Metrics
Three metric sources — Metrics Server for live data, the agent for history and flows, or your existing Prometheus (including managed offerings).
KubeBolt has three metric sources. They compose: every cluster starts with Metrics Server, and the agent adds history when you want it.
| Source | Setup | What you get |
|---|---|---|
| Metrics Server | None (pre-installed on most distros) | Live CPU/memory for pods and nodes |
| Agent — collectors / scrape | Install the agent | Historical metrics in KubeBolt’s embedded VictoriaMetrics: kubelet and node signals, optional vmagent scrape sidecar for Prometheus targets, optional Hubble network flows |
| Agent — read your Prometheus | Agent with promRead | Same history, sourced from the Prometheus you already run — including Amazon Managed Prometheus, Google Managed Prometheus, and Azure Monitor |
Metrics Server (baseline)
The Metrics Collector polls metrics.k8s.io/v1beta1 (PodMetrics and
NodeMetrics) every 30 seconds. Results are stored in an in-memory cache.
Graceful degradation: if Metrics Server is not installed, KubeBolt shows
all resource state and events normally; CPU/memory bars display a one-click
install command. The Collector distinguishes “not installed” from
“403 Forbidden” via apierrors.IsForbidden().
Namespace-scoped fallback: when cluster-wide metrics access is denied, the Collector polls per accessible namespace instead.
Agent-shipped history
The agent ships samples over gRPC into KubeBolt’s embedded VictoriaMetrics, which powers the Capacity and Reliability tabs, workload metric history, and the Cost tab:
- Built-in collectors (always on) — the DaemonSet ships kubelet stats plus node load/pressure signals.
- Scrape sidecar (
scrape.enabled=true) — a bundledvmagentscrapes in-cluster Prometheus targets, with defensive cardinality caps (maxSeriesPerTarget, total-series cap) so one misbehaving exporter can’t flood the store. vmagent ships over Prometheus remote_write (itsscrape.remoteWriteUrl), so it needs the backend’s receiver turned on — see below. - promRead (
agent.promRead.enabled=true) — a single-replica Deployment queries your existing Prometheus’squery_rangeAPI for the families the collectors don’t produce (kube-state-metrics, node load/PSI, disk, network errors). Auth modes:none,basicAuth,bearer,awsSigV4(AMP via IRSA),gcpIam(GMP via Workload Identity),azureWorkloadIdentity.
scrape and promRead are mutually exclusive — the chart fails at
helm template if both are enabled. If a node-exporter source already
ships load/PSI series, set agent.deferNodeStress=true to avoid duplicate
series.
Prometheus remote_write receiver
KubeBolt can also accept Prometheus remote_write at POST /api/v1/prom/write
— from the agent’s scrape sidecar or from a Prometheus you run. The receiver is
off by default: turn it on with KUBEBOLT_REMOTE_WRITE_ENABLED=true (or in
Administration → Agents & Ingest → Configuration). Its authentication
is KUBEBOLT_REMOTE_WRITE_AUTH_MODE: disabled (the default — no bearer token
checked), permissive (a token is checked and a bad or missing one is logged, but the
request still passes) or enforced (a valid ingest token is required; anything
else gets 401). Use enforced for anything reachable from outside
the cluster.
Querying
Historical metrics are exposed through the API (/api/v1/metrics/query and
/api/v1/metrics/query_range) using PromQL, scoped to the selected cluster.