自定义SSH密钥下az aks get-credentials多用户访问配置问题
Hey there! Let's figure out how to get User B access to that AKS cluster, since az aks get-credentials doesn't have a direct --ssh-key-file option like ACS used to. Here's the step-by-step breakdown:
Step 1: Copy the private key to User B's SSH directory
The key here is making sure User B's SSH client can find the private key (mykey) when authenticating to the cluster. Place the file in their user-specific SSH folder:
- Windows: Put
mykeyintoC:\Users\<UserB>\.ssh\(create the.sshfolder if it doesn't exist). - Linux/macOS: Copy
mykeyto~/.ssh/(the hidden SSH directory in User B's home folder).
Step 2: Set strict permissions on the private key
SSH requires private keys to have limited access to work securely:
- For Linux/macOS, run this in the terminal:
chmod 600 ~/.ssh/mykey - For Windows, if using Git Bash or WSL, use the same
chmodcommand. If using PowerShell/File Explorer:- Right-click the
mykeyfile → Properties → Security → Advanced - Disable inheritance, then remove all inherited permissions
- Add User B's account with only "Read" access to the file
- Right-click the
Step 3: Run az aks get-credentials as User B
Now User B can execute the standard credentials command:
az aks get-credentials --resource-group XXX --name zzz
This downloads the cluster's kubeconfig to User B's default location (usually ~/.kube/config on Linux/macOS, or C:\Users\<UserB>\.kube\config on Windows). The kubeconfig will reference the SSH private key path we set up, so kubectl will automatically use mykey for authentication when interacting with the cluster.
Important: Don't forget RBAC permissions
Even with the correct SSH key, User B will get authorization errors if they don't have the right cluster permissions. Make sure to assign them an appropriate RBAC role (like Contributor, Reader, or a custom role) on the AKS cluster via Azure Portal or Azure CLI.
内容的提问来源于stack exchange,提问作者MaurGi

