techlite/gke-iap-proxy
1.0.0
endpoint/tcpSOCKS proxy to a private control plane, through an IAP tunnel on a bastion
provider
How to use
dependencies:
myEndpoint:
provider: techlite/gke-iap-proxy@^1.0.0Opens an IAP tunnel to a bastion and exposes its SSH dynamic forward as a SOCKS proxy on port 1080 — the way into a GKE control plane that has no public IP, without the pipeline's machine holding any standing network access.
The consuming step composes the address itself, e.g. `k8s_proxy_url: "socks5://${dependencies.clusterProxy.address}"` — the provider only guarantees a live SOCKS endpoint for exactly as long as the step runs.
Provides
The endpoint type is the whole interface: the consuming task declares it, and how the address is reached is this provider’s business.
endpoint/tcp
Inputs
They parameterize the PATH — validated against this schema and templated into the args. A value that resolved secret is refused: argv is no place for a credential.
| dependency | type | |
|---|---|---|
bastionrequired | string | The bastion instance's name |
zonerequired | string | |
projectrequired | string | |
userrequired | string | The remote user whose key the bastion knows. Prefer a dedicated account (e.g. `pipeline`) over a person's login: the key is shared by whoever runs the pipeline, and the bastion's auth log should say so. |
What the service itself consumes
Declared by the provider and wired by the pipeline, a step’s own grammar. This list is what the consent gate prices.
| dependency | type | placement | privilege | |
|---|---|---|---|---|
gcloudToken | secret | CLOUDSDK_AUTH_ACCESS_TOKEN | medium | Short-lived token able to open IAP tunnels to the bastion. |
sshKey | secret-file | /keys/id | medium | The PRIVATE key, as content — the public half is derived. |
Runtime
The service, as the document declares it: the image that runs, and the port whose readiness gates the step. The port is the author’s declaration, not runtime discovery.
| image | google/cloud-sdk:slim |
| port | 1080 |
Args
The command the service starts with, one argument per line. Inputs arrive templated here.
sh
-c
mkdir -p /root/.ssh
cp /keys/id /root/.ssh/google_compute_engine
chmod 600 /root/.ssh/google_compute_engine
ssh-keygen -y -f /root/.ssh/google_compute_engine \
> /root/.ssh/google_compute_engine.pub
attempt=1
while [ $attempt -le 4 ]; do
gcloud --quiet compute ssh ${inputs.user}@${inputs.bastion} \
--project=${inputs.project} \
--zone=${inputs.zone} \
--tunnel-through-iap \
--ssh-flag="-D 0.0.0.0:1080 -N" && exit 0
echo "tunnel attempt $attempt failed; retrying" >&2
attempt=$((attempt+1))
sleep 8
done
exit 1