Kết nối thông qua Cloudflare Access bằng kubectl Connect through Cloudflare Access using kubectl ការភ្ជាប់តាម Cloudflare Access ដោយប្រើ kubectl
Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។
← Danh mục ← Catalog ← បញ្ជីGiải thích nhanh Quick context បរិបទរហ័ស
Thuộc Cloudflare One — Zero Trust, truy cập an toàn và kiểm soát traffic người dùng/thiết bị. Tutorial «Kết nối through Cloudflare Access using kubectl» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Đọc phần tóm tắt và lưu ý trước — sau đó mở docs gốc để copy lệnh và cấu hình chi tiết.
Connecting to Cloudflare's network using kubectl. Create a Zero Trust policy for your machine. Create an outbound-only connection between your machine and Cloudflared's network.
ការតភ្ជាប់ជាមួយបណ្តាញ Cloudflare ដោយប្រើ kubectl ។ បានបង្កើតគោលការណ៍ Zero Trust សម្រាប់ម៉ាស៊ីនរបស់អ្នក។ បានបង្កើតការតភ្ជាប់តែខាងក្រៅរវាងម៉ាស៊ីនរបស់អ្នកនិងបណ្តាញរបស់ Cloudflared ។
Lưu ý Note ចំណាំ
Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម
- Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
- Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
- Zero Trust thường cần quyền admin trên tenant Cloudflare One và IdP đã kết nối.
- Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
- This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
- Open the Official docs link below for CLI commands, code snippets, and full screenshots.
- Zero Trust typically requires Cloudflare One tenant admin access and a connected IdP.
- Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
- នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
- ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
- Zero Trust ជាទូទៅតម្រូវការ Cloudflare One អ្នកគ្រប់គ្រងហិរញ្ញវត្ថុ access និង IdP ។
- Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។
Tài liệu gốc — rà soát lần cuối: almost 4 years ago Official docs — last reviewed: almost 4 years ago ឯកសារផ្លូវការ — ពិនិត្យចុងក្រោយ: almost 4 years ago
Overview Overview Overview
Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
kubectl bằng cách sử dụng nền tảng Cloudflare của Zero Trust.kubectl using Cloudflare's Zero Trust platform.kubectl ដោយប្រើវេទិកា Zero Trust នៃ Cloudflare ។- Tạo một chính sách trong Cloudflare Access để bảo mật máy
- Kết nối máy với mạng Cloudflare bằng kubectl
- Kết nối từ máy khách
- Build a policy in Cloudflare Access to secure the machine
- Connect a machine to Cloudflare's network using kubectl
- Connect from a client machine
- បានបង្កើតគោលនយោបាយនៅក្នុង Cloudflare Access ដើម្បីសុវត្ថិភាពម៉ាស៊ីន
- ការផ្លាស់ប្តូរកុំព្យូទ័រទៅលើបណ្តាញ Cloudflare ដោយប្រើ kubectl
- ការភ្ជាប់ពីម៉ាស៊ីនអតិថិជន
Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Tạo chính sách Access Create an Access policy ការបង្កើតគោលនយោបាយ Access
Phần «Tạo Access policy» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Create an Access policy" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ការបង្កើតគោលនយោបាយ Access» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Trong Cloudflare dashboard ↗, đi đến Zero Trust \> Access controls \> Applications.
- Chọn Create new application
- Chọn Self-hosted and private
- Chọn Add public hostname và input là một tên miền con. Đây sẽ là tên máy chủ nơi ứng dụng của bạn sẽ có sẵn cho người dùng.
- Create a new policy để kiểm soát ai có thể truy cập ứng dụng, hoặc chọn các chính sách hiện có.
- Làm theo phần còn lại self-hosted application creation steps để xuất bản ứng dụng.
- In the Cloudflare dashboard ↗, go to Zero Trust \> Access controls \> Applications.
- Select Create new application.
- Select Self-hosted and private.
- Select Add public hostname and input a subdomain. This will be the hostname where your application will be available to users.
- Create a new policy to control who can reach the application, or select existing policies.
- Follow the remaining self-hosted application creation steps to publish the application.
