Skip to content

Access and security

This page covers everything between you and the cluster’s API server: the kubeconfig, how the endpoint is exposed, the firewall rules around the cluster, TLS on the API, and automatic certificate renewal.

  • A running cluster. See Clusters.
  • For team members: the kubernetes.kubeconfig_download permission, if your account is a subuser. See your team administrator.

On the cluster page, click Download kubeconfig. The panel mints a fresh cluster-admin client certificate on every download and streams the file (kubeconfig-<slug>.yaml) to you.

Terminal window
export KUBECONFIG=~/Downloads/kubeconfig-mycluster.yaml
kubectl get nodes

Key rules:

  • Each downloaded certificate is valid for 90 days. Download a new kubeconfig before yours expires.
  • There is no revocation: the Kubernetes API server does not honour certificate revocation lists, so a leaked kubeconfig stays usable until its certificate expires. The 90-day validity is the bound on that exposure. Treat the file like a password.
  • Downloads are rate-limited; a scripted re-download loop will get throttled.

The create wizard offers two endpoint modes:

Mode What you get
Public & Private (default) The API load balancer gets an internal (VPC) endpoint and a public endpoint. kubectl works from the internet, subject to the load balancer security group.
Private The API load balancer gets an internal (VPC) endpoint only. kubectl must run from inside the VPC, for example through a VPN gateway.

The cluster page header shows the endpoints that exist for your cluster.

Every cluster gets three auto-managed security groups, edited on the cluster’s Security tab in three scopes, each with inbound and outbound rules:

Scope Attached to Seeded rules
Load balancer The API load balancer Inbound TCP 443 (the API port; from anywhere on public clusters, from the VPC CIDR on private clusters). All outbound.
Control plane Control plane nodes Inbound TCP 6443 from the load balancer group only (the load balancer is the only path to the API). etcd (2379-2380) and kubelet (10250) between control plane nodes. All outbound.
Workers Worker nodes All inbound from the control plane group. All inbound from peer workers (pod networking). NodePort range 30000-32767 from anywhere. All outbound.

The API itself listens on TCP 443 on the load balancer, which passes traffic straight through to the control plane; TLS is terminated by the API server, so kubectl always verifies the cluster’s own certificate.

To control who can reach a public API, edit the inbound rules of the load balancer scope: replace the open TCP 443 rule with your own source ranges. Tighten the NodePort rule in the workers scope if you do not want NodePort Services open to the internet.

On the cluster’s SSL & domains tab, click Add Certificate to bind a TLS certificate to the cluster’s API load balancer and expose the API on a custom domain like k8s.example.com:

  • Let’s Encrypt: the panel issues the certificate for the domain you enter and renews it; the tab shows its status. Issuance runs in the background.
  • Custom upload: paste a Certificate (PEM), a Private Key (PEM, unencrypted) and an optional Chain (PEM, intermediates).

The certificates Kubernetes itself uses (API server, etcd, kubelet) renew automatically:

  • The panel checks daily and renews any cluster whose certificates expire within 30 days.
  • Renewal runs on the control plane nodes one at a time: certificates are re-issued and the control plane components restart, waiting for the API to come back healthy before moving on. Worker workloads keep running.
  • You get an email when renewal starts and when it completes. Your provider is alerted if a renewal fails.
  • Renewal re-issues the admin client certificate too. Afterwards the cluster page shows a reminder that your previous kubeconfig is no longer valid: click Download kubeconfig to get the new one, or dismiss the reminder if you already have it.
  • kubectl gets connection refused or times out. Confirm the cluster is Running. For a public endpoint, check the load balancer scope allows your source IP on TCP 443. For a private-only endpoint, run kubectl from inside the VPC.
  • kubectl reports x509 certificate expired. Your downloaded client certificate passed its 90-day validity. Download a fresh kubeconfig.
  • A team member cannot see the download button. Their subuser role lacks kubernetes.kubeconfig_download.