Connecting with kubectl
kubectl talks to a cluster using a kubeconfig file. In Hyperkub you get
one by creating a cluster credential.
Why credentials are separate objects
Section titled “Why credentials are separate objects”A credential is issued per person or per machine, not per cluster. That means you can revoke one laptop’s access without disturbing anyone else, and you can see which credentials exist for a cluster.
Credentials are also short-lived. Expect to reissue them periodically rather than storing one forever.
Create and download
Section titled “Create and download”- Open the cluster in the control plane.
- Go to Credentials → Create credential.
- Download the file when prompted.
Point kubectl at it
Section titled “Point kubectl at it”For a single cluster, the simplest approach is an environment variable:
export KUBECONFIG=~/.kube/hyperkub-production.yamlkubectl get nodesTo make it the default, save it as ~/.kube/config instead.
Working with several clusters
Section titled “Working with several clusters”KUBECONFIG accepts a list, and kubectl merges the files:
export KUBECONFIG=~/.kube/config:~/.kube/hyperkub-production.yamlList what merged, then switch between them:
kubectl config get-contextskubectl config use-context hyperkub-productionTo avoid running the right command against the wrong cluster, set the context per command instead of switching globally:
kubectl --context hyperkub-staging get podsUse in CI
Section titled “Use in CI”Do not commit the kubeconfig. Store its contents in a masked CI variable and write it to disk at job start:
deploy: script: - echo "$KUBECONFIG_PRODUCTION" > "$CI_PROJECT_DIR/kubeconfig" - export KUBECONFIG="$CI_PROJECT_DIR/kubeconfig" - kubectl rollout restart deployment/apiIssue a dedicated credential for CI so it can be revoked independently of anyone’s laptop.
Troubleshooting
Section titled “Troubleshooting”Unable to connect to the server: dial tcp ... i/o timeout
Section titled “Unable to connect to the server: dial tcp ... i/o timeout”The cluster is probably not running yet. Check its status in the control
plane — a cluster in provisioning does not answer.
error: You must be logged in to the server (Unauthorized)
Section titled “error: You must be logged in to the server (Unauthorized)”The credential has expired or been revoked. Create a new one.
kubectl get nodes returns nothing
Section titled “kubectl get nodes returns nothing”You are connected, but the pool has no nodes. Check the pool’s node count.
The wrong cluster responds
Section titled “The wrong cluster responds”You have several files merged and the active context is not the one you meant.
Run kubectl config current-context to confirm.