Dashboard access
Expose add-on dashboards only when installation, health, trust, and session policy permit it.
Dashboard access
| Mode | Status | Security |
|---|---|---|
| Direct dashboard | Available | Operator-managed endpoint, TLS, authentication and network policy. |
Access gates
- ✓The add-on installation reached a successful terminal state.
- ✓All critical resource and semantic health gates pass.
- ✓The endpoint resolves through the approved ingress/network path with trusted TLS.
- ✓The user has the required ClusterPilot role and add-on access policy.
- ✓Any short-lived session, cookie, or broker token is bound, bounded, and audited.
- ✓No raw dashboard credential, Service DNS name, bearer token, or kubeconfig is returned in ProblemDetails.
Blocked dashboard states
| Code/state | Action |
|---|---|
DASHBOARD_HEALTH_GATE_BLOCKED | Repair the latest add-on health-gate failure; dashboard retry must not reinstall the add-on. |
DASHBOARD_INSTALLING | Wait for the add-on OperationRun to reach a terminal state. |
health_gate_failed | Inspect linked run evidence, then rerun only the eligible gate/plan. |
Safe diagnostics
Capture add-on key, cluster, OperationRun, health check, correlation ID, endpoint mode, and the redacted ProblemDetails code. Do not copy raw URLs with session material, cookies, tokens, kubeconfigs, Secret values, or dashboard response bodies into tickets or screenshots.