lumovi: Secrets you make, each with a kubeconfig.cluster-api: the kubeconfig Cluster API keeps for each cluster it makes.argocd: Argo CD’s cluster Secrets, for the clusters it deploys to.
LUMOVI_FLEET_REFRESH_SECONDS), so clusters come and go as their Secrets do.
Turn it on
With the Helm chart, name the sources, and the namespaces their Secrets are in:values.yaml
LUMOVI_FLEET_SECRETS (lumovi,cluster-api,argocd) and LUMOVI_FLEET_SECRETS_NAMESPACES (comma-separated, the service account’s namespace unless set), and give the service account list on Secrets there.
This works only inside a cluster. Outside one, Lumovi doesn’t start:
Secret argocd/cluster-prod-us.
Lumovi’s own
A Secret labelledlumovi.dev/cluster (with any value), with a kubeconfig under kubeconfig. Each context of the kubeconfig is a cluster, called by the context’s name, with Lumovi’s settings in its extension if it has them, prefixes included.
It has no kubeconfig (data.kubeconfig)., and one whose kubeconfig isn’t one says so, like Secret lumovi/prod-eu isn't a kubeconfig: …. Paths in it would be read in Lumovi’s container, which has none of your files: embed certificates with the *-data fields.
Cluster API’s
Cluster API keeps each cluster’s kubeconfig in a Secret called<cluster>-kubeconfig, under value, in the namespace of its Cluster, and labels it, like the cluster’s other Secrets, with cluster.x-k8s.io/cluster-name. Lumovi reads the -kubeconfig ones, uses their kubeconfig’s first context, and calls each cluster by that label. It skips the cluster’s other Secrets, and a -kubeconfig one that has no value or no context yet. List the namespaces your Cluster objects are in.
When Cluster API replaces a kubeconfig, Lumovi reads the new one at its next look.
Argo CD’s
Argo CD keeps each cluster it deploys to in a Secret labelledargocd.argoproj.io/secret-type: cluster, with its name, its server, and a config that says how to sign in. Lumovi calls each cluster by its name, and reads from config:
The Secret’s own labels become the cluster’s, except Argo CD’s (
argocd.argoproj.io/…). A Secret without a name or a server is shown under its own name, saying It has no name or server., and one whose config isn’t JSON is shown under its own name as Misconfigured. One with none of these credentials, like the entry Argo CD may keep for the cluster it runs in, says Lumovi has no credentials for it….
Argo CD’s credentials are usually its argocd-manager service account’s, which may do anything in the cluster. As with Cluster API’s, Lumovi uses them only to impersonate.
Lumovi’s settings, as annotations
Any of these Secrets can carry Lumovi’s settings for its clusters as annotations, for every cluster it describes. Each one that’s set wins over a cluster’s own setting, from its kubeconfig’s extension or its Argo CD labels.
A Secret whose
lumovi.dev/labels isn’t like this is shown under its own name, as Misconfigured, saying why, like lumovi.dev/labels must be labels like env=production,region=eu, not "staging".
There are no annotations for prefixes. A cluster in Lumovi’s own Secret can have its own in its kubeconfig’s extension; Cluster API’s and Argo CD’s take the server’s.
A fleet of clusters
The other ways to describe clusters, and the fleet page.
Helm values
The chart’s fleet values.