Access
Give kubectl access
Give a teammate time-limited kubectl access to a cluster, in the browser or from their own computer.
About 5 minutes
With Beam you give a teammate kubectl access to one cluster for a set time, limited to the namespaces you pick. Nobody gets a permanent kubeconfig. When the time ends, the browser and laptop sessions end, and Zaysa deletes the temporary Kubernetes identity from the cluster within 15 minutes. Revoking does both at once.
Before you start
- The Pro or Business plan. Just-in-time team access is not on Free.
- The cluster is connected through a connector. See Connect a Kubernetes cluster.
- You are the organization’s owner. Owners grant access; owners and admins can change how people connect.
- The teammate is a member of your organization.
Grant access
Open the cluster in Beam
Open Beam → Kubernetes Access. Each connected cluster has a card. Click Grant access on it (1).
Choose who, what and for how long
- Teammate: the person who gets access.
- Privileges: Read, Write or Admin. They map to Kubernetes’ built-in
view,editandadminroles. - Namespace(s): click each namespace to include. Leave Cluster-wide off unless the person needs every namespace.
- Expires in (min): how long the access lasts, from 5 minutes to 8 hours.
Click Grant. Zaysa creates a temporary ServiceAccount in
beam-systemand binds it to the role you chose, in those namespaces only.
Cluster-wide Admin
cluster-admin. The connector cannot grant that unless you install the separate cluster-admin add-on in the cluster. Everything else, including Autopilot, works without it.Use it in the browser
The teammate opens Beam → My Access and clicks Open terminal on the grant. A terminal opens with kubectl ready (k works too). The session is recorded, and it ends when the grant expires.
In this example the grant is Read on shop: listing pods in shop works, while other namespaces, deleting and reading Secrets are refused by the cluster itself.
Use it from their own computer
For tools like Helm or Lens, the teammate clicks Connect from your computer on the same grant and follows the three steps shown:
- Download the helper once. It needs Node.js 22 or later.
- Run the
node zaysa.mjs connect …command shown and leave it open. The ticket in it is only for this person and this grant. - Click Get kubeconfig on the grant and use that file with
kubectl, Helm or Lens. It points at the address the helper shows.
curl -fsSL https://zaysa.io/zaysa.mjs -o zaysa.mjs
node zaysa.mjs connect <ticket shown in Zaysa>The connection goes through Zaysa’s relay to the connector in the cluster. The cluster API does not need to be reachable from the internet.
Choose how people may connect
On Beam → Kubernetes Access, the How people connect card has two ways (see the picture above):
| Way | Setting |
|---|---|
| Browser terminal (recorded) | Always on. |
| From their own computer (Helm, Lens…) | On by default. Turn the switch (3) off to allow only the browser terminal for every cluster in your organization. |
To allow only the browser terminal for one cluster, click the gear icon on its card (2) and turn on Browser terminal only. Turning laptop access off stops new tickets at once. A session that is already open ends when its ticket or grant ends.
Revoke access early
Open Beam → Team Access, find the grant and click Revoke. A teammate can also end their own access with Revoke my access on the grant. Open sessions are cut and the temporary ServiceAccount is deleted from the cluster.
If something goes wrong
“Error from server (Forbidden)”
The grant does not cover that namespace or action. Grant again with the namespace or privilege needed.
“Laptop access is turned off for this cluster”
Laptop access is off for your organization or this cluster. Use Open terminal, or ask an owner or admin to change the switch.