Skip to content

Configuration ​

Both agents are configured entirely through Helm values (which map to the container's environment). This page is a reference; see installation for install commands.

kubespend-agent ​

ValueEnvDefault
clusterIdCLUSTER_ID"" (auto-detected)
apiKeyAPI_KEY (via Secret)—
serverAddrSERVER_ADDRingest.kubespend.io:443
ingestInsecureINGEST_INSECUREfalse (TLS)
scrapeIntervalSCRAPE_INTERVAL30s
namespaceNAMESPACE(all)
image.repository / image.tag—chart appVersion
resources—50m/64Mi → 200m/128Mi
serviceAccount.create—true
nodeSelector / tolerations / affinity—{}

clusterId is optional. Left empty it is auto-detected: an eksctl cluster-name node label if one is present, otherwise a stable id derived from the kube-system namespace UID. Set it for a readable name, or rename the cluster in the console afterwards.

The sink is fixed to grpc and in-cluster auth is used automatically (the chart grants the required RBAC).

kubespend-ebpf-agent ​

ValueEnv / argDefault
modeRELAY_MODErelay
clusterIdCLUSTER_ID(auto-detected)
relay.service—— (required in relay mode)
relay.port—9099
relay.addr—— (composed from relay.service, namespace and port)
relay.tokenAudience—kubespend-relay
apiKey / existingSecretAPI_KEY— (direct mode only)
serverAddrSERVER_ADDRingest.kubespend.io:443
vethRegexPOD_VETH_REGEX^(veth|lxc|cali|eni)
nodeRegexNODE_IFACE_REGEX^(ens|eth|en[posx])
ifaceWatchIntervalIFACE_WATCH_INTERVAL5s
windowFLOW_WINDOW30s
flowDetailFLOW_DETAILconversation
enableJitInitContainer—false
securityContext.privileged—false
securityContext.capabilities.add—[BPF,PERFMON,NET_ADMIN]

In the default relay mode the DaemonSet holds no API key — it authenticates to the in-cluster kubespend-agent with a projected ServiceAccount token, and serverAddr is unused because the metrics agent owns the outbound push. apiKey and serverAddr apply only when mode: direct.

relay.service has no default, and one of relay.service or relay.addr must be set: the chart calls fail when both are empty, so a missing value stops the install at template rendering rather than producing a DaemonSet with nowhere to dial. The metrics-agent chart names its Service after its release (kubespend-agent for the documented install, <release>-kubespend-agent otherwise) — find it with kubectl get svc -n <namespace> -l app.kubernetes.io/name=kubespend-agent.

Secrets & GitOps ​

Prefer existingSecret over inline apiKey so the token never lands in values files or release history. Create the Secret out-of-band (sealed-secrets, external-secrets, or kubectl create secret).

Self-hosted endpoints ​

Override serverAddr to your VPC ingest endpoint. TLS is expected to terminate at your load balancer; agents dial the endpoint on :443 and verify its certificate against the system CA roots.

ingestInsecure: true makes the metrics agent dial without TLS. Use it only when nothing terminates TLS in front of core, such as a local stack: the API key travels in request metadata, so it is then sent in cleartext.

Every figure in KubeSpend traces to a real cloud price. Where we cannot measure something, we say so.