Skip to main content
A fleet’s Lumovi reaches each cluster with credentials that may only impersonate: it acts as whoever signed in, and the cluster applies their RBAC. The Helm chart makes them in the cluster you add, and prints the kubeconfig entry to give Lumovi. This is for clusters whose API server Lumovi can reach. For a cluster in a network it can’t reach, run an agent there instead.

With the Helm chart

1

Install the chart as a member

With your kubeconfig pointing at the cluster to add:
mode: member makes no Lumovi in this cluster, only what the fleet’s Lumovi needs here, named after the release:
  • a service account, lumovi,
  • a ClusterRole and a ClusterRoleBinding, lumovi-impersonate, that let it impersonate users and groups, and nothing else,
  • a Secret, lumovi-token, in which Kubernetes keeps a token for the service account that doesn’t expire.
clusterName is what the fleet calls the cluster. With rbac.create: false, the chart makes no ClusterRole or binding, and you give the service account the same permission yourself. Creating them needs an account that may impersonate users and groups itself, or has the escalate and bind verbs on cluster roles: a cluster administrator has these.
2

Get its kubeconfig entry

The chart’s notes, printed after helm install, start with prod-eu can join a fleet now, and have two commands. They print a kubeconfig with the cluster’s address (as your kubeconfig has it), its certificate authority, and the token. Here, they write it to prod-eu.yaml:
helm get notes lumovi --namespace lumovi prints them again later. If Lumovi reaches the cluster at another address than yours, change server. The API server’s certificate must be valid for that address, or set tls-server-name to a name it’s valid for.
3

Add it to the fleet's kubeconfig

Copy its cluster, user and context into the fleet’s kubeconfig, and give the context Lumovi’s settings for it, if you want any:
fleet.yaml
See Settings for each cluster.
4

Give Lumovi the new kubeconfig

In a Secret (fleet.kubeconfigSecret), replace it, with your kubeconfig pointing at the fleet’s cluster:
Lumovi reads it again by itself, and the log says Fleet: prod-eu added. In LUMOVI_FLEET_KUBECONFIG, change the setting, and restart Lumovi.Or, when Lumovi reads Secrets, give the cluster a Secret of its own instead, with prod-eu.yaml as it is, and its settings as annotations: see Clusters from Secrets.
Whoever has the token can act as anyone in the cluster. Keep the fleet’s kubeconfig only where its administrators can read it. Deleting the lumovi-token Secret revokes the token, and so does uninstalling the release.

Without the chart

The same objects, for kubectl apply:
member.yaml
The first is the user’s token, and the second, as it is, the cluster’s certificate-authority-data. Applying them needs the same permissions as installing the chart: an account that may impersonate users and groups itself, or has the escalate and bind verbs on cluster roles.

A fleet of clusters

The kubeconfig, its settings, and the fleet page.

Private clusters

When Lumovi can’t reach the cluster’s API server.