yeke.io · docs

Monitoring

Monitoring shows the cluster's node, workload and storage metrics inside YEKE. The YEKE agent collects them, so there is no extra monitoring component to install in the cluster. This guide covers what is collected and from where, the screens, Scan, and the limits.

What is collected, and from where

The collector lives inside the YEKE agent. It reads each node's kubelet under the agent's own identity, with read-only access.

  • Source: each kubelet's /stats/summary and /metrics/cadvisor endpoints. The nodes/proxy permission is deliberately not used.
  • Frequency: every 30 seconds.
  • Coverage: CPU, memory, disk and network for nodes, workloads and storage.
  • History: 30 days in Community, 90 days in Enterprise.

Why there is nothing extra to install

You don't need Prometheus, Grafana, node-exporter, kube-state-metrics or metrics-server. The read permissions the agent needs are already in the agent manifest.

ResourceVerbsWhat for
nodeslist, watchNode addresses, allocatable capacity and conditions
nodes/stats, nodes/metricsgetThe kubelet's /stats/summary and /metrics/cadvisor endpoints
podslist, watchThe pod's owner chain (which workload it belongs to)
replicasetslist, watchThe Deployment → ReplicaSet → Pod link

All four are read permissions; none grants access to Secrets or any write. Which metrics a user gets to see is decided by an access check under that user's own identity, not by this role.

An older agent installed in full-access mode picks these permissions up with an agent update, which refreshes the ClusterRole along with the image. In restricted mode the UI shows the command to apply instead of a button.

If the cluster already runs metrics-server or your own Prometheus / VictoriaMetrics, pod charts can use them too; neither is required.

Screens

Open Monitoring from a cluster's left-hand menu. The page has six tabs.

  • Overview, Nodes, Workloads, Storage — metrics and their history.
  • Scan — the Run scan button and earlier scans (below).
  • Alerts — Enterprise; see the Alerts guide.

The KubeWorld band in the page header (Enter KubeWorld) opens the same cluster as a living city: namespaces are districts, workloads are buildings, pods are windows, and the weather shows the cluster's overall health. KubeWorld reads YEKE's metrics store and the cluster's live object lists under your identity; it adds no collector of its own. Traffic is not measured; it is estimated from the pods' network ingress. See the KubeWorld guide.

Scan

A scan reads this cluster's measurements and Kubernetes events once, with your own permissions, and reports what it finds. It is not a security or image scan; it is a health and diagnosis scan.

  • What it looks at: Pending pods, image-pull errors, crash loops, OOMKilled, running out of capacity and similar states. Each finding comes with its evidence, and with a suggested fix where one applies.
  • It needs an AI provider. A scan is a model run on your own AI provider (Administration → Integrations → AI providers). With no provider selected, or with AI turned off for the cluster, it doesn't run. No license needed; the model cost is yours.
  • Community: manual scans (Run scan) and the report as JSON — GET /api/clusters/<cluster>/metrics/scans/<scan>.
  • Enterprise: scheduled scans and the single-file HTML report (Download HTML report).

Community and Enterprise

Monitoring, Scan and KubeWorld are free in Community, with no license key.

FeatureCommunityEnterprise
Collection and chartsYesYes
History30 days90 days
KubeWorldYesYes
Manual scans and JSON reportYesYes
Scheduled scans—Yes
HTML version of the scan report—Yes
Alerts and anomaly detection—Yes

The Enterprise items are unlocked by the metrics-retention (90-day history) and metrics-alerts (alerts, anomaly detection, scheduled scans, HTML report) license flags. More on Pricing.

Limits

The collector ships with the agent; where it can't reach or can't trust a kubelet, there is no data.

  • Collection needs agent mode. A cluster connected with a kubeconfig has no collector; object pages use metrics-server if the cluster has it. For the connection modes, see Connecting a cluster.
  • Self-signed kubelet certificates. With the kubeadm and Kubespray defaults, the kubelet's certificate can't be verified against the cluster CA; the node stays at "TLS not verified" and sends no data. You have three options: turn on kubelet serving certificate rotation; set YEKE_KUBELET_INSECURE_TLS=true on the agent Deployment; or, in full-access mode, use the Accept unverified TLS button on the Monitoring page, which writes the same setting through an approval card. The last two mean unverified TLS inside the cluster network.

See the cluster as a city, too

KubeWorld draws what Monitoring collects as a living city.