EnderDash

Install on Kubernetes

Install with explicit RBAC and verify the agent service account before using cluster actions.

Before you begin

You need kubectl access to the target cluster, permission to create the installation's namespace and RBAC, and the key from Setup. Dashboard Kubernetes operations also need the Kubernetes management plan feature.

Choose the agent's cluster permissions before installation:

InstallationCluster access
Kustomize readonly overlayRead-only inventory, including Secrets
Kustomize baseFull wildcard cluster access
Helm rbac.mode=readonlyRead-only inventory, including Secrets
Helm rbac.mode=cluster-adminFull wildcard cluster access

Read-only can still expose secrets

The public read-only rules allow reading Kubernetes Secrets. Review and reduce the RBAC if this exceeds your intended scope. The base manifests and Helm default grant full cluster access.

The public manifests do not provide an operator overlay. The chart does not implement a narrowly scoped operator mode. Use only the documented values and inspect the rendered RBAC.

Create the namespace and key

kubectl create namespace enderdash
kubectl -n enderdash create secret generic enderdash-agent \
  --from-literal=agentKey='<agentKey>'

If either resource already exists, update that installation instead of running these creation commands again. Keep the key out of checked-in manifests and command transcripts.

Install with Kustomize

For read-only access:

kubectl apply -k 'https://github.com/enderdash-com/deploy//agent/kustomize/readonly?ref=main'

For full cluster access, review the base RBAC, then use:

kubectl apply -k 'https://github.com/enderdash-com/deploy//agent/kustomize/base?ref=main'

These URLs follow main. For reproducible deployment, replace that ref with a reviewed revision from the deployment repository.

Or install with Helm

Use Helm instead of Kustomize to avoid two owners managing the same resources. The chart uses the enderdash-agent Secret created above.

helm repo add enderdash https://charts.enderdash.com
helm repo update
helm template enderdash-agent enderdash/enderdash-agent \
  --namespace enderdash --set rbac.mode=readonly

Review the rendered permissions. Then install:

helm install enderdash-agent enderdash/enderdash-agent \
  --namespace enderdash \
  --set rbac.mode=readonly

Use --set rbac.mode=cluster-admin only when full cluster access is intended. The chart's RBAC template grants wildcard permissions for values other than readonly.

By default, chart state uses emptyDir. Set persistence.enabled=true and choose appropriate storage to retain state across pod replacement. Review chart values for image tags, storage, security contexts, resources, and scheduling.

Verify the permissions and live data

kubectl -n enderdash get pods
kubectl -n enderdash logs deployment/enderdash-agent --tail=100
kubectl auth can-i list pods \
  --as=system:serviceaccount:enderdash:enderdash-agent --all-namespaces
kubectl auth can-i delete deployments.apps \
  --as=system:serviceaccount:enderdash:enderdash-agent --all-namespaces

For the read-only installation, expect yes for listing pods and no for deleting deployments. Impersonation checks require your kubectl identity to have impersonation permission.

Confirm Online in EnderDash. Open Kubernetes and verify that the inventory belongs to the expected cluster.

Diagnose an unavailable action

  • Forbidden: check this service account's RBAC for the exact resource, subresource, and verb.
  • No CPU or memory readings: check the cluster metrics API.
  • Helm unavailable: the Helm CLI must be available to the agent.
  • Maintenance unavailable: relevant drain and eviction actions require kubectl.
  • No YAML diff: investigate API discovery, read permissions, and dry-run permissions. YAML comparison is native and does not require kubectl.

Read container platform requirements for auth and native-target limitations. Next: agent maintenance.

Was this page helpful?

Send a quick note if anything is missing or unclear.

Last updated on

On this page