Skip to main content
Read-only mode is for the clusters you only want to look at: production on a busy day, a customer’s cluster, a shared machine. Lumovi shows everything as usual, and changes nothing.
A deployment in a read-only cluster: a Read-only badge next to its actions, and its actions menu open with every action disabled and the note that changes are turned off for this cluster.A deployment in a read-only cluster: a Read-only badge next to its actions, and its actions menu open with every action disabled and the note that changes are turned off for this cluster.

A cluster made read-only: Lumovi won't change anything in it until allowed.

For one cluster

Open the cluster switcher at the top of the sidebar, and turn on Read-only. Its caption reads “Lumovi won’t change” and the cluster’s name.
A read-only cluster has a lock next to its name. Next to an object’s actions, a Read-only badge says changes are off; choose it, then Allow changes, to turn them back on. Lumovi remembers which clusters you made read-only, by their kubeconfig context name.

For every cluster

Set LUMOVI_READ_ONLY to 1 (or true) in the environment Lumovi starts in. Every cluster is read-only, and it can’t be turned off from the app: the switch is disabled, with the caption “Set by LUMOVI_READ_ONLY”, and the command palette leaves out its read-only command. That makes it a good fit for shared machines, demos and screen shares.
To set it for every launch, or on Windows, see Setting environment variables.

What it turns off

It isn’t only the buttons. The part of Lumovi that talks to your clusters (the desktop app’s main process, or the server when Lumovi runs in your cluster) refuses every change to a read-only cluster, whatever asks for it:
production is read-only in Lumovi. Allow changes to it to continue.
Actions that are off stay visible, disabled, with “Changes are turned off for this cluster.” One button stays enabled: Install chart on Helm releases. Its dialog opens, and when you choose Review, it shows the refusal above instead of a dry run.

In your cluster

When Lumovi runs in your cluster as a shared dashboard, read-only works at two levels:
  • For everyone. Set readOnly: true in the Helm chart’s values (LUMOVI_READ_ONLY=true when you run the image another way). Nobody changes anything through Lumovi, whatever their RBAC allows. The switch shows “For everyone, on this server”. See Helm values.
  • For yourself. Anyone can make the cluster read-only for themselves from the cluster switcher or the command palette. It’s kept in their browser, and the server enforces it for them.
Read-only mode is a guard rail in Lumovi, not a permission. To keep someone from changing a cluster at all, give their account read-only RBAC, like the built-in view ClusterRole. See Permissions.

Changing things safely

The other guard rails, for when changes are on.

Environment variables

Everything Lumovi reads from its environment.