Is there a way to forward authorization header through the Kubernetes API server proxy?

Viewed 877

I have some endpoint running on a pod inside of my Kubernetes cluster that is secured by basic auth. The normal way of accessing this pod through the API server would be:

https://{{ apiServer }}:{{ apiServerPort }}/api/v1/namespaces/{{ namespaceName }}/pods/{{ podName }}:{{ podPort }}/proxy/somepath

This works fine for endpoints that are not secured using Basic Auth, but when trying to access the secure endpoints, I get a 403 Forbidden every time because I can not specify two authentication headers and I already need to authenticate myself to the API server itself. Is it possible to get those Basic Auth credentials forwarded to the pod or am I out of luck using the API server proxy?

1 Answers

The working solution that I can think of is to use kubectl port-forward. As a result of that Kubernetes API server will establish a single http connection between your localhost and the resource running on your cluster. This will preserve all your client requests.

kubectl port-forward TYPE/NAME [options] LOCAL_PORT:REMOTE_PORT

You can send the traffic to specific pod, use random local port or even specify local ip address use for forwarding.

You can read more about port forwarding here and check this example in the official kuberentes document.

If you want some alternatives you want to check telepresence.

PS. I tried to use a sidecar container with kubectl proxy but that did not work unfortunately.

Related