Skip to content

USER GUIDE

Admin Basics (Aether)

Ports / access

Port Service
5090 Dashboard + API

Auth

OIDC + SAML + LDAP as configured, or a static API key (AETHER_API_KEY) for non-interactive/CLI access. If none of OIDC/SAML/LDAP/API-key is configured, Aether allows all requests (local-dev mode) — the chart now auto-generates an API key by default so a fresh install isn't left open; retrieve it:

kubectl -n <namespace> get secret <release>-aether-secrets -o jsonpath='{.data.api-key}' | base64 -d; echo

Set your own at install time with --set apiKey.value="a-real-key", or reference an existing Secret via apiKey.existingSecret.

Encryption key for stored secrets

AETHER_SECRET_KEY encrypts Aether's own on-disk secret store (stored credentials for the runtimes it manages — not just a login token). Also auto-generated by the chart by default now; without it, the app derives a key from the pod's HOSTNAME, which is predictable and visible to anyone with pod-list RBAC in the namespace — not a private seed in a Kubernetes deployment. Retrieve or set it the same way as the API key (encryption-key data key / --set secretKey.value=... / secretKey.existingSecret). Changing this key after secrets have been stored makes existing stored secrets unrecoverable — treat it like any other encryption key: set it once, back it up.

Install sketch

Follow the product README and deploy/Helm docs in the repository. Verify health endpoints or CLI status before opening the UI.

Operate from the console (UX)

  1. Open this route from the nav or command palette and wait for live API data.
  2. Use filters/search when present; drill into a row for detail.
  3. For mutating actions: confirm role gates and impact before applying.
  4. Empty / fail: Check service health, auth, and that required CRDs/backends for this domain are installed.
  5. Success: Live data loads; created/updated objects appear without error toasts.