Project reference ↗

Headlamp gives people a visual way to inspect Kubernetes resources and perform cluster operations without making every interaction through kubectl. It can run as a desktop application or inside a cluster, and the user's Kubernetes permissions still govern access. It is useful for teams that want a shared or local interface for understanding workloads and their state. Choose its authentication, exposure and plugins according to the people and clusters it will serve.

Chart ownership

Headlamp's official in-cluster guide publishes the headlamp chart through https://kubernetes-sigs.github.io/headlamp/. In-cluster deployment and the desktop application have different exposure and credential-handling considerations.

Before adoption

Choose authentication and RBAC deliberately. Documentation examples that grant cluster-admin are demonstrations, not a least-privilege policy for every user. Verify a restricted user's read and write actions before exposing the interface. Configure TLS, protect mounted kubeconfigs and review plugin provenance. If adding cluster discovery or multiple clusters, limit the namespaces and credentials the instance can access. Keep command-line administration available while evaluating the replacement.

Follow the in-cluster Helm guide and authentication guidance.

Sources & further reading

  1. Headlamp official Helm installation
  2. Headlamp authentication and RBAC

Spotted something that needs another look?

Help improve this page →