yeke.io · docs
Monitoring
Monitoring shows the cluster's node, workload and storage metrics inside YEKE. The YEKE agent collects them, so there is no extra monitoring component to install in the cluster. This guide covers what is collected and from where, the screens, Scan, and the limits.
What is collected, and from where
The collector lives inside the YEKE agent. It reads each node's kubelet under the agent's own identity, with read-only access.
- Source: each kubelet's
/stats/summaryand/metrics/cadvisorendpoints. Thenodes/proxypermission is deliberately not used. - Frequency: every 30 seconds.
- Coverage: CPU, memory, disk and network for nodes, workloads and storage.
- History: 30 days in Community, 90 days in Enterprise.
Why there is nothing extra to install
You don't need Prometheus, Grafana, node-exporter, kube-state-metrics or metrics-server. The read permissions the agent needs are already in the agent manifest.
| Resource | Verbs | What for |
|---|---|---|
nodes | list, watch | Node addresses, allocatable capacity and conditions |
nodes/, nodes/ | get | The kubelet's /stats/ and /metrics/ endpoints |
pods | list, watch | The pod's owner chain (which workload it belongs to) |
replicasets | list, watch | The Deployment → ReplicaSet → Pod link |
All four are read permissions; none grants access to Secrets or any write. Which metrics a user gets to see is decided by an access check under that user's own identity, not by this role.
An older agent installed in full-access mode picks these permissions up with an agent update, which refreshes the ClusterRole along with the image. In restricted mode the UI shows the command to apply instead of a button.
If the cluster already runs metrics-server or your own Prometheus / VictoriaMetrics, pod charts can use them too; neither is required.
Screens
Open Monitoring from a cluster's left-hand menu. The page has six tabs.
- Overview, Nodes, Workloads, Storage — metrics and their history.
- Scan — the Run scan button and earlier scans (below).
- Alerts — Enterprise; see the Alerts guide.
The KubeWorld band in the page header (Enter KubeWorld) opens the same cluster as a living city: namespaces are districts, workloads are buildings, pods are windows, and the weather shows the cluster's overall health. KubeWorld reads YEKE's metrics store and the cluster's live object lists under your identity; it adds no collector of its own. Traffic is not measured; it is estimated from the pods' network ingress. See the KubeWorld guide.
Scan
A scan reads this cluster's measurements and Kubernetes events once, with your own permissions, and reports what it finds. It is not a security or image scan; it is a health and diagnosis scan.
- What it looks at:
Pendingpods, image-pull errors, crash loops,OOMKilled, running out of capacity and similar states. Each finding comes with its evidence, and with a suggested fix where one applies. - It needs an AI provider. A scan is a model run on your own AI provider (Administration → Integrations → AI providers). With no provider selected, or with AI turned off for the cluster, it doesn't run. No license needed; the model cost is yours.
- Community: manual scans (Run scan) and the report as JSON —
GET /api/clusters/.<cluster>/ metrics/scans/ <scan> - Enterprise: scheduled scans and the single-file HTML report (Download HTML report).
Community and Enterprise
Monitoring, Scan and KubeWorld are free in Community, with no license key.
| Feature | Community | Enterprise |
|---|---|---|
| Collection and charts | Yes | Yes |
| History | 30 days | 90 days |
| KubeWorld | Yes | Yes |
| Manual scans and JSON report | Yes | Yes |
| Scheduled scans | — | Yes |
| HTML version of the scan report | — | Yes |
| Alerts and anomaly detection | — | Yes |
The Enterprise items are unlocked by the metrics-retention (90-day
history) and metrics-alerts (alerts, anomaly detection, scheduled scans, HTML
report) license flags. More on Pricing.
Limits
The collector ships with the agent; where it can't reach or can't trust a kubelet, there is no data.
- Collection needs agent mode. A cluster connected with a kubeconfig has no collector; object pages use metrics-server if the cluster has it. For the connection modes, see Connecting a cluster.
- Self-signed kubelet certificates. With the kubeadm and Kubespray defaults, the
kubelet's certificate can't be verified against the cluster CA; the node stays at "TLS not
verified" and sends no data. You have three options: turn on kubelet serving certificate
rotation; set
YEKE_KUBELET_INSECURE_TLS=trueon the agent Deployment; or, in full-access mode, use the Accept unverified TLS button on the Monitoring page, which writes the same setting through an approval card. The last two mean unverified TLS inside the cluster network.