Kubernetes (OpenCost)
What Plutus imports
Section titled “What Plutus imports”- Cluster cost by namespace and workload, with pod labels
Connecting
Section titled “Connecting”Method: Plutus Agent (Helm install)
Unlike every other cost source, Plutus doesn’t pull this data — your cluster is behind your firewall, and Plutus can’t reach an in-cluster API from outside it. Instead, you install a small agent that reads OpenCost’s already-computed allocation data (OpenCost is a free CNCF project — the same engine behind Azure’s own AKS cost analysis) and pushes it out to Plutus over HTTPS. Plutus runs no other code inside your cluster and needs no inbound access to it.
-
In Plutus, go to Cost Sources → Kubernetes and click Generate API Key. This requires an account admin — a member can view the panel but won’t see this button.
-
Plutus shows the key once, along with a ready-to-run install command:
Terminal window helm install plutus-collector oci://ghcr.io/plutus-cloud/charts/plutus-collector \--namespace plutus-collector --create-namespace \--set clusterName=<your-cluster-name> \--set currency=<ISO-4217-code> \--set apiKey=<the key shown above>Replace
clusterNamewith whatever you want this cluster called in Plutus, andcurrencywith the ISO 4217 code your cluster’s costs are priced in — OpenCost doesn’t report a currency anywhere in its own output, so Plutus never assumes USD here. This installs OpenCost as a bundled subchart (if you don’t already run it — see the optional step below) plus the pusher itself, and cost data starts arriving within one push cycle (daily by default). -
Tracking more than one cluster? Run the same command again in each one — a single API key covers every cluster that pushes with it, and each push identifies its own cluster.
-
Optional — already running OpenCost yourself? Point the chart at it instead of installing a second copy:
Terminal window helm install plutus-collector oci://ghcr.io/plutus-cloud/charts/plutus-collector \--namespace plutus-collector --create-namespace \--set opencost.enabled=false \--set opencost.endpoint=http://opencost.<your-namespace>.svc.cluster.local:9003 \--set clusterName=<your-cluster-name> \--set currency=<ISO-4217-code> \--set apiKey=<the key shown above> -
Optional — to avoid putting the API key in Helm values/history, create the Secret yourself first and point the chart at it instead:
Terminal window kubectl create secret generic plutus-collector-key \--namespace plutus-collector \--from-literal=api-key=<the key shown above>helm install plutus-collector oci://ghcr.io/plutus-cloud/charts/plutus-collector \--namespace plutus-collector --create-namespace \--set clusterName=<your-cluster-name> \--set currency=<ISO-4217-code> \--set existingSecret=plutus-collector-key -
Once the agent’s first push succeeds, the connection panel in Plutus shows Receiving data with the last push time. If it still shows “No data received yet” after a few minutes, check the agent’s pod logs (structured JSON, one line per push cycle) for the error, or its
/metricsendpoint’splutus_collector_last_push_successvalue.
Kubernetes costs are an allocation of spend you are already paying your cloud provider, so they are shown as a breakdown by namespace and workload and deliberately do not add to your account total — that money is already counted under AWS, GCP or Azure. Figures come from OpenCost’s own pricing, which does not account for negotiated discounts, committed-use discounts or savings plans, so they read high against a discounted bill. Unallocated and idle cluster capacity is shown rather than hidden.