KUBESTACKS_CONTEXTpicks the context to show; without it, the kubeconfig’s current context.- The cluster is called by its context’s name, unless
KUBESTACKS_CLUSTER_NAMEsays otherwise. - KubeStacks listens on port 8080 (
KUBESTACKS_PORT), and answers/healthzfor health checks.
Whose credentials it uses
That depends on how people sign in, exactly as in a cluster:- With tokens (the default), people’s requests carry their own tokens. The kubeconfig only says where the cluster is and how to trust its certificate.
- With single sign-on or a proxy, KubeStacks uses the kubeconfig’s credentials to impersonate people. Give it a service account’s, with permission to impersonate users and groups, and nothing more.
*-data fields. The image runs as a non-root user (UID 65532), so make sure that user can read what you mount.
With single sign-on
-e KUBESTACKS_OIDC_CLIENT_SECRET without a value passes the variable on from your shell, so the secret stays out of your shell history. Put TLS in front of KubeStacks with a reverse proxy, and set KUBESTACKS_URL to the address people open. See Single sign-on for registering KubeStacks with your provider.
Pin a version
Without a tag, Docker pullslatest, the latest release. Pin a version to know what runs:
Configuration
Every environment variable.
Security
What KubeStacks is trusted with, and how to contain it.