Accessing VPC clusters through the private cloud service endpoint
For VPC clusters, the private service endpoint can be accessed from anywhere inside IBM Cloud, or from a client connected to the VPC private network through a VPN or IBM Cloud Direct Link connection.
Before you begin
- Install the required CLI tools.
- Set up one of the following connections to the VPC private network.
- Verify your cluster is healthy:
ibmcloud oc cluster get -c CLUSTER_NAME_OR_ID.
Accessing a private VPC cluster from the CLI
For regions other than ca-mon, in-che, and in-mum, the private service endpoint can be accessed from anywhere inside IBM Cloud, or from a client using a VPN to connect to IBM Cloud.
The private service endpoint URL for a cluster looks like c<XXX>.private.<REGION>.containers.cloud.ibm.com:XXXXX. Use the following command to get a kubeconfig that uses this private endpoint.
-
Download the kubeconfig for the cluster using the private endpoint.
Log in as admin:
ibmcloud oc cluster config -c CLUSTER_NAME_OR_ID --admin --endpoint privateLog in with an API key: See Accessing clusters from automation tools.
Log in with a passcode:
- Get the Private Service Endpoint URL from the output of
ibmcloud oc cluster get -c CLUSTER_NAME_OR_ID. - Open https://iam.cloud.ibm.com/identity/passcode and copy your one-time passcode.
- Log in to the cluster.
oc login -u passcode -p IAM_PASSCODE --server=PRIVATE_SERVICE_ENDPOINT_URL
- Get the Private Service Endpoint URL from the output of
-
Verify the connection.
oc get nodes
Accessing through the Virtual Private Endpoint (VPE) gateway
VPC clusters also support access through a VPE gateway, which is available from inside the VPC or via a VPN into that specific VPC. See Accessing VPC clusters through the Virtual Private Endpoint gateway.