How does 'kubectl exec' work? (2019)
erkanerol.github.io
erkanerol.github.io
Fun challenge is to then convert it into a websocket or http handler.
Tip for anyone trying to do this in Go, look at Docker CLI's code for all the knobs you need to turn to have an actually interactive terminal, for example, setting raw mode on the terminal, handling terminal resizes, and other things across platforms.
1. kubectl exec -ti foo -- bash # start shell in some pod
2. echo $$ # get pid of that shell
3. # close terminal without explicitly exiting bash
4. kubectl exec -ti foo -- sh -c 'ls /proc/<previous pid>'
It looks like SIG* on the kubectl side aren't getting propagated to the in-pod process. Does anyone know of a proper way to prevent this process leak?
“By default, the apiserver does not verify the kubelet’s serving certificate, which makes the connection subject to man-in-the-middle attacks, and unsafe to run over untrusted and/or public networks.”