Docs

How the Monidori agent works.

A small read-only agent runs inside your cluster and reports out over HTTPS. Monidori never connects in, and never holds your cluster credentials. Here is exactly what it reads, what it sends and how it is secured.

your cluster         monidori.com┌──────────────────┐│ monidori-agent   │ every 30 s│ 1 pod, read-only │ ─ snapshot ───▶ stored│                  ││                  │ "logs of pod X?"│                  │ ◀─ held request ─│                  │ ─ answer ──────▶ you└──────────────────┘outbound HTTPS onlyno inbound port · no kubeconfig

Install it in two commands

kubectl apply -f \ monidori.com/agent/v1/install.yaml kubectl -n monidori-system create secret \ generic monidori-agent \ --from-literal=token=mdr_…

The dashboard hands you both with your own token filled in. The manifest is plain YAML you can read first: a ServiceAccount, a read-only ClusterRole and one Deployment.

When something goes wrong

  • Data older than 3 minutes is marked stale, and alert rules pause rather than guess
  • An Agent offline alert tells you when it stops reporting
  • If Monidori is unreachable the agent backs off and retries; nothing is lost, the last snapshot stays

What it reads

  • get / list on nodes, namespaces, pods, events, PVCs, Deployments, CronJobs and Jobs
  • get on pod logs, only when you open them
  • get on nodes/stats, for volume usage straight from each node's kubelet
  • No Secrets, no exec, no write verbs of any kind

What it sends

  • A snapshot every 30 seconds: names, statuses, restart counts, timestamps, capacities and volume usage
  • Never Secrets, environment variables or pod specs; only the fields the dashboard shows
  • Gzipped JSON, capped at 5 MB, validated field by field on arrival
  • We keep only the latest snapshot per cluster, plus 7 days of volume-usage history

Logs and YAML

  • Not collected in the background: fetched on demand when you open them
  • The agent keeps a request open to Monidori, so an answer comes back in about a second
  • Five request types exist: pod logs (current or previous run), node, Deployment and pod YAML, and refresh now
  • Each request is validated on the server and again in the agent. There is no generic "run this API call"
  • Answers are kept for about ten minutes and then deleted

Security

  • Outbound HTTPS to monidori.com only. No inbound port, no load balancer, no kubeconfig leaves your cluster
  • One token per cluster, shown once, stored only as a hash; rotate or revoke it from the dashboard
  • Runs as non-root with a read-only filesystem, all capabilities dropped and the default seccomp profile
  • A 55 MB distroless image with no shell, public on GitHub Container Registry
  • Read the whole manifest before you apply it, and uninstall by deleting the namespace