This commit is contained in:
Ev Kontsevoy
2017-09-11 13:52:14 -07:00
parent 986eb872f3
commit 69c8b7fa61
2 changed files with 20 additions and 10 deletions
+18 -8
View File
@@ -826,17 +826,18 @@ tunnel to "main" if it knows the secret, the cluster join token declared in the
permitted to. Trusted clusters work only one way: users from "east" cannot
connect to the nodes in "main".
Now, with the main claster prepared to allow remote clusters to connect to it,
lets configure "east". The administrator of the eastern cluster must create the
following resource file:
Now, with the main cluster prepared to allow remote clusters to connect to it,
lets configure "east". The administrator of "east" must create the following
resource file:
```bash
# save this to main-cluster.yaml
# cluster.yaml
kind: trusted_cluster
version: v2
metadata:
# each trusted cluster must be given a name
name: master
# each trusted cluster must be given a name. it does not have to match how
# clusters are named internally.
name: main
spec:
# this field allows to create tunnels that are disabled, but can be enabled later.
enabled: true
@@ -844,12 +845,21 @@ spec:
token: secret-token-to-add-new-clusters
# the address in 'host:port' form of the reverse tunnel listening port on the
# "master" proxy server:
tunnel_addr: proxy.master:3024
tunnel_addr: proxy.main:3024
# the address in 'host:port' form of the web listening port on the
# "master" proxy server:
web_proxy_addr: proxy.master:3080
web_proxy_addr: proxy.main:3080
```
... and create it:
```bash
$ tctl create cluster.yaml
```
At this point the users of the main cluster should be able to see "east" in the
list of available clusters.
### Using Trusted Clusters
It's worth repeating: the users of "east" cannot see or connect to the main
+2 -2
View File
@@ -25,10 +25,10 @@
<switch>
<foreignObject style="overflow:visible;" pointer-events="all" width="136" height="22" requiredFeatures="http://www.w3.org/TR/SVG11/feature#Extensibility">
<div xmlns="http://www.w3.org/1999/xhtml" style="display: inline-block; font-size: 20px; font-family: Helvetica; color: rgb(77, 77, 77); line-height: 1.2; vertical-align: top; overflow: hidden; max-height: 26px; max-width: 181px; width: 138px; white-space: normal; word-wrap: normal; font-weight: bold; text-align: center;">
<div xmlns="http://www.w3.org/1999/xhtml" style="display:inline-block;text-align:inherit;text-decoration:inherit;">master cluster</div>
<div xmlns="http://www.w3.org/1999/xhtml" style="display:inline-block;text-align:inherit;text-decoration:inherit;">"main" cluster</div>
</div>
</foreignObject>
<text x="68" y="21" fill="#4D4D4D" text-anchor="middle" font-size="20px" font-family="Helvetica" font-weight="bold">master cluster</text>
<text x="68" y="21" fill="#4D4D4D" text-anchor="middle" font-size="20px" font-family="Helvetica" font-weight="bold">"main" cluster</text>
</switch>
</g>

Before

Width:  |  Height:  |  Size: 12 KiB

After

Width:  |  Height:  |  Size: 12 KiB