# Can we access k8s-cluster-1 from another k8s cluster k8s-cluster-2?

**URL:** <https://discuss.kubernetes.io/t/can-we-access-k8s-cluster-1-from-another-k8s-cluster-k8s-cluster-2/20249>\
**Category:** microk8s\
**Tags:** docs, development, minikube, network, microk8s\
**Created:** [June 7, 2022, 5:39am UTC](https://discuss.kubernetes.io/t/can-we-access-k8s-cluster-1-from-another-k8s-cluster-k8s-cluster-2/20249 "2022-06-07T05:39:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![naraen\_diran](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/naraen_diran/32/9489_2.png) [@naraen\_diran](https://discuss.kubernetes.io/u/naraen_diran)\
**Post date:** [June 7, 2022, 5:39am UTC](https://discuss.kubernetes.io/t/can-we-access-k8s-cluster-1-from-another-k8s-cluster-k8s-cluster-2/20249/1 "2022-06-07T05:39:47Z")

</div>

Do we have any steps to achieve this ? ie., Acessing one k8s cluster from another k8s cluster.

---

<div class="post-metadata">

**Author:** ![xavi](https://avatars.discourse-cdn.com/v4/letter/x/8e8cbc/32.png) [@xavi](https://discuss.kubernetes.io/u/xavi)\
**Post date:** [June 9, 2022, 4:12pm UTC](https://discuss.kubernetes.io/t/can-we-access-k8s-cluster-1-from-another-k8s-cluster-k8s-cluster-2/20249/2 "2022-06-09T16:12:05Z")

</div>

Hi naraen\_diran:

If the `k8s-cluster-1` API is **reachable** from `k8s-cluster-2`, yes, it can be done.

To connect, you need some type of [client](https://github.com/orgs/kubernetes-client/repositories); you can also use a containerized version of `kubectl` or _just_ use `curl` ([Access Clusters Using the Kubernetes API | Kubernetes](https://kubernetes.io/docs/tasks/administer-cluster/access-cluster-api/#directly-accessing-the-rest-api) )

Let’s assume that your `k8s-cluster-1` API is available at `https://k8s-cluster-1.example.org:6443/api`.  
You can create a Pod in your cluster 2 and run the equivalent to:

```nohighlight
> K8S_API=https://k8s-cluster-1.example.org:6443/api
> curl -k $K8S_API
{
  "kind": "Status",
  "apiVersion": "v1",
  "metadata": {},
  "status": "Failure",
  "message": "Unauthorized",
  "reason": "Unauthorized",
  "code": 401
}

```

Even if you receive an _Unauthorized_ reply, this reply comes from the `k8s-cluster-1` API 😉 proving that we are on the right track.

The section [“Without kubectl proxy”](https://kubernetes.io/docs/tasks/administer-cluster/access-cluster-api/#without-kubectl-proxy) shows how to generate a TOKEN and use it to authenticate the `curl` requests:

```nohighlight
# Get the token value
TOKEN=$(kubectl get secret default-token -o jsonpath='{.data.token}' | base64 --decode)

# Explore the API with TOKEN
curl -X GET $APISERVER/api --header "Authorization: Bearer $TOKEN" --insecure

```

Depending on why you need to access the `k8s-cluster-1` from the `k8s-cluster-2`, you may want to consider creating a restricted user in `k8s-cluster-1` to be used when accessing the `k8s-cluster-1`.

Hope it helps!

Xavi
