Ingress Access
Typically, clusters are accessed through the platform proxy, that is, requests to the cluster API server, are proxied through the platform itself. This behavior allows for the platform to act as a single endpoint for all clusters in the platform deployment. Because of this behavior, the platform is also able to act as a central point of authentication and authorization, and to log all interactions (if vCluster Platform Auditing is licensed and enabled).
In some situations you may prefer to access a cluster API server directly, that is, not
through the platform proxy. This behavior can be enabled with the cluster AccessPoint feature.
Enabling AccessPoint on a cluster requires that the control plane cluster has a valid ingress
controller deployed, and the Cluster object has the loft.sh/ingress-suffix annotation set
with a valid domain.
Gateway API is the recommended path for new endpoint and tenant routing deployments. Existing ingress access remains supported in vCluster Platform v4.10, but Gateway API migration is explicit and should be planned. See Gateway API and Migrate from ingress-nginx to Gateway API.
The hostname used to access a cluster that has the AccessPoint feature enabled, will
be of the following format:
<VIRTUAL_CLUSTER_INSTANCE_NAME>-<PROJECT_NAME>.<INGRESS_SUFFIX>
Where the <VIRTUAL_CLUSTER_INSTANCE_NAME> is the name of the cluster instance, the
<PROJECT_NAME> is the name of the project the cluster instance is created in, and the
<INGRESS_SUFFIX> is the value from the loft.sh/ingress-suffix annotation on the cluster.
Enable ingress access when creating the cluster​
Enabling the AccessPoint feature can be done during cluster creation in the Platform UI.
- Platform UI
From the project drop-down menu (top left corner), select the project you'd like to create the cluster in.
Click on Clusters.
Click the button.
Click the button to skip selecting a cluster template.
Click the Advanced Options.
Click the to expand the configuration section.
Slide the Enable Ingress Access slider to enable the ingress action.
Finish configuring anything else you'd like on your cluster, then click the button.
vcluster create vcluster-1 --link 'my-issue=https://github.com/kubernetes/kubernetes/pull/1234'
vcluster create vcluster-1 --link 'https://loft.sh'
vcluster create vcluster-1 --link 'my-issue=https://github.com/kubernetes/kubernetes/pull/1234,documentation=https://example.com/docs'
The AccessPoint feature can also be enabled on the template.