You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 07189dd
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/src/getting-started/cloud-resources.md
+9Lines changed: 9 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -129,6 +129,15 @@ by CABPK, stored in a Kubernetes Secret, and sent to STACKIT as cloud-init user
129
129
data when each server is created. Leave `sshKeyName` and
130
130
`STACKIT_SSH_KEY_NAME` empty when SSH access is not required.
131
131
132
+
Because the CAPSTK controller accesses STACKIT through a service account, the SSH key pairs must be attached to that service account. Key pairs are scoped per identity and cannot be shared across service accounts or users.
133
+
134
+
Authenticate the STACKIT CLI using your service account credentials:
Copy file name to clipboardExpand all lines: docs/src/topics/accessing-vm-instances.md
+37Lines changed: 37 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -31,6 +31,43 @@ control-plane and worker VMs.
31
31
`spec.template.spec.sshKeyName`. The bastion does not inject SSH keys into
32
32
existing node VMs.
33
33
34
+
## Configure SSH keys for the service account
35
+
36
+
The CAPSTK controller authenticates to STACKIT through a service account key. Because SSH key pairs are scoped to the authenticated identity in this case a service account, the SSH keys you want to use on the bastion or on cluster machines must be attached under that exact service account and not your personal user.
37
+
38
+
1. Generate an SSH key pair locally if you do not already have one:
0 commit comments