Clusters · Pro and Team

Edit, scale, restart and delete

On the Pro and Team plans, Kubepier changes the cluster. On Free, everything is read-only: on the web, the buttons show a lock; on desktop, from 2.4.0 on, too, with an upgrade notice (up to 2.3.0, the actions do not show on Free).

Where
Web and Desktop
Plans
Pro and Team
Role
Admin only (on desktop, from 2.7.0)

What it does

ActionHow it works
Edit YAMLReplaces the object with the edited YAML (PUT), putting back the last-applied-configuration annotation the screen hides.
ScaleChanges the replicas through the scale subresource.
RestartLike kubectl rollout restart: stamps the pod template with restartedAt.
DeleteDeletes the object. For a pod, the controller creates another.

What is accepted

  • Web, edit: the types in the web menu, except Secret. The YAML must be the same object (same kind, name and namespace).
  • Web, scale: Deployments, StatefulSets, ReplicaSets and ReplicationControllers, from 0 to 1000 replicas.
  • Web, restart: Deployments, StatefulSets and DaemonSets.
  • Web, delete: the types in the web menu, except namespaces and nodes.
  • Desktop: the Freelens menus for each type, including custom resources and triggering a CronJob.

What is not accepted

  • Web: editing a Secret (the values never reach the browser and the edited YAML would wipe the data).
  • Web: invalid YAML, or YAML for another object.
  • Web: saving over a change someone else made while you edited: Kubernetes refuses it (409) and you reload.
  • Web: scaling above 1000 replicas or below 0; deleting a namespace or node.
  • Web: editing or deleting custom resource instances (read-only on the web).
  • Members (on the web; on desktop, from 2.7.0) and anyone on Free.

Confirmations

  • Web: restart asks for confirmation; delete asks you to type the resource name.
  • Desktop: restart and delete ask for confirmation; from 2.7.0, delete, force and finalize ask for the typed name.
  • Edit and scale apply on save.

Audit

  • Web: every attempt, successful or not, goes to the organization audit log, in the database: who, when, cluster, kind, namespace, name, action and the error, if any.
  • Desktop: apply, edit, scale, restart and delete go to the kubepier-audit.log file, in the app data folder, with who, when, cluster, kind, namespace, name and whether it worked. Cordon, uncordon and drain record that the command was sent, not its result.
  • Never the manifest, the edited YAML or the patch.

Permissions you need on your side

ActionKubernetes permission (RBAC)
Editget and update on the resource
Scalepatch on the scale subresource (deployments/scale, statefulsets/scale…)
Restartpatch on the resource
Deletedelete on the resource

The action uses the permissions of the cluster credential (web) or your kubeconfig (desktop). If it cannot, Kubernetes refuses and the screen shows the error.

Common errors

  • Button with a lock: the organization is on Free or you are a member. On desktop, from 2.4.0 on, the action opens an upgrade notice; up to 2.3.0, it does not show on Free.
  • 409 on save: someone changed the object; reload and edit again.
  • 422 or "invalid YAML": the YAML failed validation; the message names the field.
  • 403: the credential lacks the verb in the table above.