Slack (App)
Connect your Slack workspace once with a Slack App bot token, then send alerts to any channel from a dropdown — no incoming webhook per channel. This is the recommended way to alert into multiple Slack channels.
note: Each customer creates their own Slack app in their own workspace (KubeSense is self-hosted, so there is no shared app to install). The bot token is stored encrypted at rest and is never shown to clients — see Encryption & key rotation.
1. Create a Slack app
- Go to https://api.slack.com/apps → Create New App → From scratch.
- Name it (e.g.
KubeSense) and select your workspace.
2. Add bot scopes
Under OAuth & Permissions → Scopes → Bot Token Scopes, add:
| Scope | Why |
|---|---|
chat:write | Post alert messages |
channels:read | List public channels in the picker |
groups:read | List private channels in the picker |
chat:write.public | (optional) post to public channels without inviting the bot |
note: channels:read and groups:read are both needed — Slack rejects the whole channel-list call for a missing scope, so without groups:read the picker comes back empty.
3. Install & copy the token
- Click Install to Workspace and authorize.
- Copy the Bot User OAuth Token — it starts with
xoxb-.
4. Connect in KubeSense
- Alerts → Notification Channels → New (or Settings → Notification Channels).
- Type = Slack (App) → paste the
xoxb-token → Connect. KubeSense validates it and remembers the workspace (you only do this once).
5. Add a channel & test
- Pick the target Slack channel from the dropdown, name the channel, Save.
- Invite the bot to that channel in Slack (
/invite @KubeSense) — or use a public channel withchat:write.public. Anot_in_channelerror means the bot isn't in the channel. - Click Test to confirm a message arrives.
Repeat step 5 for any other channel — you won't paste the token again.
Large workspaces
Slack has no channel-search API, so KubeSense lists channels by walking
conversations.list. On a very large workspace a full walk would exceed the
request timeout, so the walk stops at a time budget and the picker shows a notice
when public channels were cut short. Workspaces of a few thousand channels
list in full; only beyond that does the notice normally appear.
Private channels are always listed in full. They are fetched separately, which is cheap because Slack only reveals the private channels the bot was invited to — a handful, however large the workspace. This matters because the two cases are not equally recoverable:
| Channel | If it isn't listed |
|---|---|
| Public | Type its exact name and choose the Use "#your-channel" entry — Slack resolves a name for public channels, so no lookup is needed. |
| Private | Run /invite @KubeSense in that channel, then reopen the picker — it will be there. |
Then press Test to confirm: a wrong name reports "Channel not found — check the channel name."
warning: Typing a name works for public channels only — Slack cannot resolve a private channel by name. That is why inviting the bot (not typing) is the path for a private channel. If you already have its ID (Slack: channel name → About → copy the ID at the bottom), you can paste that instead; an ID works for both.
Administrators can widen the listed batch with these API env vars (all optional):
| Variable | Default | Effect |
|---|---|---|
KUBESENSE_SLACK_PAGE_SIZE | 200 | Channels requested per Slack call (max 999) |
KUBESENSE_SLACK_MAX_PAGES | 50 | Backstop on the number of calls |
KUBESENSE_SLACK_LIST_BUDGET_MS | 5000 | Wall-clock budget for the whole walk |
Whichever limit is reached first ends the walk. In practice the budget is the one that ends it: Slack returns far fewer channels per call than requested (~50 is typical), so the page count is a poor proxy for elapsed time and is set high enough not to interfere. Raise the budget if a large workspace is being cut short — raising the page count alone won't help.
Reconnecting
If the picker shows "This Slack workspace needs to be reconnected" (the stored
token can't be decrypted — the KUBECOL_CONFIG_KEK changed, or the workspace was
connected on a different instance), click Reconnect on the channel and paste the
bot token again. See Encryption & key rotation.
Custom templates
Slack (App) supports message templates: Settings → Alert Templates → New → Slack
(App) with a Title and a Body (Slack mrkdwn), preview it, then select it on
the channel. The body renders through KubeSense's template engine
({{ range .Alerts }}…, severity/value/threshold fields, log samples) and drives the
message body; leave it unset to use the built-in layout. See
Templates.