Technology · Ebook
Paralus: Zero-Trust Access for Kubernetes
by Shriira Press
Paralus is a free, open-source CNCF sandbox project that solves a quiet but dangerous problem: who can reach your Kubernetes clusters, with what permissions, and can you prove it afterward. Instead of long-lived kubeconfigs and static tokens scattered across laptops and pipelines, it offers just-in-time, RBAC-aware kubectl access from a single control plane, with every action audited. This book builds the system from the ground up — the access problem it fixes, its control-plane-and-relay-agent architecture, the mutual-TLS zero-trust tunnel, single sign-on and the project-and-role model, kubeconfig-as-a-service through pctl and the in-browser prompt, central audit logging, and finally installing and operating Paralus for real.
Contents
- 1Preface
- 2Chapter 1 — The Kubernetes Access Problem
- 3Chapter 2 — Architecture: Control Plane and Relay
- 4Chapter 3 — The Zero-Trust Tunnel
- 5Chapter 4 — Identity, Projects, and Roles
- 6Chapter 5 — Kubeconfig as a Service
- 7Chapter 6 — Audit Logs and Compliance
- 8Chapter 7 — Paralus in Practice
