3.9 KiB
title | description | cascade | menu | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Install the Pinniped Supervisor | Install the Pinniped Supervisor service in a Kubernetes cluster. |
|
|
This guide shows you how to install the Pinniped Supervisor, which allows seamless login across one or many Kubernetes clusters. You should have a supported Kubernetes cluster with working HTTPS ingress capabilities.
In the examples below, you can replace {{< latestversion >}} with your preferred version number. You can find a list of Pinniped releases on GitHub.
With default options
Using kapp
-
Install the latest version of the Supervisor into the
pinniped-supervisor
namespace with default options using kapp:kapp deploy --app pinniped-supervisor --file https://get.pinniped.dev/{{< latestversion >}}/install-pinniped-supervisor.yaml
Using kubectl
-
Install the latest version of the Supervisor into the
pinniped-supervisor
namespace with default options:kubectl apply -f https://get.pinniped.dev/{{< latestversion >}}/install-pinniped-supervisor.yaml
With custom options
Pinniped uses ytt from Carvel as a templating system.
-
Install the
ytt
andkapp
command-line tools using the instructions from the Carvel documentation. -
Clone the Pinniped GitHub repository and visit the
deploy/supervisor
directory:git clone git@github.com:vmware-tanzu/pinniped.git
cd pinniped/deploy/supervisor
-
Decide which release version you would like to install. All release versions are listed on GitHub.
-
Checkout your preferred version tag, e.g.
{{< latestversion >}}
:git checkout {{< latestversion >}}
-
Customize configuration parameters:
-
See the default values for documentation about individual configuration parameters. For example, you can change the number of Concierge pods by setting
replicas
or apply custom annotations to the impersonation proxy service usingimpersonation_proxy_spec
. -
In a different directory, create a new YAML file to contain your site-specific configuration. For example, you might call this file
site/dev-env.yaml
.In the file, add the special ytt comment for a values file and the YAML triple-dash which starts a new YAML document. Then add custom overrides for any of the parameters from
values.yaml
.Override the
image_tag
value to match your preferred version tag, e.g.{{< latestversion >}}
, to ensure that you use the version of the server which matches these templates.Here is an example which overrides the image tag, the default logging level, and the number of replicas:
#@data/values --- image_tag: {{< latestversion >}} log_level: debug replicas: 1
-
Parameters for which you would like to use the default value should be excluded from this file.
-
If you are using a GitOps-style workflow to manage the installation of Pinniped, then you may wish to commit this new YAML file to your GitOps repository.
-
-
Render templated YAML manifests:
ytt --file . --file site/dev-env.yaml
By putting the override file last in the list of
--file
options, it will override the default values. -
Deploy the templated YAML manifests:
ytt --file . --file site/dev-env.yaml | kapp deploy --app pinniped-supervisor --file -
Next steps
Next, [configure the Supervisor as an OIDC issuer]({{< ref "configure-supervisor" >}})!