Configure Access for Portworx Backup Web Console
Before you expose the Portworx Backup web console, decide how much network access it needs. For most deployments, keep the console private and reachable only through a controlled path:
kubectl port-forwardto thepx-backup-uiservice (no external endpoint)- A private or internal ingress
- A VPN or bastion host
- A private (internal) load balancer, using your cloud provider's internal load balancer annotation
Setting the UI service type to ClusterIP, or keeping LoadBalancer with an internal load balancer annotation, prevents the console from being reachable on a public, internet-facing endpoint. For the service types, per-cloud annotations, and source-range options, see Configure Access to Portworx Backup Web Console.
On managed cloud platforms, a LoadBalancer service can create a public, internet-facing endpoint unless you request an internal load balancer. Expose the console publicly only when you specifically intend to.
If the standard Portworx Backup web console endpoint configuration does not meet your requirements, you can configure access using HTTPS, access it through the load balancer (ingress, AWS ALB), or navigate to one of your node IPs directly.
Retrieve admin credentials and sign in
To log in to the Portworx Backup web console after installation and access the configuration, retrieve the admin username and password.
-
Run the following command from your local host terminal to get the admin username from the
pxcentral-admin-userConfigMap:kubectl get cm pxcentral-admin-user -n <pxb-namespace> -o jsonpath='{.data.DEFAULT_USER_NAME}{"\n"}' -
Run the following command to get the admin password from the Keycloak secret:
kubectl get secret pxcentral-keycloak-http -n <pxb-namespace> -o jsonpath="{.data.password}" | base64 --decode && echonoteThe password is randomly generated at installation time and is unique to each deployment.
-
Access the Portworx Backup web console and enter the admin username and password retrieved in the previous steps. Upon first login, you are prompted to change the password.
-
Change the admin password with the password of your choice.
tip- Use a strong password with at least 12 characters.
- Include uppercase, lowercase, numbers, and special characters.
- Store the new password securely.
Configure access in your environment
The following topics explain how to configure and access the Portworx Backup web console in different environments:
- Configure access to UI — Configure access to the Portworx web console
- Access UI with Istio — Learn how to access Portworx Backup UI when using Istio service mesh.
- Access UI with AWS ALB — Learn how to use AWS ALB to access Portworx Backup UI