Skip to content

Triagic + Kubernetes: ticket investigations over your infrastructure, read-only

Read pods, deployments, events, and logs. Only the server's read-only tools are enabled. Triagic connects to Kubernetes from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Kubernetes.

What you can ask

  • Ask Kubernetes which import-worker pods restarted today and why
  • In Kubernetes, is the payments service running the version we deployed at 16:02?
  • Pull the last 200 log lines from the failing container in Kubernetes
  • Which Kubernetes workspace changed last week, and what did the plan touch?
  • Is the consumer group for order events in Kubernetes lagging, and by how much?

What the agent can do

Triagic exposes every tool the Kubernetes server annotates as read-only, and nothing else. Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale.

Connect in three steps

  1. 1

    Mint a read-only credential in Kubernetes

    Create a dedicated user or token that can only read. Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale.

  2. 2

    Add it in the Triagic portal

    Integrations, then Add shared data source, then Kubernetes.

    • Kubeconfig: The whole file, pasted. Produce a self-contained one with `kubectl config view --raw --minify --flatten`: `--minify` keeps only the current context and `--flatten` inlines certificates that would otherwise be paths to files this machine does not have. Stored encrypted like any other secret.
    • Kubeconfig path: The kubeconfig is read on the machine running Triagic, not on the portal's host and not on anyone else's laptop. Paste it here instead when the members who will use this integration do not all keep one at the same path. Path on each machine running Triagic, or paste the file itself.
    • API server URL
    • Service-account token: The bearer token of a read-only service account: `kubectl create token triagic`, or the `token` value of its secret.
  3. 3

    Let a desktop pick it up

    Saving validates the shape of what you typed. The first desktop app to sync starts Kubernetes locally and reports running or degraded with the error text.

Field-by-field setup, TLS options and the error table: Kubernetes in the docs.

Read-only, by construction

Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale.

FAQ

Can Triagic change anything in Kubernetes?
No. Started with ALLOW_ONLY_READONLY_TOOLS=true, so the server never registers apply, delete, exec or scale. Give it a read-only credential as well, so the guarantee does not rest on one layer.
What do I need to connect Kubernetes?
Kubeconfig, Kubeconfig path, API server URL, Service-account token. The desktop app on a member's machine starts the connection; the portal never holds a live process.
Does Kubernetes cost extra?
No. Every connector is included in the seat price. Start a 14-day trial without a card.

Related integrations

Try it on your own Kubernetes

No card. Install the desktop app, connect Kubernetes read-only, and triage a real ticket this afternoon.