Dashboard access
Expose add-on dashboards only when installation, health, trust, and session policy permit it.
RC
Exact release scope. This page documents the reviewed v0.0.1 source at fcc5871. Check release status before enabling a gated capability.
Access modes and maturity
| Mode | v0.0.1 status | Boundary |
|---|---|---|
| Direct public dashboard | Preview / gated | Operator-managed endpoint, TLS, authentication, and network policy. |
| Brokered SSO | Preprod-only | Disabled by default; not a general enterprise IdP claim. |
Access gates
- ✓The add-on installation reached a successful terminal state.
- ✓All critical resource and semantic health gates pass.
- ✓The endpoint resolves through the approved ingress/network path with trusted TLS.
- ✓The user has the required ClusterPilot role and add-on access policy.
- ✓Any short-lived session, cookie, or broker token is bound, bounded, and audited.
- ✓No raw dashboard credential, Service DNS name, bearer token, or kubeconfig is returned in ProblemDetails.
Blocked dashboard states
| Code/state | Action |
|---|---|
DASHBOARD_HEALTH_GATE_BLOCKED | Repair the latest add-on health-gate failure; dashboard retry must not reinstall the add-on. |
DASHBOARD_INSTALLING | Wait for the add-on OperationRun to reach a terminal state. |
health_gate_failed | Inspect linked run evidence, then rerun only the eligible gate/plan. |
Safe diagnostics
Capture add-on key, cluster, OperationRun, health check, correlation ID, endpoint mode, and the redacted ProblemDetails code. Do not copy raw URLs with session material, cookies, tokens, kubeconfigs, Secret values, or dashboard response bodies into tickets or screenshots.