Clusters and resources: kubeconfig, cloud accounts and RBAC
Each cluster opens with the same menu as the IDE: overview, nodes, workloads, config, network, storage, Helm and CRDs. Web and desktop accept different kubeconfigs and credentials, because the web connects from Kubepier’s server and the desktop from your machine; either way the credential’s RBAC applies, and you can start with a read-only ServiceAccount.
What it does
- Failing pods and warning events rise to the top.
- CPU and memory per cluster, node and namespace: on the web, from the cluster’s metrics-server; on desktop, from the Prometheus of the provider picked under the cluster Settings › Metrics (Lens Metrics, for example), or from metrics-server when there is no Prometheus.
- Every CronJob shows its last run and whether it is suspended; every Job, whether it completed, failed or is running.
- Every resource (Pods, Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, ConfigMaps, Secrets, Services, Ingresses, volumes, HPAs, RBAC and the rest), with each one’s YAML. Items the cluster does not serve drop out of the menu.
What is accepted
- Web, pasted kubeconfig: contexts with an embedded token or an embedded client certificate and key (client-certificate-data and client-key-data), with an embedded CA (certificate-authority-data) or insecure-skip-tls-verify.
- Web, Azure account: a Service Principal (tenant, client id and secret), optional subscriptions. Discovers AKS clusters with local accounts and with Entra ID.
- Web, AWS account: an IAM access key (optional session token) and optional regions. Discovers the EKS clusters in those regions.
- Desktop: any kubeconfig kubectl accepts, including exec plugins (kubelogin, aws, gke-gcloud-auth-plugin), local files and VPN.
What is not accepted
- Web: a context with an exec plugin (kubelogin, az, aws, aws-iam-authenticator, gke-gcloud-auth-plugin, gcloud, ibmcloud, oci). For AKS and EKS, use the cloud account; for the rest, a ServiceAccount token.
- Web: a context with auth-provider (deprecated in kubectl).
- Web: a CA, certificate or token in a local file (certificate-authority, client-certificate, tokenFile). Generate the embedded version with kubectl config view --flatten --minify.
- Web: a context pointing to a cluster that does not exist in the file, or with no token or certificate.
- Web: a fully private cluster, or one whose API is restricted to IPs that do not include Kubepier’s egress IPs.
- Refused contexts show up on screen with the reason; the others in the same file are imported.
Web-only and desktop-only features
| Feature | Web | Desktop |
|---|---|---|
| Secrets | Only the keys and the size of each value | As in kubectl, with your kubeconfig |
| Helm | Installed releases (read-only) | Charts and releases |
| Port forwarding | No: it opens a port on your machine | Yes |
| Metrics | Uses the metrics-server the cluster has | Installs Lens Metrics (Prometheus, kube-state-metrics and node-exporter) under the cluster Settings › Metrics |
Permissions you need on your side
| Screen | Kubernetes permission (RBAC) |
|---|---|
| Lists and details | get and list on the resources (the desktop also uses watch) |
| Secrets | get and list on secrets (the view role does not include them) |
| Helm releases on the web | list on secrets labelled owner=helm |
| CPU and memory usage | get and list on pods and nodes in the metrics.k8s.io group (metrics-server installed); on desktop with Prometheus, access to its Service through the API proxy (services/proxy) |
| Install or uninstall Lens Metrics (desktop) | create and delete Namespace, ServiceAccount, ConfigMap, Service, DaemonSet, Deployment, StatefulSet, ClusterRole and ClusterRoleBinding: in practice, cluster-admin |
| CRDs and custom resources | get and list on customresourcedefinitions and on each CRD’s resources |
On the web, every read uses the credential saved for the cluster. Whatever it cannot read shows as a permission error on that screen.
Read-only RBAC: a read-only ServiceAccount
To connect with no risk of changing anything, use a ServiceAccount bound to the Kubernetes view ClusterRole, which reads almost everything and does not read Secrets. The full script, which builds the kubeconfig with the token, is in Get started on the web and in the app, under the Grant access tab of the clusters screen.
Common errors
- Context "not supported" when pasting the kubeconfig: read the reason next to the name; the cases are under "What is not accepted".
- Cluster unreachable: the API did not answer Kubepier’s server: check the address and that the egress IPs are allowed.
- 403 on a list: the credential lacks get or list on that resource; grant it or use another credential.