Skip to content

Commit 07189dd

Browse files
committed
docs: ssh key-pair configuration
Signed-off-by: Jan Larwig <jan.larwig@digits.schwarz>
1 parent e52060d commit 07189dd

2 files changed

Lines changed: 46 additions & 0 deletions

File tree

‎docs/src/getting-started/cloud-resources.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,15 @@ by CABPK, stored in a Kubernetes Secret, and sent to STACKIT as cloud-init user
129129
data when each server is created. Leave `sshKeyName` and
130130
`STACKIT_SSH_KEY_NAME` empty when SSH access is not required.
131131

132+
Because the CAPSTK controller accesses STACKIT through a service account, the SSH key pairs must be attached to that service account. Key pairs are scoped per identity and cannot be shared across service accounts or users.
133+
134+
Authenticate the STACKIT CLI using your service account credentials:
135+
136+
```sh
137+
stackit auth activate-service-account \
138+
--service-account-key-path "${STACKIT_SERVICE_ACCOUNT_JSON_FILE}"
139+
```
140+
132141
Import an existing SSH public key:
133142

134143
```sh

‎docs/src/topics/accessing-vm-instances.md‎

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,43 @@ control-plane and worker VMs.
3131
`spec.template.spec.sshKeyName`. The bastion does not inject SSH keys into
3232
existing node VMs.
3333

34+
## Configure SSH keys for the service account
35+
36+
The CAPSTK controller authenticates to STACKIT through a service account key. Because SSH key pairs are scoped to the authenticated identity in this case a service account, the SSH keys you want to use on the bastion or on cluster machines must be attached under that exact service account and not your personal user.
37+
38+
1. Generate an SSH key pair locally if you do not already have one:
39+
40+
```sh
41+
ssh-keygen -t ed25519 -f ~/.ssh/id_stackit -C "capstk-access"
42+
```
43+
44+
2. Authenticate the STACKIT CLI using your service account credentials:
45+
46+
```sh
47+
stackit auth activate-service-account \
48+
--service-account-key-path /path/to/service-account.json
49+
```
50+
51+
3. Import the public key as a key pair under that service account:
52+
53+
```sh
54+
export STACKIT_SSH_KEY_NAME="capstk-key"
55+
56+
stackit key-pair create \
57+
--project-id "${STACKIT_PROJECT_ID}" \
58+
--region "${STACKIT_REGION}" \
59+
--name "${STACKIT_SSH_KEY_NAME}" \
60+
--public-key "@${HOME}/.ssh/id_stackit.pub"
61+
```
62+
63+
4. Reference the key in your cluster definition:
64+
65+
When using `templates/cluster-template-bastion.yaml`, pass the key name to the template variables:
66+
- `STACKIT_BASTION_SSH_KEY_NAME`: sets `spec.bastion.sshKeyName` on `StackitCluster`
67+
- `STACKIT_SSH_KEY_NAME`: sets `spec.template.spec.sshKeyName` on `StackitMachineTemplate` for control-plane and worker nodes
68+
69+
You can use separate keys for the bastion and the nodes, or point both variables to the same key.
70+
3471
## Enable the bastion
3572

3673
Patch or edit the generated `StackitCluster`:

0 commit comments

Comments
 (0)