Paralus: Zero-Trust Access for Kubernetes
Shriira Press
How Paralus brings controlled, audited, zero-trust access to your Kubernetes clusters — kubeconfig as a service, without the credential sprawl.
Welcome to Paralus: Zero-Trust Access for Kubernetes.
Paralus is a free, open-source CNCF sandbox project that solves one of the quietest but most dangerous problems in any Kubernetes estate: who can reach your clusters, with what permissions, and can you prove it afterward. Instead of long-lived kubeconfigs and static service-account tokens scattered across laptops and CI pipelines, Paralus offers just-in-time, RBAC-aware kubectl access driven from a single control plane, with every action recorded in an audit trail. This book walks through the whole system from the ground up. We begin with the access problem that Paralus exists to fix, then dissect its architecture — the central control plane and the per-cluster relay agent that together form a zero-trust tunnel secured by mutual TLS. From there we cover identity and single sign-on, the project-and-role model that scopes who sees what, kubeconfig-as-a-service through the pctl plugin and the in-browser prompt, and the audit logging that ties it all together. The final chapter is about running Paralus for real: installing it with Helm, importing clusters, and the operational habits that keep access both convenient and accountable.
This title is part of the ShriIra library and is free to read in full, right here — our small contribution to making world-class knowledge easy to reach.
A note on reading it: open the Contents menu at the top of the reader to jump between chapters, use the Aa menu to set a comfortable text size, theme (light, sepia, or night), and single- or two-page layout. Your place is saved automatically, so you can always pick up where you left off.
We hope it serves you well.
— Shriira Press