Installing Headlamp

Installing Headlamp for BookNest's Cluster

Headlamp's documented in-cluster install is its Helm 29,435 chart. By default the chart also binds its own service account to cluster-admin; since users log in with their own tokens, turn that off. The kind 14,561 cluster l2-tools maps NodePort 30080 to host port 32080 (an extraPortMappings entry, Multi-Node Cluster), so a NodePort Service makes the UI reachable from the Windows browser. Then create a read-only identity to log in as, bound to the built-in view ClusterRole (Roles and ClusterRoles):

Installing Headlamp 0.45.0 with Helm, and a read-only viewer to log in asShell
helm repo add headlamp https://kubernetes-sigs.github.io/headlamp/ >/dev/null
helm install headlamp headlamp/headlamp --version 0.45.0 -n headlamp --create-namespace \
  --set clusterRoleBinding.create=false \
  --set service.type=NodePort --set service.nodePort=30080 --wait | grep STATUS
kubectl create serviceaccount viewer -n headlamp
kubectl create clusterrolebinding headlamp-viewer --clusterrole=view \
  --serviceaccount=headlamp:viewer
kubectl get pods,services -n headlamp
kubectl create token viewer -n headlamp --duration=1h > viewer.token
kubectl auth can-i delete pods -n booknest --as=system:serviceaccount:headlamp:viewer
Output
STATUS: deployed
serviceaccount/viewer created
clusterrolebinding.rbac.authorization.k8s.io/headlamp-viewer created
NAME                            READY   STATUS    RESTARTS   AGE
pod/headlamp-6fd8cf44d5-7gwkr   1/1     Running   0          12s
NAME               TYPE       CLUSTER-IP    EXTERNAL-IP   PORT(S)        AGE
service/headlamp   NodePort   10.96.45.42   <none>        80:30080/TCP   13s
no

kubectl 5,150 create token issues a short-lived token through the TokenRequest API (Service Accounts); nothing is stored in a Secret, and after an hour the login expires. Open http://localhost:32080, paste the token into the ID token field, and pick the booknest namespace:

Headlamp 0.45.0 in the l2-tools cluster, logged in with the viewer token: BookNest's five Pods (headless Chrome on the Windows host)
Headlamp 0.45.0 in the l2-tools cluster, logged in with the viewer token: BookNest's five Pods (headless Chrome 1 on the Windows host)

Headlamp reads RBAC before it draws a page. The same Deployment, opened with the viewer token and then with a short-lived cluster-admin token, shows the difference:

booknest-api's page header with the viewer token (top: view-only icons) and a cluster-admin token (bottom: rollback, restart, scale, edit and delete)
booknest-api's page header with the viewer token (top: view-only icons) and a cluster-admin token (bottom: rollback, restart, scale, edit and delete)

For the team, publish Headlamp through the Gateway of Ingress and the Gateway API with TLS instead of a NodePort, and prefer OIDC logins from your identity provider over pasted tokens.