LUMOVI_CONTEXTpicks the context to show; without it, the kubeconfig’s current context.- The cluster is called by its context’s name, unless
LUMOVI_CLUSTER_NAMEsays otherwise. - Lumovi listens on port 8080 (
LUMOVI_PORT), and answers/healthzfor health checks.
Whose credentials it uses
That depends on how people sign in, exactly as in a cluster:- With tokens (the default), people’s requests carry their own tokens. The kubeconfig only says where the cluster is and how to trust its certificate.
- With single sign-on or a proxy, Lumovi uses the kubeconfig’s credentials to impersonate people. Give it a service account’s, with permission to impersonate users and groups, and nothing more.
*-data fields. The image runs as a non-root user (UID 65532), so make sure that user can read what you mount.
With single sign-on
-e LUMOVI_OIDC_CLIENT_SECRET without a value passes the variable on from your shell, so the secret stays out of your shell history. Put TLS in front of Lumovi with a reverse proxy, and set LUMOVI_URL to the address people open. See Single sign-on for registering Lumovi with your provider.
Pin a version
Without a tag, Docker pullslatest, the latest release. Pin a version to know what runs:
Configuration
Every environment variable.
Security
What Lumovi is trusted with, and how to contain it.