techlite/gke-iap-proxy

1.0.0

endpoint/tcp

SOCKS proxy to a private control plane, through an IAP tunnel on a bastion

provider

How to use

dependencies:
  myEndpoint:
    provider: techlite/gke-iap-proxy@^1.0.0

↓ Download YAML 4

Opens an IAP tunnel to a bastion and exposes its SSH dynamic forward as a SOCKS proxy on port 1080 — the way into a GKE control plane that has no public IP, without the pipeline's machine holding any standing network access.

The consuming step composes the address itself, e.g. `k8s_proxy_url: "socks5://${dependencies.clusterProxy.address}"` — the provider only guarantees a live SOCKS endpoint for exactly as long as the step runs.