Before you start
- The fleet’s kubeconfig: each cluster as a context, with credentials that may only impersonate. Add a cluster makes them.
- Your OpenID Connect provider, to register Lumovi with. A fleet needs single sign-on or an authenticating proxy, and on a platform, single sign-on is the simple one.
- The address people will open, like
https://lumovi.example.com: the one Sevalla gives the application, or a domain of your own.
Set it up
1
Encode the kubeconfig
Platform settings are single values, with no files to mount, so give Lumovi the kubeconfig encoded in base64, on one line:Lumovi takes a setting that’s only base64 characters as encoded, and decodes it.
2
Register Lumovi with your provider
Add Lumovi as a web application, with this redirect URI: your address’s origin, then Note the client ID and secret. See Single sign-on for the rest: the claims, and the groups in the ID token.
auth/callback.3
Create the application
In Sevalla, create an application from a Docker image:
ghcr.io/lumovi/lumovi:1.1.0. Pin a version, so you know what runs, and change it to upgrade.4
Set its environment variables
Leave out
LUMOVI_PORT. Sevalla tells the application which port to listen on in PORT, and Lumovi listens on that one. (LUMOVI_PORT wins, when it’s set.)5
Run one instance
Sessions live in Lumovi’s memory, and a sign-in has to finish where it started, so keep the application to one instance. If you set a health check, its path is
/healthz: it answers 200 ok without signing in.6
Deploy, and sign in
Lumovi’s log says what it shows, starting
Lumovi 1.1.0 shows a fleet of 3 clusters (prod-eu, prod-us, staging). A setting that doesn’t make sense stops it, and the log says which and why. Open your address, and sign in.Change the fleet
Lumovi readsLUMOVI_FLEET_KUBECONFIG and LUMOVI_FLEET_AGENTS when it starts. To add or remove a cluster, change the variable, and deploy again. Restarting signs everyone out.
Reaching the clusters
Lumovi reaches each cluster’s API server from Sevalla, over the internet:- API servers that only let some addresses in must let in your application’s outbound IP addresses. Sevalla’s applications reach out from fixed ones.
- Clusters it can’t reach at all, in a private network, need an agent. Agents dial your application’s address, like
https://lumovi.example.com, with a WebSocket.
LUMOVI_HEARTBEAT_SECONDS), so idle connections aren’t closed.
A fleet of clusters
The kubeconfig, its settings, and the fleet page.
Server configuration
Every setting, as an environment variable.