Installing Kubernetes Dashboard
Products: FastReport Corporate Server
Kubernetes-Dashboard is a WEB interface for cluster management. It allows you to manage Kubernetes using a WEB browser. Dashboard is not a necessary component for running the report server, but it helps to simplify server setup and configuration, as well as to monitor the state of nodes and containers.
Install Dashboard
kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.0-rc7/aio/deploy/recommended.yaml
Configure Dashboard
When configuring Dashboard, the variable SERVER_DOMAIN_NAME is used. Note, that the same IP address is used for Dashboard as for the report server in the configuration below. To access the Dashboard page, a rule is used to define the path to the Dashboard.
export SERVER_DOMAIN_NAME="my.server-server.com"
cat <<EOF | kubectl apply -f -
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
name: fastreport.cloud-dashboard
namespace: kubernetes-dashboard
annotations:
kubernetes.io/ingress.class: "nginx"
nginx.ingress.kubernetes.io/backend-protocol: HTTPS
nginx.ingress.kubernetes.io/use-regex: "true"
nginx.ingress.kubernetes.io/rewrite-target: "/\$2"
nginx.ingress.kubernetes.io/configuration-snippet: |
rewrite ^(/dashboard)\$ \$1/ redirect;
spec:
tls:
- hosts:
- $SERVER_DOMAIN_NAME
secretName: fr-corporate-tls
rules:
- host: $SERVER_DOMAIN_NAME
http:
paths:
- path: /dashboard(/|$)(.*)
backend:
serviceName: kubernetes-dashboard
servicePort: 443
EOF
You can verify the created nginx server configuration using the following commands, replacing nginx-ingress-controller-6674ff5868-t47xk with the name of the created nginx container:
kubectl exec -it nginx-ingress-controller-6674ff5868-t47xk -n nginx -- ls /etc/nginx/
kubectl exec -it nginx-ingress-controller-6674ff5868-t47xk -n nginx -- cat /etc/nginx/nginx.conf
Next, you need to create a token that will be used for administrative access to the Dashboard. Create an administrative account:
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: ServiceAccount
metadata:
name: dashboard-admin-user
namespace: kube-system
EOF
Assign access rights to the administrative account:
cat <<EOF | kubectl apply -f -
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: dashboard-admin-user
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: dashboard-admin-user
namespace: kube-system
EOF
Create a token:
kubectl -n kubernetes-dashboard create token dashboard-admin-user -n kube-system
Unpack and display the token used for authorization on the Dashboard:
kubectl -n kube-system describe secret $(kubectl -n kube-system get secret | grep dashboard-admin-user | awk '{print $1}')
Save the token for later use in an inaccessible place and use it for authorization in Dashboard. Example URL to access the dashboard:
https://my.server-server.com/dashboard/