Remote shell into your Kubernetes cluster over Tailscale
Coming soon: Kubepier installs a shell pod in your cluster and joins it to your Tailscale tailnet. You open the shell from your phone, laptop or browser, with Tailscale SSH, your tailnet ACL and no port open to the internet. The feature is not available yet: join the beta waitlist.
Status: under development
Coming soon: the remote shell over Tailscale is under development and will open first as a closed beta, through a waitlist. This page describes how it will work and may change before release. Today, for a shell, use the pod and node shell and the Bastion.
What it is for
- Open a shell into the cluster from anywhere, including your phone, with no corporate VPN, no bastion with a public IP and without exposing the Kubernetes API to the internet.
- Reach private clusters (AKS and EKS with a private endpoint, on-premises): the pod dials out to Tailscale and you come in through your tailnet, with nothing inbound allowed on the firewall.
- Get kubectl, helm, k9s and network tools (curl, nc, dig, ssh) preinstalled, with the RBAC you choose.
How it will work
- Its own Shell item in the Kubepier Web and Kubepier Desktop menu, separate from clients and clusters.
- A wizard installs the kubepier-shell Deployment in the kubepier-shell namespace, with Tailscale in userspace mode (no privileges, no hostNetwork).
- The pod joins YOUR tailnet with a tag (tag:kubepier-shell) and a one-off, tagged, pre-approved auth key generated in your Tailscale. Never a TR99 key.
- Who can get in is decided by your tailnet ACL (grants and ssh rules), with the check action, which asks for a fresh Tailscale login from time to time.
- On a phone: the Tailscale app (iOS and Android) plus an SSH client such as Termius, Blink Shell or JuiceSSH. On Linux, Windows and macOS: tailscale ssh or the system ssh.
- In the browser (optional): Kubepier Web opens the same pod in a terminal, through the Kubernetes API, like today's pod shell.
- Revoking takes one click: Kubepier deletes the pod and the Secrets and, with an OAuth client from your tailnet, also removes the machine from your tailnet.
Security
- No public ports: the pod only makes outbound connections to Tailscale.
- RBAC profiles at install time: read-only (view), operations in chosen namespaces, cluster admin (with typed confirmation) or no API access (network only).
- Unprivileged pod, PodSecurity restricted profile, image pinned by digest.
- Install, profile change, revoke and uninstall go to the Kubepier audit log. SSH connections are logged on your Tailscale side; Kubepier does not record what is typed.
- An admin action on Kubepier Web, with typed confirmation, like the other dangerous actions.
Plans
Planned for the Pro and Team plans, on the web and on desktop, with the same limits. On Free, the Shell menu shows a lock, like the other paid features. You get Tailscale directly from Tailscale. On the Tailscale Personal (free) plan, Tailscale SSH covers up to 5 hosts, that is, up to 5 clusters with the shell; beyond that you need a paid Tailscale plan. Pricing and limits may change before release.
Join the waitlist
Email contato@kubepier.com.br with the subject "Waitlist: Remote shell over Tailscale", telling us your cloud (Azure, AWS, other), whether the cluster is private and which devices you want to connect from. We will let you know when the beta opens.