mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
1. `tsh kube clusters` - lists registered kubernetes clusters note: this only includes clusters connected via `kubernetes_service` 2. `tsh kube credentials` - returns TLS credentials for a specific kube cluster; this is a hidden command used as an exec plugin for kubectl 3. `tsh kube login` - switches the kubectl context to one of the registered clusters; roughly equivalent to `kubectl config use-context` When updating kubeconfigs, tsh now uses the exec plugin mode: https://kubernetes.io/docs/reference/access-authn-authz/authentication/#client-go-credential-plugins This means that on each kubectl run, kubectl will execute tsh with special arguments to get the TLS credentials. Using tsh as exec plugin allows us to put a login prompt when certs expire. It also lets us lazy-initialize TLS certs for kubernetes clusters.