Install on Kubernetes
Install with explicit RBAC and verify the agent service account before using cluster actions.
Before you begin
You need kubectl access to the target cluster, permission to create the installation's namespace and RBAC, and the key from Setup. Dashboard Kubernetes operations also need the Kubernetes management plan feature.
Choose the agent's cluster permissions before installation:
| Installation | Cluster access |
|---|---|
Kustomize readonly overlay | Read-only inventory, including Secrets |
Kustomize base | Full wildcard cluster access |
Helm rbac.mode=readonly | Read-only inventory, including Secrets |
Helm rbac.mode=cluster-admin | Full wildcard cluster access |
Read-only can still expose secrets
The public read-only rules allow reading Kubernetes Secrets. Review and reduce the RBAC if this exceeds your intended scope. The base manifests and Helm default grant full cluster access.
The public manifests do not provide an operator overlay. The chart does not implement a narrowly scoped operator mode. Use only the documented values and inspect the rendered RBAC.
Create the namespace and key
kubectl create namespace enderdash
kubectl -n enderdash create secret generic enderdash-agent \
--from-literal=agentKey='<agentKey>'If either resource already exists, update that installation instead of running these creation commands again. Keep the key out of checked-in manifests and command transcripts.
Install with Kustomize
For read-only access:
kubectl apply -k 'https://github.com/enderdash-com/deploy//agent/kustomize/readonly?ref=main'For full cluster access, review the base RBAC, then use:
kubectl apply -k 'https://github.com/enderdash-com/deploy//agent/kustomize/base?ref=main'These URLs follow main. For reproducible deployment, replace that ref with a reviewed revision from the deployment repository.
Or install with Helm
Use Helm instead of Kustomize to avoid two owners managing the same resources. The chart uses the enderdash-agent Secret created above.
helm repo add enderdash https://charts.enderdash.com
helm repo update
helm template enderdash-agent enderdash/enderdash-agent \
--namespace enderdash --set rbac.mode=readonlyReview the rendered permissions. Then install:
helm install enderdash-agent enderdash/enderdash-agent \
--namespace enderdash \
--set rbac.mode=readonlyUse --set rbac.mode=cluster-admin only when full cluster access is intended. The chart's RBAC template grants wildcard permissions for values other than readonly.
By default, chart state uses emptyDir. Set persistence.enabled=true and choose appropriate storage to retain state across pod replacement. Review chart values for image tags, storage, security contexts, resources, and scheduling.
Verify the permissions and live data
kubectl -n enderdash get pods
kubectl -n enderdash logs deployment/enderdash-agent --tail=100
kubectl auth can-i list pods \
--as=system:serviceaccount:enderdash:enderdash-agent --all-namespaces
kubectl auth can-i delete deployments.apps \
--as=system:serviceaccount:enderdash:enderdash-agent --all-namespacesFor the read-only installation, expect yes for listing pods and no for deleting deployments. Impersonation checks require your kubectl identity to have impersonation permission.
Confirm Online in EnderDash. Open Kubernetes and verify that the inventory belongs to the expected cluster.
Diagnose an unavailable action
Forbidden: check this service account's RBAC for the exact resource, subresource, and verb.- No CPU or memory readings: check the cluster metrics API.
- Helm unavailable: the Helm CLI must be available to the agent.
- Maintenance unavailable: relevant drain and eviction actions require kubectl.
- No YAML diff: investigate API discovery, read permissions, and dry-run permissions. YAML comparison is native and does not require kubectl.
Read container platform requirements for auth and native-target limitations. Next: agent maintenance.
Was this page helpful?
Send a quick note if anything is missing or unclear.
Last updated on