Skip to main content
KubeStacks also runs in a cluster, as a dashboard for that cluster. It’s the same app as the desktop one, in a browser: people open its address, sign in, and see and change what their own Kubernetes permissions allow. Nobody installs anything, and a link to any page (a pod, its logs, a release) can be shared.
KubeStacks served from a cluster: who's signed in, and their groups.KubeStacks served from a cluster: who's signed in, and their groups.

KubeStacks served from a cluster, with the menu of who's signed in open.

This page gets it running in a few minutes, signed in with a token. When you’re ready to share it, give it an address and single sign-on.

Before you start

  • A cluster running Kubernetes 1.28 or later, for signing in with a token.
  • Helm and kubectl on your computer, with access to install into a namespace.

Try it

1

Install the chart

The chart runs one KubeStacks pod. In the default token mode, its service account needs no permissions at all: everyone acts with their own.
2

Open it

Forward a port to it, and open http://localhost:8080.
3

Get a token to sign in with

KubeStacks asks for a bearer token the cluster accepts, and sends your requests with it. For a quick look, make a service account that can view everything, and a token for it that’s valid for an hour:
4

Sign in

Paste the token and choose Sign in. You’re on the cluster’s overview, with exactly the access the view role gives.
KubeStacks served from a cluster: signing in with a token.KubeStacks served from a cluster: signing in with a token.
KubeStacks never gives anyone more than their own permissions. Bind a role like edit instead of view, and the same page offers scaling, restarts and the rest.

Make it your team’s

Give it an address

Turn on the chart’s ingress, with TLS, so people open it at a URL of its own.

Single sign-on

Sign in with Okta, Entra ID, Google, Keycloak, Dex or any OpenID Connect provider.

Behind a proxy

Let oauth2-proxy or Pomerium sign people in, and pass on who they are.

Keep it safe

What to know about impersonation, sessions and read-only mode.

How it differs from the desktop app

It’s the same app, so nearly everything in these docs applies to both. Served from a cluster:
  • It shows one cluster, the one it runs in. There’s no list of clusters to switch between.
  • There’s no port forwarding, since there’s no computer of yours to forward a port to.
  • Charts come from repositories, registries or URLs, never from files on your computer.
  • Preferences belong to each browser: the theme, which clusters you’ve made read-only, and where usage history comes from.
  • A few shortcuts belong to the browser: ⌘N and ⌘1…6. The command palette (⌘K) has those commands.
Overview of KubeStacks in your cluster covers how it works, and every setting.