Clusters
The Clusters tab (Settings > Clusters) is where you register the Kubernetes clusters that the product watches. For each cluster you supply the connection details the console uses to scan pods, PVCs, and nodes. You can also connect a RunAI workload scheduler and the Dell CSI storage credentials.
This is the first tab to configure on a new install. The Data Security Posture, AI Risk Pipeline, and File Activity pages have no data until at least one cluster is registered and scanned.
Overview
Each cluster you add becomes one collapsible card. The console connects to the cluster's Kubernetes API on a schedule to build the topology and risk picture, and it never writes to the cluster.
Storage devices (PowerScale and ObjectScale / ECS) are configured on the Storage tab and act only as audit event sources. This tab covers the Kubernetes side and the per-cluster integrations.
- Click Add Cluster to create a card, complete its sections, then click Save Settings at the bottom of the tab. When there are unsaved edits, the button turns orange and reads Save Changes.
- Remove a cluster with the trash icon in its header.
Adding a cluster requires a license. Add Cluster is disabled, with a note above the list, until an active subscription is installed under Settings > Licensing. See Licensing.
- Clusters you already have keep working, and you can still edit or remove them, after a subscription expires.
- If the license ends while the page is open, Save Settings still saves your other changes. The new cluster stays on the page, unsaved, with a message, and saves once a license is installed.
- Without a license, removing a saved cluster asks you to confirm first, because you cannot add it back until a license is installed.
Secret fields (Bearer Token, RunAI client secret) are never returned to the browser in plaintext. Each secret field has a masked row with an eye icon to view the stored value, and a separate write-only input. Leave the write-only input blank to keep the existing secret, and type in it only to replace the stored value.
Cluster connection
This section is required for every cluster.
-
Display Name — a friendly label for the cluster. It appears in the cluster selectors on the Data Security and File Activity pages.
-
K8s API Endpoint — the HTTPS URL of the Kubernetes API server. It must be reachable from the host that runs the console.
- Rancher-managed clusters: use the Rancher proxy URL, for example
https://rancher.host/k8s/clusters/c-m-xxxx. - Direct clusters: use the kube-apiserver address, for example
https://192.0.2.10:6443.
- Rancher-managed clusters: use the Rancher proxy URL, for example
-
Bearer Token — a Kubernetes service-account token with read access to pods, PVCs, and nodes. Leave the input blank to keep the existing token. Generate a token with:
kubectl create token <service-account> -n <namespace> --duration=8760h -
Ignore SSL Certificates (Bypass Validation) — disables TLS certificate validation for the API endpoint. Enable it when the cluster uses a self-signed or private-CA certificate. Leave it off in production with publicly trusted certificates, because bypassing validation removes protection against man-in-the-middle attacks.
-
Test Connection — validates the endpoint and token immediately. A green check confirms that the console can reach the API. A red message shows the error so you can fix the URL, token, or TLS setting before saving.
Workload scheduler
This section is optional. It integrates RunAI so the topology can attribute GPU workloads to RunAI users and the RunAI scheduler filter on the Data Security page has data. Leave it blank if you do not run RunAI.
- Base URL — the RunAI control-plane URL, for example
https://runai.yourdomain.com. - Client ID / Client Secret — the RunAI API application credentials. Leave the secret blank to keep the existing one.
- Ignore SSL Certificates — applied to the RunAI endpoint.
- Test Connection — verifies that the console can authenticate to RunAI.
Dell storage integration
These fields identify the Kubernetes Secret that holds the Dell CSI driver credentials. The console uses it to map a PVC to its backend PowerScale export when it builds the topology.
- CSI Namespace — the namespace where the Dell CSI driver runs. Click Load from Cluster to fill a dropdown with the cluster's namespaces, or type the name directly, for example
dell-storage. - CSI Secret — the Secret that holds the CSI credentials, for example
csi-isilon-creds. Click Load secrets to list the Secrets in the chosen namespace, or type the name. View Contents decodes and displays the Secret's values so you can confirm that you selected the right one.
Scan schedule
There is no per-cluster scan schedule on this tab. Scan cadence for all clusters is configured under Settings > System Jobs > Schedules. After you register a cluster, set or confirm its scan schedule there, or run a one-off scan from the Jobs page.
Workflows
Register a cluster
- Open Settings > Clusters and click Add Cluster.
- Enter a Display Name and the K8s API Endpoint.
- Paste a service-account Bearer Token. Enable Ignore SSL Certificates if the cluster uses a self-signed certificate.
- Click Test Connection in the Cluster connection section and confirm that it returns a green check.
- Click Save Settings.
- Open the Jobs page or Settings > System Jobs > Schedules to run or schedule the first K8 scan. When the scan completes, the cluster appears on the Data Security Posture page.
Troubleshooting
- Test Connection fails on the API endpoint — the most common causes are an unreachable URL, an expired or under-scoped Bearer Token, or a TLS error that requires Ignore SSL Certificates.
- A cluster does not appear on the Data Security and File Activity pages — a cluster appears only after it has been scanned at least once.
- A secret was overwritten with an empty value — leave the write-only input blank when you save unrelated changes. Use the eye icon to reveal a stored value.