43 lines
1.5 KiB
Markdown
43 lines
1.5 KiB
Markdown
|
|
# Headlamp - Kubernetes Dashboard
|
||
|
|
|
||
|
|
Headlamp is a modern, web-based Kubernetes dashboard that provides a user-friendly interface for managing and monitoring Kubernetes clusters.
|
||
|
|
|
||
|
|
## Deployment
|
||
|
|
|
||
|
|
This deployment includes:
|
||
|
|
|
||
|
|
- **Namespace**: `headlamp`
|
||
|
|
- **Service Account**: `headlamp-admin` with `cluster-admin` ClusterRoleBinding for full cluster access
|
||
|
|
- **OIDC Authentication**: Integrated with Pocket ID (https://auth.basicstack.de)
|
||
|
|
- **Ingress**: Accessible at https://headlamp.basicstack.de
|
||
|
|
|
||
|
|
## OIDC Configuration
|
||
|
|
|
||
|
|
The deployment is configured to authenticate users via Pocket ID using OpenID Connect (OIDC):
|
||
|
|
|
||
|
|
- **Issuer URL**: https://auth.basicstack.de
|
||
|
|
- **Client ID**: Stored in sealed secret `headlamp-oidc`
|
||
|
|
- **Client Secret**: Stored in sealed secret `headlamp-oidc`
|
||
|
|
- **Scopes**: openid, profile, email
|
||
|
|
|
||
|
|
### Authorized Users
|
||
|
|
|
||
|
|
The following users have access to Headlamp through Pocket ID:
|
||
|
|
- andreas.leinen@basicstack.de (admin)
|
||
|
|
- admin@basicstack.de (admin)
|
||
|
|
|
||
|
|
Users authenticate through the Pocket ID SSO and receive cluster-admin permissions via the service account.
|
||
|
|
|
||
|
|
## Resources
|
||
|
|
|
||
|
|
- **Official Documentation**: https://headlamp.dev/docs/
|
||
|
|
- **OIDC Setup Guide**: https://headlamp.dev/docs/latest/installation/in-cluster/oidc
|
||
|
|
- **Source Repository**: https://github.com/headlamp-k8s/headlamp
|
||
|
|
|
||
|
|
## Access
|
||
|
|
|
||
|
|
After deployment via ArgoCD, access the dashboard at:
|
||
|
|
https://headlamp.basicstack.de
|
||
|
|
|
||
|
|
Users will be redirected to Pocket ID for authentication before accessing the cluster dashboard.
|