# Explicit use of sudo in MicroK8s CLI

**URL:** <https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605>\
**Category:** microk8s\
**Created:** [August 20, 2019, 3:06pm UTC](https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605 "2019-08-20T15:06:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kjackal](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/kjackal/32/1750_2.png) [@kjackal](https://discuss.kubernetes.io/u/kjackal)\
**Post date:** [August 20, 2019, 3:06pm UTC](https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605/1 "2019-08-20T15:06:18Z")

</div>

With the upcoming v1.15.3 release, MicroK8s commands will require the use of sudo whenever elevated privileges are needed. For example, `microk8s.kubectl` by default authenticates you as a Kubernetes administrator and will therefore be restricted to sudo users only.

This change was made to improve the overall security of MicroK8s. Authors of scripts that use `microk8s.` commands may wish to test their scripts with an updated MicroK8s build . The `edge` channel already contains these changes; give them a try with:

```auto
sudo snap install microk8s --classic --edge

```

For more information on MicroK8s consult the official [docs](https://microk8s.io/docs/), and to contribute to the project, check out the repo at [https://github.com/ubuntu/microk8s](https://github.com/ubuntu/microk8s), or chat with us on the [Kubernetes Slack](http://slack.kubernetes.io/), in the #microk8s channel.

**[UPDATE]**  
Based on the feedback we got from the community we introduced a linux user group called “microk8s”. Users of this group are able to access MicroK8s with no restrictions (no need for sudo). Add your user to the group with:

```auto
sudo usermod -a -G microk8s $USER

```

Thank you

---

<div class="post-metadata">

**Author:** ![Danielo\_Rodriguez](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/danielo_rodriguez/32/6111_2.png) [@Danielo\_Rodriguez](https://discuss.kubernetes.io/u/Danielo_Rodriguez)\
**Post date:** [October 27, 2020, 9:45am UTC](https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605/2 "2020-10-27T09:45:21Z")

</div>

This is cool and working as expected. But then why is it asking for sudo password when I enable the dashboard? `microk8s.enable dashboard`  
It does not attaches itself to any restricted port, so I don’t see the need

---

<div class="post-metadata">

**Author:** ![balchua1](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/balchua1/32/5372_2.png) [@balchua1](https://discuss.kubernetes.io/u/balchua1)\
**Post date:** [October 31, 2020, 12:29pm UTC](https://discuss.kubernetes.io/t/explicit-use-of-sudo-in-microk8s-cli/7605/3 "2020-10-31T12:29:39Z")

</div>

This is because the dashboard addon also enables the metrics server, to get the cluster metrics such as cpu and memory.

The metrics server addon adds the `authentication-token-webhook` options in the apiserver. Followed by a restart of the apiserver.

Restarting the apiserver needs sudo permission.
