diff --git a/README.md b/README.md
index 57ae8a8..dc2ff82 100644
--- a/README.md
+++ b/README.md
@@ -13,6 +13,7 @@ k8dash is the easiest way to manage your Kubernetes cluster. Why?
## Click the video below to see k8dash in action
[](http://www.youtube.com/watch?v=u-1jGAhAHAM "k8dash - Kubernetes Dashboard")
+
# Table of Contents
- [Prerequisites](#Prerequisites)
@@ -38,6 +39,8 @@ k8dash is the easiest way to manage your Kubernetes cluster. Why?
+ [metrics server](https://github.com/kubernetes-incubator/metrics-server) installed (optional, but strongly recommended)
+ A Kubernetes cluster configured for [OpenId Connect](https://kubernetes.io/docs/reference/access-authn-authz/authentication/#openid-connect-tokens) authentication (optional)
+back to [Table of Content](#table_of_content)
+
## Getting Started
Deploy k8dash with something like the following...
@@ -69,12 +72,16 @@ spec:
serviceName: k8dash
servicePort: 80
```
+
+back to [Table of Content](#table_of_content)
+
# kubectl proxy
Unfortunately, `kubectl proxy` can not be used to access k8dash. According to the information at [https://github.com/kubernetes/kubernetes/issues/38775#issuecomment-277915961](https://github.com/kubernetes/kubernetes/issues/38775#issuecomment-277915961), it seems that `kubectl proxy` strips the Authorization header when it proxies requests. From that link:
> this is working as expected. "proxying" through the apiserver will not get you standard proxy behavior (preserving Authorization headers end-to-end), because the API is not being used as a standard proxy
+back to [Table of Content](#table_of_content)
# Logging in
@@ -101,6 +108,8 @@ kubectl describe secret k8dash-sa-token-xxxxx
Retrieve the `token` value from the secret and enter it into the login screen to access the dashboard.
+back to [Table of Content](#table_of_content)
+
## Running k8dash with OpenId Connect (oidc)
k8dash makes using OpenId Connect for authentication easy. Assuming your cluster is configured to use OIDC, all you need to do is create a secret containing your credentials and run the [kubernetes-k8dash-oidc.yaml](https://raw.githubusercontent.com/herbrandson/k8dash/master/kubernetes-k8dash-oidc.yaml) config.
@@ -133,6 +142,8 @@ Additionally, there are a few other OIDC options you can provide via environment
The other option is `OIDC_METADATA`. k8dash uses the excellent [node-openid-client](https://github.com/panva/node-openid-client) module. `OIDC_METADATA` will take a json string and pass it to the `Client` constructor. Docs [here](https://github.com/panva/node-openid-client/blob/master/docs/README.md#client). For example, `OIDC_METADATA='{"token_endpoint_auth_method":"client_secret_post"}`
+back to [Table of Content](#table_of_content)
+
## Running k8dash with NodePort
If you do not have an ingress server setup, you can utilize a NodePort service as configured in the [kubernetes-k8dash-nodeport.yaml](https://raw.githubusercontent.com/herbrandson/k8dash/master/kubernetes-k8dash-nodeport.yaml). This is ideal when creating a single node master, or if you want to get up and running as fast as possible.
@@ -145,6 +156,8 @@ NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
k8dash NodePort 10.107.107.62 4654:32565/TCP 1m
```
+back to [Table of Content](#table_of_content)
+
## Metrics
k8dash relies heavily on [metrics-server](https://github.com/kubernetes-incubator/metrics-server) to display real time cluster metrics. It is strongly recommended to have metrics-server installed to get the best experiance from k8dash.
@@ -153,6 +166,8 @@ k8dash relies heavily on [metrics-server](https://github.com/kubernetes-incubato
+ [Running metrics-server with kubeadm](https://medium.com/@waleedkhan91/how-to-configure-metrics-server-on-kubeadm-provisioned-kubernetes-cluster-f755a2ac43a2)
+back to [Table of Content](#table_of_content)
+
# Development
@@ -163,6 +178,8 @@ Installing and running [minikube](https://kubernetes.io/docs/tasks/tools/install
Once minikube is installed, you can run it with the command `minikube start --driver=docker`
+ Once the cluster is up and running, create some login credentials as described [above](https://github.com/indeedeng/k8dash#logging-in)
+back to [Table of Content](#table_of_content)
+
## k8dash is made up of 2 parts. The server and the client.
@@ -173,12 +190,16 @@ The server is a simple express.js server that is primarily responsible for proxy
During development, the server will use whatever is configured in `~/.kube/config` to connect the desired cluster. If you are using minikube, for example, you can run `kubectl config set-context minikube` to get `~/.kube/config` set up correctly.
+back to [Table of Content](#table_of_content)
+
### Client
The client is a React application (using TypeScript) with minimal other dependencies.
To run the client, open a new terminal tab and navigate to the `/client` directory, run `npm i` and then `npm start`. This will open up a browser window to your local k8dash dashboard. If everything compiles correctly, it will load the site and then an error message will pop up `Unhandled Rejection (Error): Api request error: Forbidden...`. The error message has an 'X' in the top righthand corner to close that message. After you close it, you should see the UI where you can enter your token.
+back to [Table of Content](#table_of_content)
+
# License
@@ -186,3 +207,5 @@ To run the client, open a new terminal tab and navigate to the `/client` directo
[](https://app.fossa.com/projects/git%2Bgithub.com%2Findeedeng%2Fk8dash?ref=badge_large)
+
+You Have scrolled so far, lets go back to [Top](#table_of_content)