With the Helm chart
1
Install the chart as a member
With your kubeconfig pointing at the cluster to add:
mode: member makes no Lumovi in this cluster, only what the fleet’s Lumovi needs here, named after the release:- a service account,
lumovi, - a ClusterRole and a ClusterRoleBinding,
lumovi-impersonate, that let it impersonate users and groups, and nothing else, - a Secret,
lumovi-token, in which Kubernetes keeps a token for the service account that doesn’t expire.
clusterName is what the fleet calls the cluster. With rbac.create: false, the chart makes no ClusterRole or binding, and you give the service account the same permission yourself. Creating them needs an account that may impersonate users and groups itself, or has the escalate and bind verbs on cluster roles: a cluster administrator has these.2
Get its kubeconfig entry
The chart’s notes, printed after
helm install, start with prod-eu can join a fleet now, and have two commands. They print a kubeconfig with the cluster’s address (as your kubeconfig has it), its certificate authority, and the token. Here, they write it to prod-eu.yaml:helm get notes lumovi --namespace lumovi prints them again later. If Lumovi reaches the cluster at another address than yours, change server. The API server’s certificate must be valid for that address, or set tls-server-name to a name it’s valid for.3
Add it to the fleet's kubeconfig
Copy its cluster, user and context into the fleet’s kubeconfig, and give the context Lumovi’s settings for it, if you want any:See Settings for each cluster.
fleet.yaml
4
Give Lumovi the new kubeconfig
In a Secret (Lumovi reads it again by itself, and the log says
fleet.kubeconfigSecret), replace it, with your kubeconfig pointing at the fleet’s cluster:Fleet: prod-eu added. In LUMOVI_FLEET_KUBECONFIG, change the setting, and restart Lumovi.Or, when Lumovi reads Secrets, give the cluster a Secret of its own instead, with prod-eu.yaml as it is, and its settings as annotations: see Clusters from Secrets.Without the chart
The same objects, forkubectl apply:
member.yaml
token, and the second, as it is, the cluster’s certificate-authority-data.
Applying them needs the same permissions as installing the chart: an account that may impersonate users and groups itself, or has the escalate and bind verbs on cluster roles.
A fleet of clusters
The kubeconfig, its settings, and the fleet page.
Private clusters
When Lumovi can’t reach the cluster’s API server.