Repository navigation
Look, never touch. k10s --readonly opens the dashboard with nothing
that can change the cluster — for production, for a cluster you are only
auditing, for handing the terminal to someone who should not be able to
delete a pod by reflex. The UI hides the write actions, and a transport under
every client refuses them again before a request leaves the machine, so a
code path the UI missed still cannot write.
This release is also the first built with a patched Go toolchain; see
Upgrading below.
Read-only mode (#5, #7) — thanks, @junior
k10s --readonly # your current context, nothing writable
k10s demo --readonly # the flag goes before or after demo
k10s --read-only # same flag, other spelling- The Actions pane keeps Describe, YAML, Logs and Top. Edit, Scale,
Rollout Restart, Cordon, Drain and Delete are gone, and so are Shell and
Port Forward, which open a session into the cluster. Their keys,:scale
included, answer with a notice instead of a dialog. - Plugins marked
dangerous: trueare hidden, as in k9s, and typed shell
commands do not run: they run as you, outside k10s, so read-only mode
cannot vouch for them. - The header says READ-ONLY for as long as the mode is on.
- The same rule holds on the wire. Every client k10s builds — clientset,
dynamic, discovery, metrics, and the exec and port-forward streams — gets a
transport that refuses anything other than GET, HEAD or OPTIONS, plus the
GETs that open exec, attach or port-forward streams over WebSockets, plus
anything sent through the proxy of a pod, a service or a node. Behind a
node proxy is the kubelet, whose own API includes exec, so nothing sent
through a proxy is known to only read. The tests drive a clientset, the
exec executor and the port-forward dialer against a recording server and
check that only the read reaches it.
Read-only mode is a guard against k10s, not against you: it does not change
what your kubeconfig is allowed to do, and a plugin or $EDITOR that talks to
the cluster on its own is outside it.
docs/commands.md
has the full list.
$KUBECONFIG with several files (#6) — thanks, @junior
With KUBECONFIG=a.yaml:b.yaml, k10s connected to the current context but
switching to another one failed:
load kubeconfig: stat a.yaml:b.yaml: no such file or directory
The first connection let client-go apply kubectl's loading rules and merge the
list; a context switch rebuilt the client from the raw path instead, and
client-go took the whole list as one file name. A switch now loads the same
way the first connection did. $KUBECONFIG as plugins see it is unchanged
and still carries the full list.
Also
- Returning to the table from logs, describe, YAML and the other full-screen
views goes through one helper, so every exit tears the session down the
same way.
Upgrading
Every release up to and including v0.1.6 was built with Go 1.26.0. The
release workflow read the toolchain from go.mod's go line, which is the
oldest Go the code builds with, not the one to ship. A trivy scan of the
v0.1.6 linux/amd64 binary lists 33 standard library vulnerabilities (22 rated
high) fixed in Go 1.26.1 through 1.26.6, among them crypto/x509 certificate
validation and crypto/tls issues. From v0.1.7 on, releases are built with the
newest 1.26 patch, and the build log prints go version so every release
shows which toolchain made it. If you run an older binary against clusters you
do not fully trust, upgrade.
Nothing else changes behaviour unless you pass --readonly.
/update from inside k10s — checksum-verified, atomic, offers to restart into
the new binary.
curl -fsSL https://p10node.com/k10s/install.sh | sh
go install github.com/p10node/k10s@latest
shasum -a 256 -c checksums.txt --ignore-missingchecksums.txt matches the download to what this release published; it is not
a signature of who published it.
Issues and friction reports: https://github.com/p10node/k10s/issues
What's Changed
- Build releases with the newest Go 1.26 patch, and add --readonly by @junior in #5
- Switch context with every file listed in $KUBECONFIG by @junior in #6
- Read-only mode: refuse proxy requests to pods, services and nodes by @junior in #7
New Contributors
Full Changelog: v0.1.6...v0.1.7