yeke.io · docs

Documentation

Install YEKE, connect a cluster and configure access. Choose a guide below for setup steps, examples and limits.

Getting started

Installation

Start with Docker on one machine, or use Compose and Kubernetes.

Connecting a cluster

Compare agent and kubeconfig connections, credential storage and role mapping.

Permissions and RBAC

Map user identities and limit access with Role and RoleBinding.

Identity and security

Permission groups

Scope pre-selected Kubernetes capabilities to namespaces from the UI; generate RBAC in the cluster and grant key-level access to Secrets.

Secret versions

Enterprise. Every YEKE write is versioned automatically; catches a change made outside YEKE on the next write, restores a single key or the whole Secret through an approval card.

Active Directory / LDAP Login

Enterprise. Directory connection, username choice, group mapping and just-in-time provisioning.

OIDC Login (SSO)

Enterprise. Keycloak and Entra ID, the redirect URI, group mapping and first login.

Entra ID SSO Setup

Enterprise. Registering the application in Entra ID, the client secret and the admin group; defining the provider in YEKE — step by step.

Security architecture

Trust boundaries and verification steps. Review scope: version 0.15.3.

Internal CA

How the agent, Shell and CLI trust core when its certificate is signed by your organization's own CA.

Operations and GitOps

Hook integration

Connect your system for pre-operation checks and post-operation notifications.

Monitoring

The agent collects metrics from the kubelet; no Prometheus or metrics-server needed. Screens, Scan, tier differences and limits.

Alerts

Enterprise. Threshold and "data not arriving" rules, routing, silences, maintenance windows, the email channel and SMTP.

KubeWorld

Read the cluster as a living city: district = namespace, building = workload, room = pod. Room states, weather, estimated traffic, Labels and Save.

Policies

Write CEL rules, explore examples and test your policies.

Governance

Enterprise. Dual approval (four-eyes), maintenance windows (change-freeze), centralized policy package, terminal session recording, compliance reports.

GitOps Repo Reflection

Configure a repo and deploy key, then track changes and drift.

Deployment and data

PostgreSQL Connection

Configure the connection, pool mode, snapshot key and required license.

Database Migration

SQLite to PostgreSQL with yeke-migrate: offline, one-way, with integrity verification.

High Availability

Run multiple core replicas. Requires PostgreSQL and Enterprise.

Retention and Archive

Set retention periods and configure archiving with PostgreSQL.

Air-Gap Installation

Install from Docker Hub, an internal registry or an offline bundle.

Releases and tiers

Releases

Review features and fixes in published releases.

Pricing

Tiers, Community limits, and which item sits in which tier.