Two per-context switches add safety. Set them in the Clusters & Kubeconfigs tab or in settings.json under kubernetes.contexts.<cluster-id>.
Production cluster
The cluster shows a red PROD badge in the title bar and sidebar. Destructive actions ask you to type the object's name to confirm: Delete, Kill, Drain and Undo rollout, plus Cordon, Uncordon and Scale from a list or the palette. Applying YAML asks for confirmation too, unless you set yaml_editor.confirm_apply_on_prod to false.
Read-only mode
Mutating actions are unavailable and mutating requests are blocked. That covers editing and applying, scaling, deleting and restarting, and also features that run code in the cluster:
- Exec, attach, debug containers and node shell.
- Port-forwarding and the file browser.
- Creating silences in alerts.
Reading is unaffected. Service web views are allowed on read-only clusters because they only read.
Permission checks
Independent of those switches, each action runs a SelfSubjectAccessReview first, so actions your RBAC forbids are disabled instead of failing halfway.
Bulk actions
Actions on a multi-selection report the items they skipped, for example because of RBAC or read-only mode.