Docs
How the Monidori agent works.
A small read-only agent runs inside your cluster and reports out over HTTPS. Monidori never connects in, and never holds your cluster credentials. Here is exactly what it reads, what it sends and how it is secured.
your cluster monidori.com┌──────────────────┐│ monidori-agent │ every 30 s│ 1 pod, read-only │ ─ snapshot ───▶ stored│ ││ │ "logs of pod X?"│ │ ◀─ held request ─│ │ ─ answer ──────▶ you└──────────────────┘outbound HTTPS onlyno inbound port · no kubeconfig
Install it in two commands
kubectl apply -f \
monidori.com/agent/v1/install.yaml
kubectl -n monidori-system create secret \
generic monidori-agent \
--from-literal=token=mdr_…The dashboard hands you both with your own token filled in. The manifest is plain YAML you can read first: a ServiceAccount, a read-only ClusterRole and one Deployment.
When something goes wrong
- Data older than 3 minutes is marked stale, and alert rules pause rather than guess
- An Agent offline alert tells you when it stops reporting
- If Monidori is unreachable the agent backs off and retries; nothing is lost, the last snapshot stays
What it reads
- get / list on nodes, namespaces, pods, events, PVCs, Deployments, CronJobs and Jobs
- get on pod logs, only when you open them
- get on nodes/stats, for volume usage straight from each node's kubelet
- No Secrets, no exec, no write verbs of any kind
What it sends
- A snapshot every 30 seconds: names, statuses, restart counts, timestamps, capacities and volume usage
- Never Secrets, environment variables or pod specs; only the fields the dashboard shows
- Gzipped JSON, capped at 5 MB, validated field by field on arrival
- We keep only the latest snapshot per cluster, plus 7 days of volume-usage history
Logs and YAML
- Not collected in the background: fetched on demand when you open them
- The agent keeps a request open to Monidori, so an answer comes back in about a second
- Five request types exist: pod logs (current or previous run), node, Deployment and pod YAML, and refresh now
- Each request is validated on the server and again in the agent. There is no generic "run this API call"
- Answers are kept for about ten minutes and then deleted
Security
- Outbound HTTPS to monidori.com only. No inbound port, no load balancer, no kubeconfig leaves your cluster
- One token per cluster, shown once, stored only as a hash; rotate or revoke it from the dashboard
- Runs as non-root with a read-only filesystem, all capabilities dropped and the default seccomp profile
- A 55 MB distroless image with no shell, public on GitHub Container Registry
- Read the whole manifest before you apply it, and uninstall by deleting the namespace