Triagic + Kubernetes: ticket investigations over your infrastructure, read-only
Read pods, deployments, events, and logs. Only the server's read-only tools are enabled. Triagic connects to Kubernetes from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Kubernetes.
What you can ask
- Ask Kubernetes which import-worker pods restarted today and why
- In Kubernetes, is the payments service running the version we deployed at 16:02?
- Pull the last 200 log lines from the failing container in Kubernetes
- Which Kubernetes workspace changed last week, and what did the plan touch?
- Is the consumer group for order events in Kubernetes lagging, and by how much?
What the agent can do
Triagic exposes every tool the Kubernetes server annotates as read-only, and nothing else. Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale.
Connect in three steps
- 1
Mint a read-only credential in Kubernetes
Create a dedicated user or token that can only read. Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then Kubernetes.
- Kubeconfig: The whole file, pasted. Produce a self-contained one with `kubectl config view --raw --minify --flatten`: `--minify` keeps only the current context and `--flatten` inlines certificates that would otherwise be paths to files this machine does not have. Stored encrypted like any other secret.
- Kubeconfig path: The kubeconfig is read on the machine running Triagic, not on the portal's host and not on anyone else's laptop. Paste it here instead when the members who will use this integration do not all keep one at the same path. Path on each machine running Triagic, or paste the file itself.
- API server URL
- Service-account token: The bearer token of a read-only service account: `kubectl create token triagic`, or the `token` value of its secret.
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts Kubernetes locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: Kubernetes in the docs.
Read-only, by construction
Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale.
FAQ
- Can Triagic change anything in Kubernetes?
- No. Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect Kubernetes?
- Kubeconfig, Kubeconfig path, API server URL, Service-account token. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does Kubernetes cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
- DockerInspect containers, their logs, images, networks and volumes on a Docker engine. Read-only: the server's create, start, stop, remove, pull, push and build tools are not exposed.
- TerraformRead HCP Terraform workspaces, runs, plans, and state versions to see what infrastructure changed. Runs HashiCorp's official image via Docker.
- Confluent / KafkaInspect topics, consumer-group lag, schemas, and connectors, and read messages to trace one that never arrived. Only read tools are enabled.
Try it on your own Kubernetes
No card. Install the desktop app, connect Kubernetes read-only, and triage a real ticket this afternoon.