/plushcap/analysis/cloudflare/kubectl-with-zero-trust

Kubectl with Cloudflare Zero Trust

What's this blog post about?

Cloudflare uses Kubernetes extensively for engineering tasks such as API backend, batch processing, and CI/CD pipelines. However, the large surface area exposed by Kubernetes poses security risks. To address this issue, Cloudflare employs its Zero Trust solution to secure access to Kubernetes clusters while enabling kubectl without proxies. The company initially used VPNs for network access but switched to Cloudflare Tunnels and eventually moved on to using the private network routing feature of Cloudflare Zero Trust. This approach allows engineers to access the Kubernetes APIs securely without needing to set up cloudflared tunnels or configure kubectl and other Kubernetes ecosystem tools to use tunnels.

Company
Cloudflare

Date published
June 24, 2022

Author(s)
Terin Stock

Word count
1225

Hacker News points
3

Language
English


By Matt Makai. 2021-2024.