@simu
simu force-pushed the feat/user-kubeconfig branch 7 times, most recently from 57bbbe8 to 4a633ff Compare September 10, 2026 12:57
Comment thread component/user-kubeconfig.jsonnet
@simu
simu requested a review from a team September 10, 2026 13:00
@simu

simu commented Sep 10, 2026

Copy link
Copy Markdown
Member Author

Note for reviewers: the new test case's 10_kustomize doesn't need thorough review.

@simu
simu force-pushed the feat/user-kubeconfig branch from 4a633ff to 943f770 Compare September 14, 2026 09:56
We use Espejote to render a ConfigMap which contains an index page
(`component/assets/user-kubeconfig-index.html`), the cluster's
kubeconfig and CA certificate, and a Caddy config.

We implement the serving with Caddy because we found that Cilium's
ingress implementation doesn't support `http.paths.backend.resource`.

As mentioned above, the data and config for Caddy is managed via
Espejote. The Caddy config itself is statically defined in
`component/user-kubeconfig.jsonnet` and passed to the Espejote
ManagedResource.

The ManagedResource extracts the cluster's CA certificate and kubeconfig
from the cluster API `<cluster name>-kubeconfig` secret.
The commit adds a "copy" button to the kubeconfig shown in the page
which is inspired by https://picostitch.com/blog/2025/05/allow2copy/.

Additionally, the kubeconfig download link is restyled to look the same
as the "copy" button.
Rendered from template version: main (37002ce)
@simu
simu force-pushed the feat/user-kubeconfig branch from 943f770 to 65fa10b Compare September 14, 2026 10:00
@simu
simu merged commit f70d446 into master Sep 14, 2026
13 checks passed
@simu
simu deleted the feat/user-kubeconfig branch September 14, 2026 11:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants