# Multi-user MicroK8s

**URL:** <https://discuss.kubernetes.io/t/multi-user-microk8s/13275>\
**Category:** microk8s\
**Tags:** docs\
**Created:** [October 15, 2020, 1:40pm UTC](https://discuss.kubernetes.io/t/multi-user-microk8s/13275 "2020-10-15T13:40:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![evilnick](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/evilnick/32/3481_2.png) [@evilnick](https://discuss.kubernetes.io/u/evilnick)\
**Post date:** [October 15, 2020, 1:40pm UTC](https://discuss.kubernetes.io/t/multi-user-microk8s/13275/1 "2020-10-15T13:40:04Z")

</div>

MicroK8s is inherently multi-user capable in the sense that any user added to  
the `microk8s` group can run commands against the cluster.

In some circumstances, it may be desirable to have a degree of user-isolation, e.g. when multiple users are accessing a MicroK8s cluster. MicroK8s is a full implementation of Kubernetes, and therefore any existing strategy for handling multiple users can be applied. There is extensive upstream [documentation](https://kubernetes.io/docs/reference/access-authn-authz/authentication/) relating to managing users.

> Note: If you are using the built-in dashboard addon, see the following docs to configure your user access: [dashboard/docs/user/access-control/creating-sample-user.md at master · kubernetes/dashboard · GitHub](https://github.com/kubernetes/dashboard/blob/master/docs/user/access-control/creating-sample-user.md)

As a guide though, the following steps are recommended.

1. Enable Role Based Access Control (RBAC):

```bash
microk8s enable rbac

```

1. If required, create a specific namespace for the user (in this case, ‘alice’) by generating and applying a namespace object such as:

namespace.json:

```json
{
  "apiVersion": "v1",
  "kind": "Namespace",
  "metadata": {
    "name": "alice",
    "labels": {
      "name": "alice"
    }
  }
}

```

```bash
microk8s kubectl apply -f namespace.json

```

1. Create and apply a rolebinding

RBAC uses roles to control what aspects of a namespace can be viewed and/or modified. (see upstream [rbac documentation](https://kubernetes.io/docs/reference/access-authn-authz/rbac/))

E.g to access pods:

```auto
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  namespace: alice
  name: alice-pods
rules:
- apiGroups: [""] # "" indicates the core API group
  resources: ["pods"]
  verbs: ["get", "watch", "list"]

```

To bind role this role to the user, run:

```auto
kubectl create rolebinding rolebindingname --role alice-pods --user alice

```

1. Install `kubectl`

```bash
sudo snap install kubectl

```

This installs a standalone version of the `kubectl` command, which can be used  
instead of the built-in MicroK8s version of kubectl.

1. Authenticate the user.

There are different ways of authenticating users for Kubernetes. x509 certificates are recommended. You can read the documentation for supported methods in the [upstream documentation](https://kubernetes.io/docs/reference/access-authn-authz/authentication/)

1. Create a local kubectl config

You can run the command:

```bash
microk8s config

```

…to output the contents of the configuration file used by MicroK8s. This can be used as the basis for a user config file - bear in mind that the user information and the authentication should be matched to the user and the authentication method used.

---

<div class="post-metadata">

**Author:** ![killermonk](https://avatars.discourse-cdn.com/v4/letter/k/4bbf92/32.png) [@killermonk](https://discuss.kubernetes.io/u/killermonk)\
**Post date:** [July 30, 2024, 5:24pm UTC](https://discuss.kubernetes.io/t/multi-user-microk8s/13275/2 "2024-07-30T17:24:14Z")

</div>

It is probably worth calling out the dashboard docs for integrations with RBAC. Based on github bugs, there appear to be a fair number of people (myself included) who enabled RBAC well after they’ve enabled dashboard and run into issues.

Might be worth adding a section with something like:

If you are using the built-in dashboard addon, see the following docs to configure your user access: [dashboard/docs/user/access-control/creating-sample-user.md at master · kubernetes/dashboard · GitHub](https://github.com/kubernetes/dashboard/blob/master/docs/user/access-control/creating-sample-user.md)
