In your cluster: only Lumovi in a cluster, or a fleet, has it. The desktop app does what your kubeconfig allows.
/your-access.


Your access: what Lumovi lets you do, cluster by cluster, and why.
What it shows
- You: who you’re signed in as, the groups your sign-in sent, and so the groups of Lumovi’s you’re in. With none, you get what everyone does. Lumovi’s admins are named under it: they decide. If you’re one, Open Admin opens the Access pages.
- In this cluster, or in a fleet Cluster by cluster: for each of Changes, Shells, Node shells, Logs, Secrets, Helm and AI assistants, the most you may do there, and where that’s so: “everywhere”, or how many namespaces, like “in 8 of 9; keys only in 1: Card data (PCI)”, with the limit that holds the rest back when one does. Node shells are decided for each cluster’s nodes, never by namespace.
- Whose audit events you see: your own, or everyone’s, when the server names you an auditor or your access says so.
- Why: what everyone signed in gets, each grant that gives you more, with its profile and what that adds, and each limit that holds you back, with what it holds back. Where grants overlap, you get the most of them. Limits win over all of them.
Where it’s said
Wherever your access doesn’t let you do something, Lumovi says so there, with why, and a way here:- Actions you may not take are turned off, saying why when you point at them: “Your access doesn’t let you make changes in shop: none of your grants gives it here.” The reason names the grant or limit that decides, like the limit “Production” holds it back, or your grant “Developers” gives Developer, and no more.
- Shell, a node’s Shell, and Logs tabs say You can’t open shells here, You can’t open shells on nodes here or You can’t read logs here, with why, who Lumovi’s admins are, and See your access.
- Secrets: where you see keys only, their Data says “Only the keys”, each value reads Value hidden by your access, and YAML says Values hidden by your access in place of Reveal values. Their values never reach your browser, not even in what a change you make answers with. Editing one as YAML is turned off, since that writes the Secret whole. Where Secrets are hidden, you can’t open or change them, and lists across every namespace leave them out.
- Helm releases: Upgrade…, Roll back… and Uninstall… are turned off where you may not, with why. Where you don’t see Secrets’ values, a release keeps its tabs, but Resources, Values, Manifest and History say Its values and manifests are hidden, since they can hold Secrets, and why: your access shows only their keys there, or hides them. It can’t be upgraded. Install chart says up front when you may not install there.
- A list you may not see says Not for you, here, with See your access.
When it changes
What admins change applies at once, everywhere: open pages, this one included, follow it without reloading. Your groups are the ones your sign-in sent: when they change at your identity provider, they count here once you sign in again, or behind a company login, once the page connects again.Your AI assistants
Your assistants never do more than you may: they don’t see namespaces where your access turns them off, ask you first where it says Changes ask first, change nothing where you may not, and see Secrets and logs no further than you. If your access lets you use them nowhere, you can’t allow one. See AI assistants.Permissions
What your RBAC needs to allow, for each feature.
Access for your team
How admins decide who may do what.