DocsConnect your infrastructure
Kubernetes
Deploy apps to a Kubernetes cluster you already run, and watch what runs in your clusters.
If you already run Kubernetes, OpsNexa Online can deploy apps there instead of (or as well as) on servers. It can also read your clusters to show what runs and what’s unhealthy.
Deploy apps to a cluster
You need three things:
- A namespace and a service account limited to it, allowed to create and patch Deployments, Services, Ingresses and Secrets, list and delete them by label, and read pods and logs.
- A container registry the cluster can pull from. Images are built on one of your servers and pushed there.
- An apps domain with a wildcard DNS record pointing at your ingress controller.
Then:
- Open Connections → Add connection and choose Container registry. Enter the image prefix (like
ghcr.io/acmeorharbor.corp.local/apps) and a username and token that can push. - Add another connection and choose Kubernetes cluster. Enter:
- the API server URL and the service account token;
- the cluster CA certificate, unless the API uses a publicly trusted certificate;
- the namespace (
devops-hub-appsby default) and the apps domain; - optionally the ingress class, a cert-manager ClusterIssuer for HTTPS, and an image pull secret for a private registry.
- When you create an app, pick the cluster under Where it runs.
Clusters behind a firewall
If the cluster’s API isn’t on the internet, run the private network agent inside the cluster (the Kubernetes manifest it offers) and use https://kubernetes.default.svc as the API server, with kubernetes.default.svc among the addresses the agent reaches.
Live clusters
Every Kubernetes connection can also be read: what runs, workloads short of ready replicas, containers restarting or unable to pull their image, and which images run where, checked with the same rules as your manifests. A token bound to the built-in view role is enough. Clusters are scanned on a schedule and on demand, and new serious findings send a notification.
People with access
Clusters you connect are also reviewed under People & access: who has which role bindings, and what offboarding would remove. See People and access.
Something unclear or missing? Tell us, or press the ? at the top of OpsNexa Online for the guide and tours inside the product.