Where it goes
The policy is JSON, kept where only an administrator can write it:
On macOS and Linux, the file and its folder must be
root’s, and writable by nobody else: no write permission for the group or others. Where the file is a link, so must the folder of the file it points to. On Windows, only administrators can write under HKEY_LOCAL_MACHINE\SOFTWARE\Policies, which is where Group Policy and Intune put policies.
Lumovi reads it as it starts: restart it after a change. Only when nothing is there is there no policy, and nothing locked. Something there that Lumovi can’t read is a policy that can’t be used.
policy.json
What it sets
readOnly
true makes every cluster read-only. A list makes those whose kubeconfig context names match read-only: each name whole, with * for any characters, like prod-*. false, or leaving it out, leaves read-only to each person.
What it makes read-only can’t be made changeable in Lumovi. The cluster switcher’s Read-only switch is disabled, with the caption “Set by your organization”, the command palette leaves out the read-only command, and the Read-only badge says “Your organization’s policy makes prod-eu read-only.”, without Allow changes. People can still make other clusters read-only themselves. See Read-only mode.
A list matches context names, which are each person’s to choose in their kubeconfig: it keeps them from changing those clusters through Lumovi by mistake, not someone who renames a context. true holds whatever the names.
assistants
false turns AI assistants off: Lumovi doesn’t listen for them, and they can’t be turned on. On the AI assistants page, the Connect tab’s switch is disabled, and instead of Turn on, it says “Your organization’s policy turns AI assistants off on this computer.” true, or leaving it out, leaves them to each person, off until they turn them on.
assistantRules
What assistants may do at most, as a list of rules, the same as a server’sLUMOVI_ASSISTANT_RULES: each with a name, the clusters and namespaces it applies to, and what it limits, at least one of visibility: hidden, changes: ask or never, secrets: keys or hidden, env: sensitive or all, and logs: off.
People see them first on their Permissions tab, locked, with Set by your administrator, and nothing of theirs loosens them. See What assistants may do. On a computer, clusters have no labels: match them by name or pattern, like prod-*.
updates
false leaves updates to you: Lumovi neither looks for new versions nor installs them, and you deploy each one, as you deployed the first. In the Help menu, Check for Updates… reads Updates Are Set by Your Organization, and both it and Check for Updates Automatically are disabled. A check asked for anyway says “Your organization updates Lumovi”.
true, or leaving it out, leaves Lumovi to update itself, as each person sets: see Staying up to date.
kubectl
Whether, and from where, terminals get a kubectl matching their cluster:false: they don’t. Terminals use the kubectl installed on the computer, and View → Match kubectl to Each Cluster is off and disabled.- An
httpsURL: a mirror of dl.k8s.io to get it from, laid out the same way (release/stable-1.34.txt,release/v1.34.9/bin/windows/amd64/kubectl.exeand its.sha256), for computers that can’t reach dl.k8s.io. Each kubectl is checked against the checksum published beside it, on the mirror. Plainhttpis taken only on this computer (localhost,127.0.0.1or[::1]): elsewhere, the checksum would come over the same plain connection, and both could be changed on the way. It wins overLUMOVI_KUBECTL_MIRROR. true, or leaving it out: from dl.k8s.io, or the mirrorLUMOVI_KUBECTL_MIRRORnames, unless each person turns it off.
network
The proxy and certificate authorities Lumovi’s own connections use, instead of what each person’s shell says:proxy: the proxy’s URL,http://orhttps://, with credentials in it if it wants them. It’s used forhttpsandhttpaddresses alike, whateverHTTPS_PROXYandHTTP_PROXYsay, and passed on tohelmand credential plugins. Looking for new versions goes through it too, with its credentials.noProxy: what’s reached directly, asNO_PROXY: names, with what’s under them (.corp.example.com), and addresses, each with a port or without. Not ranges. It replaces the shell’s.caFiles: files of certificate authorities, as PEM, to trust besides the system’s: the one a proxy that inspects HTTPS signs with, if it isn’t in the system’s certificates already. Looking for new versions trusts only the system’s.
proxy-url in its kubeconfig still goes through that one, and localhost never goes through a proxy. See Proxies and certificates.
A certificate authority file that can’t be read doesn’t stop Lumovi: it leaves that file out, trusts the others, and says so as it starts, in a notice titled “Lumovi started without something it was given”. Put the files where every account can read them.
Deploy it
- macOS
- Windows
- Linux
Make the folder, then copy the file into it, both With an MDM, deploy the same with a script or a package that installs it there, with that owner and mode.
root’s and writable by nobody else:Try one out
To try a policy on a computer that has none, pointLUMOVI_POLICY at a file of your own, and start Lumovi from a terminal:
root’s. Where IT’s policy is set, that one is used, and LUMOVI_POLICY is ignored: nobody can put one of their own in its place.
When it can’t be used
A policy Lumovi can’t use locks the most it could, until it’s put right: every cluster read-only, and AI assistants off. As Lumovi starts, a notice says so, titled “Lumovi started without something it was given”, and the Read-only badge says why too, like:can't be used::
What stays each person’s
The policy locks only what it sets, and only while it’s there. Lumovi shows what it sets, but doesn’t save it over anyone’s settings: a person’s own choices, like AI assistants on or automatic updates, are back if the policy goes. Everything else, like the theme, the clusters they make read-only themselves, and their own AI permissions within the policy’s rules, stays theirs. Beyond which kubectl they get, the policy doesn’t reach terminals, which are each person’s own shell: read-only doesn’t apply to what they run there.Proxies and certificates
How the desktop app reaches clusters behind a proxy.
Read-only mode
What read-only turns off, for one cluster or every one.