Data Connections

Connecting a Kubernetes cluster

Deploy the DigiUsher Kubernetes agent with Helm and connect cluster metrics to DigiUsher.

Overview

When you connect a cluster, your Kubernetes spend appears in DigiUsher beside your cloud bills. You get the cost for each namespace, workload, and team. You also see the capacity that you pay for but do not use, and the rightsizing signals of the workloads with too many resources.

To collect this data, install a small agent in your cluster with Helm. The connection takes a few minutes. First create a Kubernetes data source in DigiUsher to get an install token. Then run two Helm commands. After that, the agent sends the metrics by itself, and your cluster costs appear in DigiUsher.

What gets installed

The chart digiusher-k8s-agent installs two small workloads and nothing more. It installs no kube-state-metrics, and no time-series database in the cluster. You therefore have no database to run, to scale, or to pay for.

ComponentTypeWhat it does
agentStatefulSet (1 pod)Receives metrics from vmagent, watches the Kubernetes API to build object metadata in-process, writes the data to a persistent volume, and uploads it to DigiUsher.
vmagentDeployment (1 pod)Scrapes each node's kubelet (cAdvisor and /metrics endpoints), plus optional GPU and node exporters when present, and forwards the metrics to the agent.

Both workloads run as a user that is not root. They use a read-only root filesystem, they drop all Linux capabilities, and they cannot raise their privileges. You can therefore run the agent in a restricted cluster and in a regulated cluster.

Prerequisites

RequirementDetails
HelmHelm must be installed on your computer. The Helm documentation gives the installation steps.
Kubernetes accessUse a kubeconfig context with the permission to create namespaces, workloads, services, service accounts, config maps, secrets, and persistent volume claims. You also need the permission to create the cluster-scoped ClusterRole and ClusterRoleBinding that the agent uses to read object metadata.
DigiUsher accessYou need the permission to create a Kubernetes data source in DigiUsher.
Outbound accessThe agent must be able to reach https://app.digiusher.com/api/v3.
StorageThe cluster must have a default storage class that can provision volumes. Run kubectl get storageclass to see the default class and its provisioner. The agent claims 20Gi, and vmagent claims 30Gi. You can change both sizes.
  • Google GKE and Azure AKS create a default storage class.
  • Amazon EKS needs the aws-ebs-csi-driver add-on. The add-on registers the provisioner ebs.csi.aws.com. Without the add-on, the default gp2 class uses an in-tree provisioner that Kubernetes 1.23 and later do not support.

Keep the default namespace

Install the chart in the digiusher-k8s namespace. Use another namespace only when DigiUsher support tells you to change the chart. The default configuration of the agent points to services in this namespace.

Connect your cluster

The connection has two parts. First you create the data source in DigiUsher, which gives you a Helm command that you can run. Then you run that command in your cluster.

Create the Kubernetes data source

  1. Open the DigiUsher app.
  2. Go to Connectors, under System.
  3. Click Add Source.
  4. Select the Kubernetes tile to open its connect flow.
  5. On the Configure step, enter a Display Name for the cluster. DigiUsher gives this name to the cluster everywhere, so use a name that you know again, for example prod-eks-us-east. Click Review.
  6. On the Connect step, click Connect source.

The wizard goes to the Deploy step. It gives the full helm repo add command and helm install command, with your token in them. Copy the commands and run them in your cluster. The steps that follow give the same commands with more context. Click Done when you finish.

You can come back to this anytime

These commands stay on the page of the connector in DigiUsher. You do not have to keep a copy outside the cluster.

Add the DigiUsher Helm repository

helm repo add digiusher https://digiusher.github.io/helm-charts
helm repo update

Make sure that the chart is available:

helm search repo digiusher

Install the agent

Replace <insert_api_token> with your token.

helm install digiusher-k8s-agent digiusher/digiusher-k8s-agent \
  --set agent.env.digiusher_k8s_api_token=<insert_api_token> \
  --namespace digiusher-k8s \
  --create-namespace

Helm stores the token in a Kubernetes secret with the name digiusher-k8s-agent-api-token, under the key K8S_API_TOKEN. If you do not want to give the token on the command line, put it in a values file and install with -f values.yaml.

