如何在外部IP地址上安装Kubernetes Dashboard?是否有相关教程?
Hey there! I’ve walked many developers through getting the Kubernetes Dashboard accessible via an external IP, so let me break this down clearly with a step-by-step guide you can follow right away.
Prerequisites
First, make sure your Kubernetes cluster is up and running, and you have kubectl configured to connect to it with admin-level permissions.
Step 1: Install the Kubernetes Dashboard
Start by deploying the official stable Dashboard resources. Grab the latest recommended manifest from the Kubernetes Dashboard project, save it to a local file (e.g., dashboard-deploy.yaml), then apply it to your cluster:
kubectl apply -f dashboard-deploy.yaml
This will create all the necessary components (deployment, service, etc.) in the kubernetes-dashboard namespace. By default, the Dashboard service uses ClusterIP type—meaning it’s only accessible inside the cluster—so we’ll adjust that next.
Step 2: Expose the Dashboard to an External IP
You have a few options here, depending on your environment:
Option 1: Use NodePort (Works for any cluster, on-prem or cloud)
- First, check the default Dashboard service:
kubectl get svc -n kubernetes-dashboard - Edit the service to switch its type to
NodePort:
Find the line that sayskubectl edit svc kubernetes-dashboard -n kubernetes-dashboardtype: ClusterIPand change it totype: NodePort, then save and exit. - Grab the assigned NodePort:
Look for thekubectl get svc kubernetes-dashboard -n kubernetes-dashboardPORT(S)column—you’ll see something like443:30123/TCP, where30123is your NodePort. Now you can access the Dashboard athttps://<your-node-external-ip>:30123.
Option 2: Use LoadBalancer (Ideal for cloud clusters)
If your cluster is hosted on a cloud provider (AWS, GCP, Azure, etc.) that supports LoadBalancer services, this is the easiest method:
kubectl patch svc kubernetes-dashboard -n kubernetes-dashboard -p '{"spec":{"type":"LoadBalancer"}}'
Wait a minute or two, then check the service again:
kubectl get svc kubernetes-dashboard -n kubernetes-dashboard
Once the EXTERNAL-IP field populates, you can access the Dashboard directly at https://<that-external-ip>.
Option 3: Use Ingress (Best for production environments)
For a more secure, scalable setup (especially if you want to use a custom domain), use an Ingress resource. First, make sure you have an Ingress Controller (like NGINX Ingress) installed in your cluster.
Create a file named dashboard-ingress.yaml with this content:
apiVersion: networking.k8s.io/v1 kind: Ingress metadata: name: kubernetes-dashboard namespace: kubernetes-dashboard annotations: nginx.ingress.kubernetes.io/ssl-redirect: "true" nginx.ingress.kubernetes.io/backend-protocol: "HTTPS" spec: tls: - hosts: - dashboard.yourdomain.com # Replace with your custom domain secretName: dashboard-tls # Replace with your TLS certificate secret name rules: - host: dashboard.yourdomain.com http: paths: - path: / pathType: Prefix backend: service: name: kubernetes-dashboard port: number: 443
Apply the Ingress resource:
kubectl apply -f dashboard-ingress.yaml
Finally, point your domain’s DNS record to your Ingress Controller’s external IP. You’ll then be able to access the Dashboard at https://dashboard.yourdomain.com.
Step 3: Create an Admin User for Dashboard Access
The default Dashboard has limited permissions, so let’s create an admin-level service account to log in:
- Create the service account:
kubectl create serviceaccount admin-user -n kubernetes-dashboard - Bind it to the cluster-admin role:
kubectl create clusterrolebinding admin-user-binding --clusterrole=cluster-admin --serviceaccount=kubernetes-dashboard:admin-user - Fetch the login token:
kubectl get secret -n kubernetes-dashboard $(kubectl get serviceaccount admin-user -n kubernetes-dashboard -o jsonpath="{.secrets[0].name}") -o jsonpath="{.data.token}" | base64 --decode
Copy the token that’s output, then paste it into the Dashboard’s login screen (select the "Token" option) to gain full access.
Important Notes
- The Dashboard uses HTTPS with a self-signed certificate by default—your browser will show a security warning. You can either bypass it for testing, or configure a trusted TLS certificate (via LoadBalancer or Ingress) for production.
- If using NodePort, make sure the port is open in your cluster’s firewall/security group.
- For production, restrict Dashboard access to trusted IPs (using Ingress annotations or security groups) and avoid using the cluster-admin role unless absolutely necessary.
内容的提问来源于stack exchange,提问作者Anu V

