Skip to content
Docs · Production and read-only

Clusters

Production and read-only

Guard rails for clusters you can't afford to break.

Two per-context switches add safety. Set them in the Clusters & Kubeconfigs tab or in settings.json under kubernetes.contexts.<cluster-id>.

Production cluster

The cluster shows a red PROD badge in the title bar and sidebar. Destructive actions ask you to type the object's name to confirm: Delete, Kill, Drain and Undo rollout, plus Cordon, Uncordon and Scale from a list or the palette. Applying YAML asks for confirmation too, unless you set yaml_editor.confirm_apply_on_prod to false.

Read-only mode

Mutating actions are unavailable and mutating requests are blocked. That covers editing and applying, scaling, deleting and restarting, and also features that run code in the cluster:

Reading is unaffected. Service web views are allowed on read-only clusters because they only read.

Permission checks

Independent of those switches, each action runs a SelfSubjectAccessReview first, so actions your RBAC forbids are disabled instead of failing halfway.

Bulk actions

Actions on a multi-selection report the items they skipped, for example because of RBAC or read-only mode.

Something missing or wrong? Open an issue on GitHub.