- ក្នុង Cloudflare dashboard ↗ សូមចូលទៅទៅ Zero Trust \> Access controls \> Applications ។
- សូមជ្រើស Create new application ។
- សូមជ្រើស Self-hosted and private ។
- ជ្រើសរើស Add public hostname និង input ជាឧបករណ៍។ នេះនឹងជាឈ្មោះក្រុមហ៊ុនផ្គត់ផ្គង់ដែលកម្មវិធីរបស់អ្នកនឹងអាចរកបានសម្រាប់អ្នកប្រើ។
- Create a new policy ដើម្បីត្រួតពិនិត្យអ្នកដែលអាចចូលទៅក្នុងកម្មវិធីឬជ្រើសរើសគោលនយោបាយដែលមាន។
- បន្ទាប់ពី self-hosted application creation steps ដើម្បីបង្ហាញកម្មវិធីនេះ។
Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Cài đặt cloudflared Install cloudflared ទាញយក CloudFlared
Phần «Cài đặt cloudflared» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Install cloudflared" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ទាញយក CloudFlared» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
cloudflared. Tải xuống và cài đặt cloudflared trên máy DigitalOcean bằng cách làm theo các hướng dẫn được liệt kê trên trang Downloads.cloudflared. Download and install cloudflared on the DigitalOcean machine by following the instructions listed on the Downloads page.cloudflared ។ ទាញយកនិងដំឡើង cloudflared នៅលើម៉ាស៊ីន DigitalOcean ដោយធ្វើដូចម្តេចដែលបានបង្ហាញនៅលើទំព័រ Downloads ។Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Cloudflared xác thực Authenticate cloudflared អាកាសធាតុ Cloudflared
Phần «Authenticate cloudflared» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Authenticate cloudflared" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «អាកាសធាតុ Cloudflared» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
cloudflared tunnel login cloudflared sẽ mở ra một cửa sổ trình duyệt và nhắc bạn đăng nhập vào tài khoản Cloudflare của bạn. Nếu bạn đang làm việc trên máy mà không có trình duyệt, hoặc một cửa sổ trình duyệt không khởi động, bạn có thể sao chép URL từ đầu ra dòng lệnh và truy cập URL trong một trình duyệt trên bất kỳ máy nào.cloudflared will open a browser window and prompt you to log in to your Cloudflare account. If you are working on a machine that does not have a browser, or a browser window does not launch, you can copy the URL from the command-line output and visit the URL in a browser on any machine.cloudflared នឹងផ្លាស់ប្តូរបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិលបង្វិល ប្រសិនបើអ្នកកំពុងធ្វើការនៅលើម៉ាស៊ីនដែលមិនមានបណ្តាញឬបង្វិលបណ្តាញមិនបើកដំណើរការអ្នកអាចកាត់បន្ថយ URL ពីការនាំចេញបន្ទាត់គោលបំណងហើយស្វែងរក URL នៅក្នុងបណ្តាញនៅលើម៉ាស៊ីនណាមួយ។Tạo một Tunnel Create a Tunnel បានបង្កើត Tunnel
Phần «Tạo Tunnel» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Create a Tunnel" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «បានបង្កើត Tunnel» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
cloudflared tunnel create <NAME> <NAME> bằng tên Tunnel. Tên này có thể là bất kỳ giá trị. Một Tunnel duy nhất cũng có thể phục vụ lưu lượng truy cập cho nhiều tên máy chủ đến nhiều dịch vụ trong môi trường của bạn, bao gồm một hỗn hợp các loại kết nối như SSH và HTTP.<NAME> with a name for the Tunnel. This name can be any value. A single Tunnel can also serve traffic for multiple hostnames to multiple services in your environment, including a mix of connection types like SSH and HTTP.<NAME> ដោយឈ្មោះសម្រាប់ Tunnel ។ ឈ្មោះនេះអាចជាតម្លៃណាមួយ។ មួយ Tunnel អាចផ្គត់ផ្គង់ការដឹកជញ្ជូនសម្រាប់ឈ្មោះហ្គេមជាច្រើនទៅកាន់សេវាកម្មជាច្រើននៅក្នុងបរិស្ថានរបស់អ្នក, រួមទាំងប្រភេទទំនាក់ទំនងដូចជា SSH និង HTTP ។cloudflared tunnel list Cài đặt Tunnel Configure the Tunnel ទាញយក Tunnel
Phần «Cấu hình Tunnel» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Configure the Tunnel" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ទាញយក Tunnel» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
YAML mà cloudflared có thể đạt được. Theo mặc định, cloudflared sẽ tìm kiếm tệp trong cùng một thư mục nơi cloudflared đã được cài đặt.YAML file that cloudflared can reach. By default, cloudflared will look for the file in the same folder where cloudflared has been installed.YAML ដែល cloudflared អាចទទួលបាន។ ជាទូទៅ, cloudflared នឹងស្វែងរកឯកសារនៅក្នុងឯកសារដូចគ្នាដែល cloudflared ត្រូវបានដំឡើង។vim ~/.cloudflared/config.yml tunnel: 6ff42ae2-765d-4adf-8112-31c55c1551ef
credentials-file: /root/.cloudflared/6ff42ae2-765d-4adf-8112-31c55c1551ef.json
ingress:
- hostname: azure.widgetcorp.tech
service: tcp://kubernetes.docker.internal:6443
originRequest:
proxyType: socks
- service: http_status:404
# Catch-all rule, which responds with 404 if traffic doesn't match any of
# the earlier rules Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Đường đến Tunnel Route to the Tunnel ផ្លូវទៅ Tunnel
Phần «Route to Tunnel» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Route to the Tunnel" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ផ្លូវទៅ Tunnel» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Đăng nhập vào Cloudflare dashboard ↗ và đi đến trang DNS Records cho tên miền của bạn.
- Log in to the Cloudflare dashboard ↗ and go to the DNS Records page for your domain.
