How Platform Teams can enable developers to use their preferred Kubernetes Tools - Rafay Product Documentation

How Platform Teams can enable developers to use their preferred Kubernetes Tools

There are cases where developers may prefer to use tools on their laptops such as Lens Desktop to visualize resources and interact with Kubernetes clusters. The use of a desktop based app such as Lens can be a better user experience for developers over the Kubectl CLI.

In this blog, we will describe how Platform Teams can use Rafay’s Zero-Trust Access service to enable developers to use popular Kubernetes visualization apps to troubleshoot their applications. Watch a video showing how a developer can use Lens Desktop with Rafay's Zero Trust Kubectl Access service to securely and remotely access Kubernetes clusters.

Challenges

Platform teams have the onus of enabling developers to use such tooling while ensuring there are sufficient guardrails in place. The challenges that Platform teams typically run into are threefold:

Typical Sequence

The sequence diagram shows how a developer can use Lens Desktop with Rafay's Zero Trust Kubectl Access service.

  1. User authenticates via Org IDP
  2. User downloads consolidated kubeconfig
  3. User uploads kubeconfig
  4. Securely connects via Rafay's Zero-Trust proxy
  5. Proxy authenticates user, forwards the request
  6. Subsequent user requests are forwarded by the proxy to the remote cluster
  7. Service account gets removed after configured inactive period

Developer downloads kubeconfig file from Rafay

Developer provides the Rafay Zero Trust kubeconfig file to Lens Desktop

Day 2 Operations

Conclusion

Rafay enables platform teams to integrate best practices across Secure Access, Kubernetes RBAC and SSO to enable a Zero-Trust model for K8s infrastructure.

Challenge How does Rafay help?
Securing access to KubeAPI servers Rafay’s Zero-Trust architecture removes the need for customers to leverage a VPN solution/bastion server access model and/or open ports in firewalls
Managing Kubernetes RBAC Rafay enables customers to centralize orchestration of access policies at scale across fleet of clusters
SSO integration Rafay enables customers to integrate their IDP and have the user role/access determined by the group membership in the identity provider