Clusters · Web and Desktop

Clusters and resources: kubeconfig, cloud accounts and RBAC

Each cluster opens with the same menu as the IDE: overview, nodes, workloads, config, network, storage, Helm and CRDs. Web and desktop accept different kubeconfigs and credentials, because the web connects from Kubepier’s server and the desktop from your machine; either way the credential’s RBAC applies, and you can start with a read-only ServiceAccount.

Where
Web and Desktop
Plans
Free, Pro and Team (read-only on all)
Role
Web: admins add; admins and members read

What it does

  • Failing pods and warning events rise to the top.
  • CPU and memory per cluster, node and namespace: on the web, from the cluster’s metrics-server; on desktop, from the Prometheus of the provider picked under the cluster Settings › Metrics (Lens Metrics, for example), or from metrics-server when there is no Prometheus.
  • Every CronJob shows its last run and whether it is suspended; every Job, whether it completed, failed or is running.
  • Every resource (Pods, Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, ConfigMaps, Secrets, Services, Ingresses, volumes, HPAs, RBAC and the rest), with each one’s YAML. Items the cluster does not serve drop out of the menu.

What is accepted

  • Web, pasted kubeconfig: contexts with an embedded token or an embedded client certificate and key (client-certificate-data and client-key-data), with an embedded CA (certificate-authority-data) or insecure-skip-tls-verify.
  • Web, Azure account: a Service Principal (tenant, client id and secret), optional subscriptions. Discovers AKS clusters with local accounts and with Entra ID.
  • Web, AWS account: an IAM access key (optional session token) and optional regions. Discovers the EKS clusters in those regions.
  • Desktop: any kubeconfig kubectl accepts, including exec plugins (kubelogin, aws, gke-gcloud-auth-plugin), local files and VPN.

What is not accepted

  • Web: a context with an exec plugin (kubelogin, az, aws, aws-iam-authenticator, gke-gcloud-auth-plugin, gcloud, ibmcloud, oci). For AKS and EKS, use the cloud account; for the rest, a ServiceAccount token.
  • Web: a context with auth-provider (deprecated in kubectl).
  • Web: a CA, certificate or token in a local file (certificate-authority, client-certificate, tokenFile). Generate the embedded version with kubectl config view --flatten --minify.
  • Web: a context pointing to a cluster that does not exist in the file, or with no token or certificate.
  • Web: a fully private cluster, or one whose API is restricted to IPs that do not include Kubepier’s egress IPs.
  • Refused contexts show up on screen with the reason; the others in the same file are imported.

Web-only and desktop-only features

FeatureWebDesktop
SecretsOnly the keys and the size of each valueAs in kubectl, with your kubeconfig
HelmInstalled releases (read-only)Charts and releases
Port forwardingNo: it opens a port on your machineYes
MetricsUses the metrics-server the cluster hasInstalls Lens Metrics (Prometheus, kube-state-metrics and node-exporter) under the cluster Settings › Metrics

Permissions you need on your side

ScreenKubernetes permission (RBAC)
Lists and detailsget and list on the resources (the desktop also uses watch)
Secretsget and list on secrets (the view role does not include them)
Helm releases on the weblist on secrets labelled owner=helm
CPU and memory usageget and list on pods and nodes in the metrics.k8s.io group (metrics-server installed); on desktop with Prometheus, access to its Service through the API proxy (services/proxy)
Install or uninstall Lens Metrics (desktop)create and delete Namespace, ServiceAccount, ConfigMap, Service, DaemonSet, Deployment, StatefulSet, ClusterRole and ClusterRoleBinding: in practice, cluster-admin
CRDs and custom resourcesget and list on customresourcedefinitions and on each CRD’s resources

On the web, every read uses the credential saved for the cluster. Whatever it cannot read shows as a permission error on that screen.

Read-only RBAC: a read-only ServiceAccount

To connect with no risk of changing anything, use a ServiceAccount bound to the Kubernetes view ClusterRole, which reads almost everything and does not read Secrets. The full script, which builds the kubeconfig with the token, is in Get started on the web and in the app, under the Grant access tab of the clusters screen.

Common errors

  • Context "not supported" when pasting the kubeconfig: read the reason next to the name; the cases are under "What is not accepted".
  • Cluster unreachable: the API did not answer Kubepier’s server: check the address and that the egress IPs are allowed.
  • 403 on a list: the credential lacks get or list on that resource; grant it or use another credential.