Make sure that both pods run

Make sure that Helm deployed the release and that both workloads run:

helm status digiusher-k8s-agent --namespace digiusher-k8s
kubectl get pods --namespace digiusher-k8s

The agent pod and the vmagent pod must reach the state Running. After that, the agent starts to upload the data by itself. Your cluster costs appear in DigiUsher after the first upload and the first processing cycle. You do not have to do anything more.

What you can configure

The default values work on almost every cluster, so most teams install the chart without a change. These settings are useful to know:

  • Match your chargeback tags. The agent collects the pod annotations team, cost-center, and owner, and DigiUsher attributes the cost with them. If your organization uses other keys, set agent.informers.annotationKeys to your own list, separated by commas.
  • GPU metrics and node metrics need no configuration. If your cluster runs an NVIDIA dcgm-exporter or a node-exporter, the agent finds it and scrapes it. You then get the GPU cost and the node-consolidation analysis. To stop this, set vmagent.dcgm.enabled or vmagent.nodeExporter.enabled to false.
  • Restricted clusters. If you cannot create cluster-scoped roles, ask an administrator to create the ClusterRole and the ClusterRoleBinding of the agent first. Then install with --set agent.rbac.create=false.
  • Large clusters. The default values suit clusters into the low thousands of nodes. Above that size, raise the memory of the agent. The sizing notes give the details.

For more than one or two flags, put your values in a values file. Then install or upgrade with -f values.yaml.

What DigiUsher collects

The agent collects only the data that DigiUsher needs to allocate the cost and to rightsize the workloads. This data is the Kubernetes object metadata and the resource usage. The agent builds the object metadata in-process from the Kubernetes API. The vmagent scrapes the usage metrics from each node.

SourceExamples of collected data
Agent (Kubernetes API)Namespaces, nodes, pods, deployments, daemonsets, replica sets, replication controllers, statefulsets, jobs, cronjobs, services, persistent volumes, persistent volume claims, storage classes, resource quotas, horizontal pod autoscalers, and pod disruption budgets. It also collects the pod annotations that you configure for the cost allocation
cAdvisor (via vmagent)Container CPU usage, memory usage, network receive bytes, and network transmit bytes
kubelet (via vmagent)Persistent volume used, capacity, and available bytes
dcgm-exporter (optional)GPU utilization metrics, when an NVIDIA dcgm-exporter is present
node-exporter (optional)Node CPU, memory, filesystem, disk, and network metrics for node-consolidation analysis, when a node-exporter is present

The two optional exporters are enabled by default. On a cluster without them, they have no effect, because vmagent finds no target to scrape.

Upgrade the agent

Update the Helm repository and upgrade the release:

helm repo update
helm upgrade digiusher-k8s-agent digiusher/digiusher-k8s-agent \
  --set agent.env.digiusher_k8s_api_token=<insert_api_token> \
  --namespace digiusher-k8s

If you installed the chart with your own values file, give the same file at the upgrade:

helm upgrade digiusher-k8s-agent digiusher/digiusher-k8s-agent \
  -f values.yaml \
  --namespace digiusher-k8s

Uninstall the agent

To remove the DigiUsher Kubernetes agent from the cluster:

helm uninstall digiusher-k8s-agent --namespace digiusher-k8s

If you do not need the namespace and the resources in it, delete the namespace separately:

kubectl delete namespace digiusher-k8s

Deleting the namespace removes all resources inside it

CAUTION: Delete the digiusher-k8s namespace only when it contains the DigiUsher agent alone. The deletion removes every resource in the namespace.

Troubleshooting

IssueWhat to Check
Helm cannot find the chartRun helm repo add digiusher https://digiusher.github.io/helm-charts and helm repo update. Then run helm search repo digiusher again.
Pods stay in PendingRun kubectl get pvc --namespace digiusher-k8s. A claim that stays in Pending means that the cluster cannot provision the volume. See the Storage row in Prerequisites.
Pods are not startingRun kubectl describe pod <pod-name> --namespace digiusher-k8s and look for image pull, scheduling, persistent volume, and resource errors.
Token secret is missingMake sure that the install command contained --set agent.env.digiusher_k8s_api_token=<insert_api_token>.
Agent cannot send dataMake sure that the cluster egress permits https://app.digiusher.com/api/v3.
No Kubernetes data appears in DigiUsherMake sure that both pods in digiusher-k8s run. Then wait for the first upload and the first processing cycle.

If you have a question or a problem, write to the DigiUsher support team at support@digiusher.com.

On this page