Kubernetes
Connect
Connect Kubernetes from the terminal. Pass --help for the flags Kubernetes accepts, plus --no-browser for headless environments.
polylane cloud connect --provider kubernetesInstall the Polylane agent in your cluster with Helm.
Kubernetes connects through the Polylane agent, installed in your cluster with Helm. The agent authenticates once with a Polylane API key scoped to cloud_accounts:write, registers the cluster, and opens an outbound Cloudflare Tunnel. There is no kubeconfig to paste and no inbound ports to open, and your cluster credentials never leave the cluster.
Setup
- Start the Kubernetes connect flow in Polylane. It creates the API key for you.
- Run the Helm command shown in the flow:
helm install polylane oci://ghcr.io/coreplanelabs/charts/polylane-k8s \
--namespace polylane --create-namespace \
--set polylane.apiKey=<API_KEY> \
--set config.cluster_name=<your cluster name>
- The agent registers itself and your cluster appears in Polylane, usually in under a minute. Polylane then syncs your workloads, services, and other cluster resources.
For production installs, prefer apiKey.existingSecret (a pre-created Kubernetes Secret) over passing the key on the command line.
Permissions
The agent runs with read-only RBAC granting get, list, and watch. Polylane only makes read-only Kubernetes API calls.
Troubleshooting
If the cluster does not appear, check the agent pod: kubectl -n polylane get pods and kubectl -n polylane logs -l app.kubernetes.io/name=polylane-k8s -c agent.
Disconnecting
Uninstall the release with helm uninstall polylane --namespace polylane, disconnect the cluster in Polylane, then revoke the agent's API key under Settings → API keys.
Connect Kubernetes from a CI job or any other environment without a browser.
The Kubernetes connection is already pipeline-shaped: the agent installs with Helm and registers the cluster itself, so once you hold an API key there is no console step left.
Prerequisites
- A Polylane API key with the
cloud_accounts:writescope, stored as a pipeline secret. See API keys and OAuth. The guided flow creates this key for you; a key you create yourself works the same. - Helm and credentials for the target cluster in the job.
Install the agent
helm upgrade --install polylane oci://ghcr.io/coreplanelabs/charts/polylane-k8s \
--namespace polylane --create-namespace \
--set polylane.apiKey=$POLYLANE_API_KEY \
--set config.cluster_name=<your cluster name>
helm upgrade --install keeps the job re-runnable, and registration is idempotent per cluster, so repeating the pipeline never duplicates the connection. For production installs, prefer apiKey.existingSecret (a pre-created Kubernetes Secret) over passing the key on the command line.
The agent registers itself and the cluster appears in Polylane, usually in under a minute. If it does not, check the agent pod: kubectl -n polylane get pods and kubectl -n polylane logs -l app.kubernetes.io/name=polylane-k8s -c agent.
Disconnect
Uninstall the release with helm uninstall polylane --namespace polylane, disconnect the cluster in Polylane, then revoke the agent's API key under Settings → API keys.
Disconnect
Disconnecting stops every sync and check and deletes the credentials Polylane held. Polylane removes what Kubernetes's API lets it remove. The following stays until you remove it yourself:
- Helm release and agent pods in the cluster
polylane cloud disconnect <id>Tools
1Operations agents can perform in threads.
Supported resources
24Resource types that show up in your infrastructure graph.