Connecting a Kubernetes cluster
Deploy the DigiUsher Kubernetes agent with Helm and connect cluster metrics to DigiUsher.
Overview
When you connect a cluster, your Kubernetes spend appears in DigiUsher beside your cloud bills. You get the cost for each namespace, workload, and team. You also see the capacity that you pay for but do not use, and the rightsizing signals of the workloads with too many resources.
To collect this data, install a small agent in your cluster with Helm. The connection takes a few minutes. First create a Kubernetes data source in DigiUsher to get an install token. Then run two Helm commands. After that, the agent sends the metrics by itself, and your cluster costs appear in DigiUsher.
What gets installed
The chart digiusher-k8s-agent installs two small workloads and nothing more. It installs no kube-state-metrics, and no time-series database in the cluster. You therefore have no database to run, to scale, or to pay for.
| Component | Type | What it does |
|---|---|---|
agent | StatefulSet (1 pod) | Receives metrics from vmagent, watches the Kubernetes API to build object metadata in-process, writes the data to a persistent volume, and uploads it to DigiUsher. |
vmagent | Deployment (1 pod) | Scrapes each node's kubelet (cAdvisor and /metrics endpoints), plus optional GPU and node exporters when present, and forwards the metrics to the agent. |
Both workloads run as a user that is not root. They use a read-only root filesystem, they drop all Linux capabilities, and they cannot raise their privileges. You can therefore run the agent in a restricted cluster and in a regulated cluster.
Prerequisites
| Requirement | Details |
|---|---|
| Helm | Helm must be installed on your computer. The Helm documentation gives the installation steps. |
| Kubernetes access | Use a kubeconfig context with the permission to create namespaces, workloads, services, service accounts, config maps, secrets, and persistent volume claims. You also need the permission to create the cluster-scoped ClusterRole and ClusterRoleBinding that the agent uses to read object metadata. |
| DigiUsher access | You need the permission to create a Kubernetes data source in DigiUsher. |
| Outbound access | The agent must be able to reach https://app.digiusher.com/api/v3. |
| Storage | The cluster must have a default storage class that can provision volumes. Run kubectl get storageclass to see the default class and its provisioner. The agent claims 20Gi, and vmagent claims 30Gi. You can change both sizes.
|
Keep the default namespace
Install the chart in the digiusher-k8s namespace. Use another namespace only
when DigiUsher support tells you to change the chart. The default
configuration of the agent points to services in this namespace.
Connect your cluster
The connection has two parts. First you create the data source in DigiUsher, which gives you a Helm command that you can run. Then you run that command in your cluster.
Create the Kubernetes data source
- Open the DigiUsher app.
- Go to Connectors, under System.
- Click Add Source.
- Select the Kubernetes tile to open its connect flow.
- On the Configure step, enter a Display Name for the cluster. DigiUsher gives this name to the cluster everywhere, so use a name that you know again, for example
prod-eks-us-east. Click Review. - On the Connect step, click Connect source.
The wizard goes to the Deploy step. It gives the full helm repo add command and helm install command, with your token in them. Copy the commands and run them in your cluster. The steps that follow give the same commands with more context. Click Done when you finish.
You can come back to this anytime
These commands stay on the page of the connector in DigiUsher. You do not have to keep a copy outside the cluster.
Add the DigiUsher Helm repository
helm repo add digiusher https://digiusher.github.io/helm-charts
helm repo updateMake sure that the chart is available:
helm search repo digiusherInstall the agent
Replace <insert_api_token> with your token.
helm install digiusher-k8s-agent digiusher/digiusher-k8s-agent \
--set agent.env.digiusher_k8s_api_token=<insert_api_token> \
--namespace digiusher-k8s \
--create-namespaceHelm stores the token in a Kubernetes secret with the name digiusher-k8s-agent-api-token, under the key K8S_API_TOKEN. If you do not want to give the token on the command line, put it in a values file and install with -f values.yaml.
Make sure that both pods run
Make sure that Helm deployed the release and that both workloads run:
helm status digiusher-k8s-agent --namespace digiusher-k8s
kubectl get pods --namespace digiusher-k8sThe agent pod and the vmagent pod must reach the state Running. After that, the agent starts to upload the data by itself. Your cluster costs appear in DigiUsher after the first upload and the first processing cycle. You do not have to do anything more.
