Kubernetes Dashboard长期有效令牌生成及域名路径访问自动登录配置咨询
Hey there! Let's break down solutions for your two Dashboard challenges: creating tokens that don't expire (or last 6+ months) and setting up custom domain access with automatic login.
1. Generating Long-Lived Login Tokens
The kubectl create token command defaults to 1-hour tokens, which is why you're seeing them expire quickly. Here are two solid ways to get longer-lived tokens:
Option 1: Specify a Custom Duration (Up to 1 Year)
If you're running Kubernetes 1.21 or newer, you can use the --duration flag to set a longer expiry—maxing out at 8760 hours (1 year). For a 6-month token, run:
kubectl -n kubernetes-dashboard create token admin-user --duration=4380h
Heads up: This token will still expire after the set time, but it's perfect if you want a fixed long validity period. Just regenerate it when it runs out.
Option 2: Create a Permanent Token via ServiceAccount Secret
This method gives you a token that never expires (until you manually delete the associated Secret). Here's how:
- First, check if your
admin-userServiceAccount already has a linked token:
kubectl -n kubernetes-dashboard describe serviceaccount admin-user
If you don't see a Tokens section in the output, proceed to create a new Secret:
2. Create a file named sa-permanent-token.yaml with this content:
apiVersion: v1 kind: Secret metadata: name: admin-user-permanent-token namespace: kubernetes-dashboard annotations: kubernetes.io/service-account.name: admin-user type: kubernetes.io/service-account-token
- Apply the Secret to your cluster:
kubectl apply -f sa-permanent-token.yaml
- Extract the permanent token:
kubectl -n kubernetes-dashboard get secret admin-user-permanent-token -o jsonpath='{.data.token}' | base64 -d
Pro tip: Guard this token carefully—since it doesn't expire, a leaked token gives persistent access to your cluster.
2. Setting Up Custom Domain Access + Auto-Login
To access Dashboard at https://my-domain-name.com/kubernetes-dashboard/... with automatic login, you'll need to use an Ingress Controller (we'll use NGINX here, the most common option) and configure path rewriting + token injection.
Step 1: Install NGINX Ingress Controller (If Not Already Installed)
First, make sure you have an Ingress Controller running in your cluster. For NGINX (the most widely used option), you can deploy it using official manifests, or use your cluster's package manager (like Helm) to install it. For most standard clusters, deploying the controller will create a LoadBalancer or NodePort Service to expose it externally.
Step 2: Create the Ingress Configuration File
Make a file named dashboard-ingress.yaml with this setup. It handles path rewriting, TLS encryption, and auto-login via token injection:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: kubernetes-dashboard-ingress namespace: kubernetes-dashboard annotations: nginx.ingress.kubernetes.io/rewrite-target: /$2 nginx.ingress.kubernetes.io/ssl-redirect: "true" nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" # Auto-login magic: Inject your permanent token into the request header nginx.ingress.kubernetes.io/configuration-snippet: | proxy_set_header Authorization "Bearer <YOUR_PERMANENT_TOKEN_HERE>"; spec: tls: - hosts: - my-domain-name.com secretName: dashboard-tls-secret # Replace with your TLS certificate Secret name rules: - host: my-domain-name.com http: paths: - path: /kubernetes-dashboard(/|$)(.*) pathType: Prefix backend: service: name: kubernetes-dashboard port: number: 443
Key notes:
rewrite-target: /$2converts paths like/kubernetes-dashboard/dashboardto/dashboard, which is what the Dashboard expects.backend-protocol: "HTTPS"ensures the Ingress communicates securely with the Dashboard's HTTPS service.- The
configuration-snippetinjects your long-lived token into theAuthorizationheader, so Dashboard automatically logs you in without prompting for a token.
Step 3: Create a TLS Certificate Secret
You'll need an SSL certificate for your domain. If you have one already, create a Secret with:
kubectl -n kubernetes-dashboard create secret tls dashboard-tls-secret --cert=/path/to/your/cert.pem --key=/path/to/your/private.key
For testing, you can use a self-signed certificate, but for production, use a trusted certificate (like those from Let's Encrypt via tools like cert-manager).
Step 4: Apply the Ingress and Test
Deploy the Ingress configuration:
kubectl apply -f dashboard-ingress.yaml
Check the Ingress status to confirm it's assigned an address:
kubectl -n kubernetes-dashboard get ingress
Once the ADDRESS field shows your Ingress Controller's IP, point your domain my-domain-name.com to that IP. Now you can visit https://my-domain-name.com/kubernetes-dashboard and be automatically logged in!
Important: If your permanent token is ever revoked or deleted, you'll need to update the
configuration-snippetin the Ingress with a new valid token to keep auto-login working.
内容的提问来源于stack exchange,提问作者Vignesh Kumar

