-
Notifications
You must be signed in to change notification settings - Fork 0
Docker Deployment
Run telectl as a container you manage yourself (not via the Helm chart).
Multi-arch images (linux/amd64, linux/arm64) are published to GHCR.
docker pull ghcr.io/ksauraj/telectl:v0.1.0-beta.0Tags follow the release policy — use the latest
release tag (e.g.
v0.1.0-beta.0). latest is not pinned; prefer an explicit immutable tag.
# 1. Write your config
cat > config.yaml <<'EOF'
telegram:
bot_token: "YOUR_BOT_TOKEN"
allowed_user_ids: [YOUR_ADMIN_TELEGRAM_ID]
kubernetes:
kubeconfig_path: "/app/kubeconfig"
EOF
# 2. Run, mounting config + kubeconfig
docker run -d --name telectl \
-v "$PWD/config.yaml:/app/config.yaml:ro" \
-v "$PWD/kubeconfig":/app/kubeconfig:ro \
ghcr.io/ksauraj/telectl:v0.1.0-beta.0- The image's
ENTRYPOINTalready passes--config /app/config.yamland setsTELECTL_CONFIG=/app/config.yaml, so mounting your config there means it's picked up automatically. - Mount your kubeconfig into the container and point
kubernetes.kubeconfig_pathat it.
Inside a pod, telectl auto-detects the cluster and uses rest.InClusterConfig()
— you do not mount a kubeconfig. Mount only the config:
docker run -d --name telectl \
-v "$PWD/config.yaml":/app/config.yaml:ro \
ghcr.io/ksauraj/telectl:v0.1.0-beta.0The image runs as non-root user telectl (uid 1000), so give it a
ServiceAccount token — this is exactly what the
Helm chart wires up for you.
docker build -t telectl:local .Requires Go 1.23+ (builder stage). The ARG TARGETARCH in the Dockerfile
means multi-platform builds (docker buildx build --platform linux/amd64,linux/arm64 …)
compile the correct binary per platform.
- Keep
config.yamlout of the image; mount it read-only. - The bot token is a cluster credential (it holds kubeconfig powers). Prefer a Secret + mounted file, or the Helm chart's Secret, over baking it into the image.
- See Security and Production Checklist.
For an in-cluster Deployment with RBAC + impersonation, the
Helm chart is the recommended, declarative path — it
creates the ServiceAccount, Secret, ConfigMap, and RBAC for you. docker run
gives you full manual control but leaves RBAC wiring to you. See
Two Deployment Modes.
Getting Started
User Guides
Deployment
- Try It Locally
- Helm Chart Guide
- Docker Deployment
- Two Deployment Modes
- Kubernetes RBAC
- Impersonation & RBAC
- Production Checklist
Development
- Architecture Overview
- How It Works
- Development Setup
- Contributing Guide
- Testing Guide
- Release Process
- Versioning & Releases
Operations