- សូមចូលទៅក្នុង Cloudflare dashboard ↗ និងចូលទៅក្នុងទំព័រ DNS Records សម្រាប់ឧបករណ៍របស់អ្នក។
- Chọn Add record Chọn
CNAMElàm loại bản ghi. Đối với Name, hãy chọn tên máy chủ mà bạn muốn tạo Tunnel. Điều này nên khớp với tên máy chủ của chính sách Access. - Đối với Target, input là ID của bạn Tunnel tiếp theo là
.cfargotunnel.com. Ví dụ:
- Select Add record. Choose
CNAMEas the record type. For Name, choose the hostname where you want to create a Tunnel. This should match the hostname of the Access policy. - For Target, input the ID of your Tunnel followed by
.cfargotunnel.com. For example:
- សូមជ្រើស Add record ។ សូមជ្រើស
CNAMEជាប្រភេទសៀវភៅ។ សម្រាប់ Name, ជ្រើសឈ្មោះហ្គេមដែលអ្នកចង់បង្កើត Tunnel ។ នេះគួរតែត្រឹមត្រូវជាមួយឈ្មោះហ្គេមរបស់គោលការណ៍ Access ។ - សម្រាប់ Target, input គឺជា ID របស់អ្នក Tunnel បន្ទាប់ពី
.cfargotunnel.com។ ឧទាហរណ៍ :
6ff42ae2-765d-4adf-8112-31c55c1551ef.cfargotunnel.com - Chọn Save
- Select Save.
- សូមជ្រើស Save ។
Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Chạy Tunnel Run the Tunnel ទាញយក Tunnel
Phần «Chạy Tunnel» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Run the Tunnel" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ទាញយក Tunnel» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
<NAME> bằng tên được tạo cho Tunnel của bạn.<NAME> with the name created for your Tunnel.<NAME> ជាមួយនឹងឈ្មោះដែលបានបង្កើតឡើងសម្រាប់ Tunnel ។cloudflared tunnel run <NAME> cloudflared as a service được cấu hình để khởi động khi khởi động.cloudflared as a service that is configured to launch on start.cloudflared as a service ដែលត្រូវបានកំណត់ដើម្បីចាប់ផ្តើមនៅពេលចាប់ផ្តើម។Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Kết nối từ máy khách Connect from a client machine ការភ្ជាប់ពីម៉ាស៊ីនអតិថិជន
Phần «Kết nối từ client machine» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Connect from a client machine" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ការភ្ជាប់ពីម៉ាស៊ីនអតិថិជន» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
cloudflared.cloudflared.cloudflared ។cloudflared bằng lệnh sau bằng cách sử dụng Homebrew.cloudflared with the following command using Homebrew.cloudflared ជាមួយនឹងការបញ្ជាក់ដូចខាងក្រោមដោយប្រើ Homebrew ។brew install cloudflared cloudflared access tcp --hostname azure.widgetcorp.tech --url 127.0.0.1:1234 kubectl và cloudflared sẽ khởi động một cửa sổ trình duyệt và yêu cầu người dùng xác thực với nhà cung cấp SSO của bạn. Sau khi xác thực, cloudflared sẽ phơi bày kết nối với máy khách tại URL địa phương được chỉ định trong lệnh.kubectl command and cloudflared will launch a browser window and prompt the user to authenticate with your SSO provider. Once authenticated, cloudflared will expose the connection to the client machine at the local URL specified in the command.kubectl និង cloudflared នឹងបើកដំណើរការបង្វិលបង្វិលបង្វិលបង្វិលនិងបង្វិលអ្នកប្រើដើម្បីធ្វើការអនុម័តជាមួយអ្នកផ្គត់ផ្គង់ SSO របស់អ្នក។ នៅពេលដែលការអនុម័ត cloudflared នឹងបង្ហាញការតភ្ជាប់ទៅនឹងម៉ាស៊ីនអតិថិជននៅលើអាសយដ្ឋានអ៊ីនធឺណិតដែលបានបង្ហាញនៅក្នុងការអនុញ្ញាត។kubeconfig không hỗ trợ cấu hình lệnh proxy tại thời điểm này, mặc dù cộng đồng đã gửi kế hoạch để làm như vậy. Trong khi đó, người dùng có thể alias máy chủ API của cụm để tiết kiệm thời gian.kubeconfig does not support proxy command configurations at this time, though the community has submitted plans to do so. In the interim, users can alias the cluster's API server to save time.kubeconfig មិនគាំទ្រការកំណត់ផែនការ proxy នៅពេលនេះប៉ុន្តែសហគមន៍បានបញ្ជូនគម្រោងដើម្បីធ្វើដូច្នេះ។ ក្នុងអំឡុងពេលនេះអ្នកប្រើប្រាស់អាចអេឡិចត្រូនិ API អ្នកផ្គត់ផ្គង់កម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិតកម្រិត។alias kubeone="env HTTPS_PROXY=socks5://127.0.0.1:1234 kubectl" {"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/cloudflare-one/","name":"Cloudflare One"}},{"@type":"ListItem","position":3,"item":{"@id":"/cloudflare-one/tutorials/","name":"Tutorials"}},{"@type":"ListItem","position":4,"item":{"@id":"/cloudflare-one/tutorials/kubectl/","name":"Connect through Cloudflare Access using kubectl"}}]} Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។
Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