You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kubernetes Dashboard长期有效令牌生成及域名路径访问自动登录配置咨询

Kubernetes Dashboard: Long-Lived Tokens & Domain Access with Auto-Login

Hey there! Let's break down solutions for your two Dashboard challenges: creating tokens that don't expire (or last 6+ months) and setting up custom domain access with automatic login.

1. Generating Long-Lived Login Tokens

The kubectl create token command defaults to 1-hour tokens, which is why you're seeing them expire quickly. Here are two solid ways to get longer-lived tokens:

Option 1: Specify a Custom Duration (Up to 1 Year)

If you're running Kubernetes 1.21 or newer, you can use the --duration flag to set a longer expiry—maxing out at 8760 hours (1 year). For a 6-month token, run:

kubectl -n kubernetes-dashboard create token admin-user --duration=4380h

Heads up: This token will still expire after the set time, but it's perfect if you want a fixed long validity period. Just regenerate it when it runs out.

Option 2: Create a Permanent Token via ServiceAccount Secret

This method gives you a token that never expires (until you manually delete the associated Secret). Here's how:

  1. First, check if your admin-user ServiceAccount already has a linked token:
kubectl -n kubernetes-dashboard describe serviceaccount admin-user

If you don't see a Tokens section in the output, proceed to create a new Secret:
2. Create a file named sa-permanent-token.yaml with this content:

apiVersion: v1
kind: Secret
metadata:
  name: admin-user-permanent-token
  namespace: kubernetes-dashboard
  annotations:
    kubernetes.io/service-account.name: admin-user
type: kubernetes.io/service-account-token
  1. Apply the Secret to your cluster:
kubectl apply -f sa-permanent-token.yaml
  1. Extract the permanent token:
kubectl -n kubernetes-dashboard get secret admin-user-permanent-token -o jsonpath='{.data.token}' | base64 -d

Pro tip: Guard this token carefully—since it doesn't expire, a leaked token gives persistent access to your cluster.

2. Setting Up Custom Domain Access + Auto-Login

To access Dashboard at https://my-domain-name.com/kubernetes-dashboard/... with automatic login, you'll need to use an Ingress Controller (we'll use NGINX here, the most common option) and configure path rewriting + token injection.

Step 1: Install NGINX Ingress Controller (If Not Already Installed)

First, make sure you have an Ingress Controller running in your cluster. For NGINX (the most widely used option), you can deploy it using official manifests, or use your cluster's package manager (like Helm) to install it. For most standard clusters, deploying the controller will create a LoadBalancer or NodePort Service to expose it externally.

Step 2: Create the Ingress Configuration File

Make a file named dashboard-ingress.yaml with this setup. It handles path rewriting, TLS encryption, and auto-login via token injection:

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: kubernetes-dashboard-ingress
  namespace: kubernetes-dashboard
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /$2
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
    nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
    # Auto-login magic: Inject your permanent token into the request header
    nginx.ingress.kubernetes.io/configuration-snippet: |
      proxy_set_header Authorization "Bearer <YOUR_PERMANENT_TOKEN_HERE>";
spec:
  tls:
  - hosts:
    - my-domain-name.com
    secretName: dashboard-tls-secret # Replace with your TLS certificate Secret name
  rules:
  - host: my-domain-name.com
    http:
      paths:
      - path: /kubernetes-dashboard(/|$)(.*)
        pathType: Prefix
        backend:
          service:
            name: kubernetes-dashboard
            port:
              number: 443

Key notes:

  • rewrite-target: /$2 converts paths like /kubernetes-dashboard/dashboard to /dashboard, which is what the Dashboard expects.
  • backend-protocol: "HTTPS" ensures the Ingress communicates securely with the Dashboard's HTTPS service.
  • The configuration-snippet injects your long-lived token into the Authorization header, so Dashboard automatically logs you in without prompting for a token.

Step 3: Create a TLS Certificate Secret

You'll need an SSL certificate for your domain. If you have one already, create a Secret with:

kubectl -n kubernetes-dashboard create secret tls dashboard-tls-secret --cert=/path/to/your/cert.pem --key=/path/to/your/private.key

For testing, you can use a self-signed certificate, but for production, use a trusted certificate (like those from Let's Encrypt via tools like cert-manager).

Step 4: Apply the Ingress and Test

Deploy the Ingress configuration:

kubectl apply -f dashboard-ingress.yaml

Check the Ingress status to confirm it's assigned an address:

kubectl -n kubernetes-dashboard get ingress

Once the ADDRESS field shows your Ingress Controller's IP, point your domain my-domain-name.com to that IP. Now you can visit https://my-domain-name.com/kubernetes-dashboard and be automatically logged in!

Important: If your permanent token is ever revoked or deleted, you'll need to update the configuration-snippet in the Ingress with a new valid token to keep auto-login working.


内容的提问来源于stack exchange,提问作者Vignesh Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 18:27:28