What you can configure
The default values work on almost every cluster, so most teams install the chart without a change. These settings are useful to know:
- Match your chargeback tags. The agent collects the pod annotations
team,cost-center, andowner, and DigiUsher attributes the cost with them. If your organization uses other keys, setagent.informers.annotationKeysto your own list, separated by commas. - GPU metrics and node metrics need no configuration. If your cluster runs an NVIDIA dcgm-exporter or a node-exporter, the agent finds it and scrapes it. You then get the GPU cost and the node-consolidation analysis. To stop this, set
vmagent.dcgm.enabledorvmagent.nodeExporter.enabledtofalse. - Restricted clusters. If you cannot create cluster-scoped roles, ask an administrator to create the
ClusterRoleand theClusterRoleBindingof the agent first. Then install with--set agent.rbac.create=false. - Large clusters. The default values suit clusters into the low thousands of nodes. Above that size, raise the memory of the
agent. The sizing notes give the details.
For more than one or two flags, put your values in a values file. Then install or upgrade with -f values.yaml.
What DigiUsher collects
The agent collects only the data that DigiUsher needs to allocate the cost and to rightsize the workloads. This data is the Kubernetes object metadata and the resource usage. The agent builds the object metadata in-process from the Kubernetes API. The vmagent scrapes the usage metrics from each node.
| Source | Examples of collected data |
|---|---|
| Agent (Kubernetes API) | Namespaces, nodes, pods, deployments, daemonsets, replica sets, replication controllers, statefulsets, jobs, cronjobs, services, persistent volumes, persistent volume claims, storage classes, resource quotas, horizontal pod autoscalers, and pod disruption budgets. It also collects the pod annotations that you configure for the cost allocation |
| cAdvisor (via vmagent) | Container CPU usage, memory usage, network receive bytes, and network transmit bytes |
| kubelet (via vmagent) | Persistent volume used, capacity, and available bytes |
| dcgm-exporter (optional) | GPU utilization metrics, when an NVIDIA dcgm-exporter is present |
| node-exporter (optional) | Node CPU, memory, filesystem, disk, and network metrics for node-consolidation analysis, when a node-exporter is present |
The two optional exporters are enabled by default. On a cluster without them, they have no effect, because vmagent finds no target to scrape.
Upgrade the agent
Update the Helm repository and upgrade the release:
helm repo update
helm upgrade digiusher-k8s-agent digiusher/digiusher-k8s-agent \
--set agent.env.digiusher_k8s_api_token=<insert_api_token> \
--namespace digiusher-k8sIf you installed the chart with your own values file, give the same file at the upgrade:
helm upgrade digiusher-k8s-agent digiusher/digiusher-k8s-agent \
-f values.yaml \
--namespace digiusher-k8sUninstall the agent
To remove the DigiUsher Kubernetes agent from the cluster:
helm uninstall digiusher-k8s-agent --namespace digiusher-k8sIf you do not need the namespace and the resources in it, delete the namespace separately:
kubectl delete namespace digiusher-k8sDeleting the namespace removes all resources inside it
CAUTION: Delete the digiusher-k8s namespace only when it contains the
DigiUsher agent alone. The deletion removes every resource in the namespace.
Troubleshooting
| Issue | What to Check |
|---|---|
| Helm cannot find the chart | Run helm repo add digiusher https://digiusher.github.io/helm-charts and helm repo update. Then run helm search repo digiusher again. |
Pods stay in Pending | Run kubectl get pvc --namespace digiusher-k8s. A claim that stays in Pending means that the cluster cannot provision the volume. See the Storage row in Prerequisites. |
| Pods are not starting | Run kubectl describe pod <pod-name> --namespace digiusher-k8s and look for image pull, scheduling, persistent volume, and resource errors. |
| Token secret is missing | Make sure that the install command contained --set agent.env.digiusher_k8s_api_token=<insert_api_token>. |
| Agent cannot send data | Make sure that the cluster egress permits https://app.digiusher.com/api/v3. |
| No Kubernetes data appears in DigiUsher | Make sure that both pods in digiusher-k8s run. Then wait for the first upload and the first processing cycle. |
If you have a question or a problem, write to the DigiUsher support team at support@digiusher.com.
DigiUsher Documentation