kbatch-proxy
A simple Kubernetes proxy, allowing JupyterHub users to make requests to the Kubernetes API without having direct access to the Kubernetes API.
Motivation
We want kbatch users to be able to create Kubernetes Jobs, access logs, etc., but
- Don't want to grant them direct access to the Kubernetes API
- Don't want to maintain a separate web application, with any state that's independent of Kubernetes
Enter kbatch-proxy
Design
A simple FastAPI application that sits in between kbatch users and the Kubernetes API. It's expected that the kbatch-proxy
application has access to the Kubernetes API, with permission to create namespaces, jobs, etc. This will often be run as a JupyterHub service.
Users will make requests to kbatch-proxy. Upon request we will
- Validate that the user is authenticated with JupyterHub (checking the
Bearertoken) - Validate that data the user is submitting or requesting meets our security model
- Make the request to the Kubernetes API on behalf of the user
Security model
This remains to be proven effective, but the hope is to let users do whatever they want in their own namespace and nothing outside of their namespace.
Container images
We provide container images at https://github.com/kbatch-dev/kbatch/pkgs/container/kbatch-proxy.
$ docker pull ghcr.io/kbatch-dev/kbatch-proxy:latest
Deployment
kbatch-proxy is most easily deployed as a JupyterHub service using Helm. A few values need to be configured:
# file: config.yaml
app:
jupyterhub_api_token: "<jupyterhub-api-token>"
jupyterhub_api_url: "https://<jupyterhub-url>/hub/api/"
extra_env:
KBATCH_PREFIX: "/services/kbatch"
# image:
# tag: "0.1.4" # you likely want to pin the latest here.
Note: we don't currently publish a helm chart, so you have to git clone the kbatch repository.
From the kbatch/kbatch-proxy directory, use helm to install the chart
$ helm upgrade --install kbatch-proxy ../helm/kbatch-proxy/ \
-n "<namepsace> \
-f config.yaml
You'll need to configure kbatch as a JupyterHub service. This example makes it available at /services/kbatch (this should match KBATCH_PREFIX above):
jupyterhub:
hub:
services:
kbatch:
admin: true
api_token: "<jupyterhub-api-token>" # match the api token above
url: "http://kbatch-proxy.<kbatch-namespace>.svc.cluster.local"
That example relies on kbatch being deployed to the same Kubernetes cluster as JupyterHub, so JupyterHub can proxy requests to kbatch-proxy using Kubernetes' internal DNS. The namespace in that URL should match the namespace where kbatch was deployed.
Dask Gateway Integration
If your JupyterHub is deployed with Dask Gateway, you might want to set a few additional environment variables in the job so that they behave similarly to the singleuser notebook pod.
app:
extra_env:
KBATCH_JOB_EXTRA_ENV: |
{
"DASK_GATEWAY__AUTH__TYPE": "jupyterhub",
"DASK_GATEWAY__CLUSTER__OPTIONS__IMAGE": "{JUPYTER_IMAGE_SPEC}",
"DASK_GATEWAY__ADDRESS": "https://<JUPYTERHUB_URL>/services/dask-gateway",
"DASK_GATEWAY__PROXY_ADDRESS": "gateway://<DASK_GATEWAY_ADDRESS>:80"
}
Development setup
We don't have a fully working docker-ized setup, since we (i.e. Tom) don't know how to do Kubernetes within docker. So the current setup relies on
- k3d for Kubernetes
- JupyterHub as a regular Python process
- kbatch-proxy as a regular Python process
Create a cluster
$ k3d cluster create ksubmit
Create a Hub
make sure to npm install configurable-http-proxy.
$ cd hub
$ jupyterhub
Start kbatch-proxy
KBATCH_PREFIX=/services/kbatch \
KBATCH_PROFILE_FILE=tests/profile_template.yaml \
JUPYTERHUB_API_TOKEN=super-secret \
JUPYTERHUB_API_URL=http://127.0.0.1:8000/hub/api \
JUPYTERHUB_HOST=http://127.0.0.1:8000 \
uvicorn kbatch_proxy.main:app --reload --port=8050
You'll might want to log in and create a token at http://localhost:8000/hub/token. The kbatch configure with that token.
Release files for kbatch-proxy 0.4.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| kbatch-proxy-0.4.2.tar.gz | 14.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| kbatch_proxy-0.4.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.2 kB
Release files / kbatch-proxy-0.4.2.tar.gz
| Download URL | kbatch-proxy-0.4.2.tar.gz |
|---|---|
| Size | 14.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cf81fa29616e2e798453528b705f241cf9c4007bb643d2be3703812db78ff417
|
|
BLAKE2b-256 checksum How to use checksums |
ff9815818d286757414b07526f909e634037c1686827b81045c1f47c5271205e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.5
|
Release files / kbatch_proxy-0.4.2-py3-none-any.whl
| Download URL | kbatch_proxy-0.4.2-py3-none-any.whl |
|---|---|
| Size | 14.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
70970b38fca4ce5054eb0e861ad7c6136eb6be4dcf263fda1b76ae1dbeef764f
|
|
BLAKE2b-256 checksum How to use checksums |
3eceea2e797cb05d09e15cf01a94011bcad27a3ff0e86f1bce76bc78a418c2f6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/4.0.2 CPython/3.11.5
|