Configuration
Both agents are configured entirely through Helm values (which map to the container's environment). This page is a reference; see installation for install commands.
kubespend-agent
| Value | Env | Default |
|---|---|---|
clusterId | CLUSTER_ID | "" (auto-detected) |
apiKey | API_KEY (via Secret) | — |
serverAddr | SERVER_ADDR | ingest.kubespend.io:443 |
ingestInsecure | INGEST_INSECURE | false (TLS) |
scrapeInterval | SCRAPE_INTERVAL | 30s |
namespace | NAMESPACE | (all) |
image.repository / image.tag | — | chart appVersion |
resources | — | 50m/64Mi → 200m/128Mi |
serviceAccount.create | — | true |
nodeSelector / tolerations / affinity | — | {} |
clusterId is optional. Left empty it is auto-detected: an eksctl cluster-name node label if one is present, otherwise a stable id derived from the kube-system namespace UID. Set it for a readable name, or rename the cluster in the console afterwards.
The sink is fixed to grpc and in-cluster auth is used automatically (the chart grants the required RBAC).
kubespend-ebpf-agent
| Value | Env / arg | Default |
|---|---|---|
mode | RELAY_MODE | relay |
clusterId | CLUSTER_ID | (auto-detected) |
relay.service | — | — (required in relay mode) |
relay.port | — | 9099 |
relay.addr | — | — (composed from relay.service, namespace and port) |
relay.tokenAudience | — | kubespend-relay |
apiKey / existingSecret | API_KEY | — (direct mode only) |
serverAddr | SERVER_ADDR | ingest.kubespend.io:443 |
vethRegex | POD_VETH_REGEX | ^(veth|lxc|cali|eni) |
nodeRegex | NODE_IFACE_REGEX | ^(ens|eth|en[posx]) |
ifaceWatchInterval | IFACE_WATCH_INTERVAL | 5s |
window | FLOW_WINDOW | 30s |
flowDetail | FLOW_DETAIL | conversation |
enableJitInitContainer | — | false |
securityContext.privileged | — | false |
securityContext.capabilities.add | — | [BPF,PERFMON,NET_ADMIN] |
In the default relay mode the DaemonSet holds no API key — it authenticates to the in-cluster kubespend-agent with a projected ServiceAccount token, and serverAddr is unused because the metrics agent owns the outbound push. apiKey and serverAddr apply only when mode: direct.
relay.service has no default, and one of relay.service or relay.addr must be set: the chart calls fail when both are empty, so a missing value stops the install at template rendering rather than producing a DaemonSet with nowhere to dial. The metrics-agent chart names its Service after its release (kubespend-agent for the documented install, <release>-kubespend-agent otherwise) — find it with kubectl get svc -n <namespace> -l app.kubernetes.io/name=kubespend-agent.
Secrets & GitOps
Prefer existingSecret over inline apiKey so the token never lands in values files or release history. Create the Secret out-of-band (sealed-secrets, external-secrets, or kubectl create secret).
Self-hosted endpoints
Override serverAddr to your VPC ingest endpoint. TLS is expected to terminate at your load balancer; agents dial the endpoint on :443 and verify its certificate against the system CA roots.
ingestInsecure: true makes the metrics agent dial without TLS. Use it only when nothing terminates TLS in front of core, such as a local stack: the API key travels in request metadata, so it is then sent in cleartext.