Repository navigation
|
In-cluster deployment according to https://github.com/skyhook-io/radar/blob/main/docs/in-cluster.md
|
Replies: 1 comment
|
You haven't done anything wrong here, and this isn't a "new to k8s" thing. It would catch anyone following that guide. Helm stores its release records as Secrets, and Radar's default install doesn't grant its ServiceAccount permission to read Secrets. So the Helm view asks, gets a 403 back, and shows you that card. The guide never mentions the connection. Two ways forward depending on your setup. If this is more than a personal or test cluster, turn on authentication. Everyone then browses with their own Kubernetes permissions, and the Helm view starts working on its own, with no extra flags. If it's your own cluster and you just want the panel working, there's a one-flag version: helm upgrade radar skyhook/radar \
--namespace radar \
--reset-then-reuse-values \
--set rbac.secrets=true \
--waitWorth knowing what that does: it lets Radar read every Secret in the cluster, not just Helm's records. And with no authentication configured, anyone who can open Radar can reveal those values in plaintext. Fine on a cluster only you can reach; not something I'd put on a shared one. Either way you don't need If it still doesn't work after the upgrade: kubectl auth can-i list secrets -A --as=system:serviceaccount:radar:radar(adjust if your release name or namespace differs; needs impersonation rights on your own account) The docs gap is ours. The RBAC table should say |

You haven't done anything wrong here, and this isn't a "new to k8s" thing. It would catch anyone following that guide.
Helm stores its release records as Secrets, and Radar's default install doesn't grant its ServiceAccount permission to read Secrets. So the Helm view asks, gets a 403 back, and shows you that card. The guide never mentions the connection.
Two ways forward depending on your setup.
If this is more than a personal or test cluster, turn on authentication. Everyone then browses with their own Kubernetes permissions, and the Helm view starts working on its own, with no extra flags.
If it's your own cluster and you just want the panel working, there's a one-flag version: