yeke.io · docs
Documentation
Install YEKE, connect a cluster and configure access. Choose a guide below for setup steps, examples and limits.
Getting started
Installation
Start with Docker on one machine, or use Compose and Kubernetes.
Connecting a cluster
Compare agent and kubeconfig connections, credential storage and role mapping.
Permissions and RBAC
Map user identities and limit access with Role and RoleBinding.
Identity and security
Permission groups
Scope pre-selected Kubernetes capabilities to namespaces from the UI; generate RBAC in the cluster and grant key-level access to Secrets.
Secret versions
Enterprise. Every YEKE write is versioned automatically; catches a change made outside YEKE on the next write, restores a single key or the whole Secret through an approval card.
Active Directory / LDAP Login
Enterprise. Directory connection, username choice, group mapping and just-in-time provisioning.
OIDC Login (SSO)
Enterprise. Keycloak and Entra ID, the redirect URI, group mapping and first login.
Entra ID SSO Setup
Enterprise. Registering the application in Entra ID, the client secret and the admin group; defining the provider in YEKE — step by step.
Security architecture
Trust boundaries and verification steps. Review scope: version 0.15.3.
Internal CA
How the agent, Shell and CLI trust core when its certificate is signed by your organization's own CA.
Operations and GitOps
Hook integration
Connect your system for pre-operation checks and post-operation notifications.
Monitoring
The agent collects metrics from the kubelet; no Prometheus or metrics-server needed. Screens, Scan, tier differences and limits.
Alerts
Enterprise. Threshold and "data not arriving" rules, routing, silences, maintenance windows, the email channel and SMTP.
KubeWorld
Read the cluster as a living city: district = namespace, building = workload, room = pod. Room states, weather, estimated traffic, Labels and Save.
Policies
Write CEL rules, explore examples and test your policies.
Governance
Enterprise. Dual approval (four-eyes), maintenance windows (change-freeze), centralized policy package, terminal session recording, compliance reports.
GitOps Repo Reflection
Configure a repo and deploy key, then track changes and drift.
Deployment and data
PostgreSQL Connection
Configure the connection, pool mode, snapshot key and required license.
Database Migration
SQLite to PostgreSQL with yeke-migrate: offline, one-way, with integrity verification.
High Availability
Run multiple core replicas. Requires PostgreSQL and Enterprise.
Retention and Archive
Set retention periods and configure archiving with PostgreSQL.
Air-Gap Installation
Install from Docker Hub, an internal registry or an offline bundle.