Cluster nodes, kubeconfig, and join tokens
Read node health and capacity, protect administrative access, and add workers only when cluster operations are enabled.
Treat kubeconfig files and bootstrap tokens as secrets: keep them out of tickets, chat, logs, and shell history. Downloaded kubeconfigs expire after 1 hour and are bound to a read-only role, but the underlying cluster API access must still be guarded.
Releases up to and including v0.3.0 are published under ghcr.io/valgulnecron, so this page uses that registry; releases after v0.3.0 move to ghcr.io/gameplanepanel.
Read cluster and node health
Confirm distribution, version, ready count, roles, pressure, uptime, pod capacity, CPU, and memory before changing infrastructure.
View node details via kubectl
The Gameplane dashboard’s Cluster page displays node names, roles, status (Ready/NotReady), CPU/memory allocatable capacity, and current usage (if metrics-server is installed). For deeper inspection:
# View all nodes with status
kubectl get nodes -o wide
# Inspect a single node (status, conditions, capacity, allocatable, labels, taints)
kubectl describe node <node-name>
# Check node metrics (requires metrics-server)
kubectl top nodes
kubectl top nodes <node-name>
Download and protect kubeconfig
The download action requires clusterOps.enabled in your Helm values and the downloader to hold the admin role. The generated file is a short-lived credential bound to read-only access.
Enable cluster operations
To unlock kubeconfig download and node-join actions, set clusterOps.enabled in your Helm values and reinstall:
# charts/gameplane/values.yaml (or helm upgrade --set)
clusterOps:
enabled: true
# Optional: external API server address for off-cluster access
# Omit to use the in-cluster API server address (unreachable from outside)
# externalAddress: "k8s.example.com:6443"
Then redeploy:
helm upgrade gameplane oci://ghcr.io/valgulnecron/charts/gameplane \
--version 0.2.0-beta.8 \
--set clusterOps.enabled=true
When clusterOps.enabled=false (the default), the Cluster page disables both buttons with a hint.
Add a node
Mint a short-lived token for the intended cluster, run the generated join procedure, then verify readiness and allocatable capacity.
Workflow
- Click “Add node” in the Cluster page’s actions menu.
- The API generates a 24-hour bootstrap token and returns the complete
kubeadm joincommand. - Copy the command and run it on the new node (must have kubeadm, kubelet, and a matching Kubernetes version):
kubeadm join api.k8s.example.com:6443 --token <id>.<secret> \ --discovery-token-ca-cert-hash sha256:<hex> - Wait 30–60 seconds for the node to register and become
Ready. - Verify:
kubectl get nodes kubectl top node <new-node-name> - Label or taint the node if needed (e.g., for game server affinity or isolation):
kubectl label node <new-node-name> game-server=true kubectl taint node <new-node-name> dedicated=gameservers:NoSchedule - Deploy a test GameServer to confirm scheduling and capacity.
Join token lifecycle
- Lifetime: 24 hours from creation.
- Single-use: The token expires automatically after use; no revocation needed.
- Per-cluster: Each bootstrap token is tied to the cluster the API server was reached from. Multi-cluster installs require generating a token for each control plane. Node-join token creation and kubeconfig issuance are local-cluster operations and are unavailable while viewing a remote cluster; remote node inventory instead needs the read permissions listed in the remote agent gateway guide.
- CA cert hash: The discovery token CA cert hash (
--discovery-token-ca-cert-hash) pins the cluster’s root CA and prevents man-in-the-middle attacks. It is always required.
Troubleshooting join failures
- “No ClusterCIDR configured” — typically a Kubernetes configuration issue, not Gameplane-specific. Check your cluster’s pod CIDR configuration.
- “Kubelet not ready” — the kubelet may take 1–2 minutes to initialize. Wait and retry
kubectl get nodes. - “TLS handshake timeout” — the new node cannot reach the API server. Verify network connectivity and firewall rules.
- “Token already used” — bootstrap tokens are one-time; generate a new token if the join fails.
CLUSTER OPS
Related topics
- Kubernetes Maintenance — node upgrades, drain procedures, security patches.
- High Availability — control plane redundancy, etcd backup, failover.
- Multi-cluster Topology — remote cluster registration and the unified cross-cluster dashboard.
- Remote Agent Gateway — install and register the per-cluster gateway.