Read-Only by Design
The dashboard can look, but never touch:
Because it can’t act, the UI names the problem and the fix (Health → Issues & Fixes); you make the
change with
tmo-cli, kubectl, or Helm.
The UI gets its cluster access from Kubernetes at runtime: no credentials are baked into the image
or the chart, and none ever reach the browser.
How It’s Reached
1
Default — Port-Forward
By default the UI is private to the cluster. If you have cluster access, a port-forward
is all you need:
2
Team Access — Ingress Behind SSO
For shared access, enable the ingress (
ingress.enabled=true, with your own hosts and TLS)
and put single sign-on in front of it (see below).Single Sign-On
The UI has no built-in login. When you expose it to a team, sign-in happens at the ingress, the standard pattern for in-cluster dashboards. The ingress checks each request against your identity provider (Okta, Google, Entra, Keycloak, or any OIDC provider) and passes the signed-in identity to the UI, which shows Signed in as the authenticated user.- Works with any identity provider and any ingress controller.
- Offboarding someone in your identity provider revokes their UI access immediately. There’s no separate user list to maintain.

