kube-bind Usage Guide
This section provides comprehensive documentation on how to use kube-bind's core APIs and concepts. Whether you're a service provider looking to export APIs or a consumer wanting to bind to services, this guide covers the essential workflows and components.
Core Concepts
kube-bind operates on three fundamental concepts:
Service Provider
The cluster that exports APIs and resources, making them available for other clusters to consume. Service providers label exported CRDs, grant credential RBAC, and optionally publish catalog Exports.
Service Consumer
The cluster that imports and uses APIs from service providers. Consumers apply a Connection and bindings directly, or obtain a bundle through the optional backend.
Konnector Agent
The component that establishes and maintains the secure connection between provider and consumer clusters, synchronizing resources and handling permissions.
Key API Types
Connection
Purpose: References provider credentials, discovers APIs, and controls schema delivery. Used by: Service consumers Scope: Cluster-scoped on the consumer
ClusterBinding and Binding
Purpose: Select the APIs whose instances should synchronize. Used by: Service consumers Scope: Cluster-wide or one consumer namespace
Export and Collection
Purpose: Describe and group offerings in the optional catalog. Used by: Service providers Scope: Cluster-scoped on the provider
Grant
Purpose: Record issued credentials and resolved APIs. Used by: The optional backend's gateway and issuer Scope: Cluster-scoped on the provider
Documentation Structure
API Concepts
Deep dive into the core API types, their relationships, and how they work together in the kube-bind ecosystem.
Catalog and Grants
Publish offerings, issue credentials, and inspect connected consumers.
Common Workflows
For Service Providers
- Export APIs with CRD labels and RBAC, optionally describing them as catalog Exports.
- Implement service to act on the synced/bound objects so it can be returned to the consumer/user.
For Service Consumers
- Authenticate to the kube-bind backend
- Discover available Exports through the web UI or CLI
- Request a bundle for a specific Export and apply it to the consumer
- Use imported APIs in their local cluster
The core-only alternative is to supply credentials and bindings directly through GitOps, with no backend login.
For Platform Operators
- Deploy the konnector on the consumer and the optional backend on the provider
- Configure authentication and security policies
- Monitor connections and resource synchronization
Getting Started
If you're new to kube-bind:
- Start with the Quickstart Guide for a hands-on introduction
- Review API Concepts to understand the fundamental types
- Check the Reference Documentation for complete API specifications
The konnector agents establish a secure, authenticated connection that allows:
- API schema synchronization from provider to consumer
- Spec up / status down resource data flow
- Selected Secret and ConfigMap synchronization
- Provider access governed by credential RBAC
The stock syncer does not rename namespaces or convert resource scope. Review synchronization when designing a shared provider.