Skip to main content

Connect Kubernetes

Argus scans a Kubernetes cluster read-only from its kubeconfig. Nothing is installed in the cluster, and Argus only ever reads.

Before you start​

  • A read-only context or ServiceAccount for the cluster.
  • An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.

Provider-side setup​

  1. Use or create a read-only ServiceAccount (or a read-only context) for the cluster. Argus only reads.
  2. Export a kubeconfig scoped to the target context.

Required permissions​

A read-only (view) ClusterRole is enough: Argus performs only read calls (get, list, watch). Bind that role to the ServiceAccount whose context the kubeconfig points at. Note that exec-based kubeconfigs (external auth plugins) are not supported.

Connect in Argus​

Go to Accounts and click Connect account. Pick Kubernetes, then the Kubeconfig method. Enter:

FieldValue
Cluster namea name for this cluster
Kubeconfig contentspaste the full kubeconfig for the target context

Connection test​

Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the kubeconfig and use Test connection on the account card to retry.

Official Kubernetes documentation​