My previous blog actually introduced another Dashboard provisioning scheme. That scheme didn’t involve Dashboard secondary development. The earlier scheme suits clusters where rbac is usable; the current scheme has broader applicability — you only need a kubeconfig file to provide users a Dashboard with complete permission control.
Dashboard‘s own permission control is too weak, and its frontend pages are many and complex. To integrate it into our platform,
the frontend needs trimming and the backend’s authentication method changing. Modifications throughout should be as small as possible,
so we can update along with Dashboard‘s updates later — otherwise, when a security issue someday requires updating, patching would be hard.

This modification doesn’t require prior Dashboard experience, but you should have some understanding of K8s APIs,
then read some Dashboard code. Its frontend is Angular; its backend is Golang.
Well-written code generally has a similar style, mostly practicing table-driven methods and middleware thinking. Frontend page config files are certainly kept together; the backend certainly has middleware — we just add an authentication module.
First Get the Program Running
First you need a usable kubeconfig file, ensuring your kubectl operations work.
My previous blog introduced kubectl proxy usage; if interested, read it — I believe your understanding of Kubernetes API concepts
will deepen.
Frontend
The frontend is fairly simple to run
1 | > yarn start:frontend |
Enabling websocket Support
One thing to note: the default config read, aio/proxy.conf.json, doesn’t explicitly enable websocket,
so the shell page’s usage isn’t a long connection. If you want full-featured webshell while debugging locally too,
change it to the following.
1 | { |
Backend
I personally dislike that Golang must compile to a binary before running; I usually just
go run main.godirectly.
1 | > cd src/app/backend/ |
Then open the frontend page — there should be a full-featured Dashboard.
Frontend Page Trimming
Sidebar Trimming
The concrete code is in
src/app/frontend/chrome/nav/template.html; you can adjust the order and remove unneeded components
1 | <kd-nav-item class="kd-nav-item" |
Streamlining the search Feature
Because when the search box triggers, it searches all given resources — and a single NS may have very many pods, making the search box slow — we also hide certain components of the search logic. Of course you can also adjust the display order here.
The concrete code is in
src/app/frontend/search/template.html
1 | <kd-job-list (onchange)="onListUpdate($event)" |
Adding Backend Authentication
Authentication Location
The dashboard backend uses the go-restful library. Let’s find how it adds middleware —
it has the concept of filter:
1 | // code from https://github.com/emicklei/go-restful/blob/v3/examples/filters/restful-filters.go |
Our goal is adding several global filters to the dashboard backend for authentication and user event recording.
Now look at the dashboard code location — we just re-authenticate once for all APIs.
1 | // src/app/backend/handler/apihandler.go |
The Authentication Scheme
We use OpenID for login, but I didn’t want to develop this login module either, so I reused keycloak-gatekeeper — which, looking again recently, has stopped being maintained…
Its function is mainly filtering non-logged-in users while passing the logged-in user’s concrete information (e.g. email or username) to the backend.
Based on email and username, judge whether the current request’s namespace and api are allowed for the user.

Automatic kubeconfig Refresh
In the Kubernetes cluster we use, the kubeconfig token expires and needs periodic refreshing. This involves another Dashboard modification:
1 | // src/app/backend/dashboard.go |
To be able to update kubeconfig according to my own wishes, I added a new generator:
1 | func NewXXXClientManager(kubeConfigPath, apiserverHost string) clientapi.ClientManager { |
Summary
I’m just sharing our scheme, hoping those maintaining PaaS platforms gain something. Personally I feel PaaS platforms with strong development capability embed WebShell directly; we really have no frontend people, so we patched this together. The scheme has run stably for half a month so far — stability should be no problem.