USER GUIDE
Admin Basics (Aether)
Ports / access¶
| Port | Service |
|---|---|
| 5090 | Dashboard + API |
Auth¶
OIDC + SAML + LDAP as configured, or a static API key (AETHER_API_KEY) for
non-interactive/CLI access. If none of OIDC/SAML/LDAP/API-key is configured, Aether
allows all requests (local-dev mode) — the chart now auto-generates an API key by
default so a fresh install isn't left open; retrieve it:
kubectl -n <namespace> get secret <release>-aether-secrets -o jsonpath='{.data.api-key}' | base64 -d; echo
Set your own at install time with --set apiKey.value="a-real-key", or reference an
existing Secret via apiKey.existingSecret.
Encryption key for stored secrets¶
AETHER_SECRET_KEY encrypts Aether's own on-disk secret store (stored credentials for
the runtimes it manages — not just a login token). Also auto-generated by the chart by
default now; without it, the app derives a key from the pod's HOSTNAME, which is
predictable and visible to anyone with pod-list RBAC in the namespace — not a private
seed in a Kubernetes deployment. Retrieve or set it the same way as the API key
(encryption-key data key / --set secretKey.value=... / secretKey.existingSecret).
Changing this key after secrets have been stored makes existing stored secrets
unrecoverable — treat it like any other encryption key: set it once, back it up.
Install sketch¶
Follow the product README and deploy/Helm docs in the repository. Verify health endpoints or CLI status before opening the UI.
Related¶
Operate from the console (UX)¶
- Open this route from the nav or command palette and wait for live API data.
- Use filters/search when present; drill into a row for detail.
- For mutating actions: confirm role gates and impact before applying.
- Empty / fail: Check service health, auth, and that required CRDs/backends for this domain are installed.
- Success: Live data loads; created/updated objects appear without error toasts.