Skip to main content
When Lumovi runs in a cluster, it’s a web page. Open the address your team gave you, sign in, and the cluster’s overview opens. Everything you see, and every change you can make, is what your own Kubernetes account allows: Lumovi never gives anyone more.

Sign in

How you sign in depends on how your team set Lumovi up. The sign-in page shows the right way.
Choose Sign in with … (your company’s provider, like Okta or Google), and sign in there as you usually do. You come back to Lumovi, signed in.
Lumovi served from a cluster: signing in with single sign-on.Lumovi served from a cluster: signing in with single sign-on.

Who you are, and what you can do

Your initials, at the bottom of the sidebar, open a menu that shows who you’re signed in as, and your groups: four by name, then how many more. system:authenticated, which everyone signed in is in, isn’t listed. Where the name and groups come from depends on how you signed in:
  • With a token: the cluster’s own answer for that token. That’s exactly the name and groups the cluster applies roles to.
  • With single sign-on: what your provider says about you when you sign in.
  • Behind a company login: what the proxy passes on to Lumovi.
Your access comes from the roles bound to that name and those groups. With single sign-on or a company login, the cluster may know them with a prefix your team chose, like oidc:: then roles are bound to oidc:alice@example.com and oidc:platform, while the menu shows alice@example.com and platform.
Lumovi served from a cluster: who's signed in, and their groups.Lumovi served from a cluster: who's signed in, and their groups.

Who's signed in, and their groups.

  • Actions you aren’t allowed to take are turned off, with the reason, like “Your account can’t delete pods in shop.”
  • If you can only see some namespaces, pick one from the namespace menu, or type its name.
  • Sign out is in the same menu. Behind a company login, it signs you out of the proxy, if your team set that up. Otherwise the menu says Signed in by the proxy in front of Lumovi.

Good to know

A session lasts 12 hours unless your team changed that. It also ends when Lumovi restarts, after an upgrade say. You come back to the sign-in page, and land where you were. Behind a company login, Lumovi keeps no session of its own: the proxy decides when you sign in again.
A banner says Reconnecting to Lumovi…, and the page keeps what it showed. It picks up again as soon as the server answers. If it goes on, the server may be down, or a proxy in front of it may not pass WebSockets.
The theme, whether you’ve made the cluster read-only for yourself, and where usage history comes from are kept in your browser. Changing them doesn’t affect anyone else.
Browsers keep ⌘N and ⌘1…6 for themselves. The command palette (⌘K, or CtrlK on Windows and Linux) has those commands. Everything else is the same as in the desktop app.

Take the tour

Five minutes through the app’s main ideas.

Changing things safely

What Lumovi checks before it changes anything.