Skip to main content
KubeStacks is open source under the Apache 2.0 license, on GitHub. It’s written in TypeScript: an Electron app with a React interface, and a small Node.js server for running it in a cluster.

Build the app

You need Node.js 24 or later (the repository’s .nvmrc asks for 26) and npm.
1

Get the code

2

Build the installers

The installers for your platform land in release/: a .dmg and .zip on macOS, an .exe on Windows, and an AppImage, .deb and .rpm on Linux. npm run package builds an unpacked app there instead, which is quicker.
A copy you build yourself isn’t signed or notarized. For everyday use, the official releases are signed on macOS, come with checksums and provenance, and keep themselves up to date.

Run it while you work on it

dev and dev:mock reload as you change the code. The demo clusters are the ones the tests use: a busy one with every kind of problem, an empty one without metrics, one with 2,500 pods, and contexts that fail in every way a real one can.
The app can change clusters. Try your work against the demo clusters or a local kind cluster, not production. KUBESTACKS_READ_ONLY=1 npm run dev keeps every cluster read-only.

Commands

How it’s built

src
main
backend
server
preload
renderer
shared
charts
tests
e2e
web
mock-cluster
mock-oidc
integration
docs
scripts
A few ideas hold it together:
  • One page, two hosts. The interface talks to its host through one typed API: over IPC in the desktop app, over a WebSocket when served. Both answer from the same handlers. What only one can do, like port forwards on the desktop or sessions on the server, is an optional part of that API, which the page shows only when it’s there.
  • Credentials never reach the page. It runs sandboxed, with context isolation, no Node.js access and a strict Content Security Policy. Every IPC call is checked for its sender and validated in the main process, the only place that talks to clusters. See Privacy and security.
  • Plain REST. Authentication comes from @kubernetes/client-node, and requests are plain REST calls with gzip, so any API path, metrics and logs included, works the same way.
  • Status colors are for health. They always come with an icon and a label, and charts use a palette checked for color blindness in both themes.

Tests

KubeStacks keeps 100% end-to-end coverage of statements, branches, functions and lines, enforced in CI.
  • End-to-end tests drive the real Electron app with Playwright, against a mock API server with the demo clusters. Coverage is collected from all three Electron processes, the server and the page, and merged across Linux, macOS and Windows. The test windows stay invisible and never take focus, so you can keep working; set KUBESTACKS_E2E_FOREGROUND=1 to watch them.
  • Web tests start the server against the same mock clusters and a mock OpenID Connect provider, and drive the page in Chromium: every way of signing in, sessions ending, the WebSocket dropping and coming back, shells, logs and Helm.
  • Integration tests check the same app against a real three-node kind cluster with metrics-server and kube-prometheus-stack. They change things for real and check the result with kubectl. They need Docker, kind, kubectl and Helm:
    The cluster gets its own kubeconfig in .kind/. Your ~/.kube/config isn’t read or changed.

Contributing

Bug reports, ideas and pull requests are welcome. The contributing guide has the details; in short:
1

Agree on the approach

For anything bigger than a small fix, open an issue first. KubeStacks is for looking after workloads, clusters and Helm releases; managing kubeconfig files is out of scope.
2

Make a focused change

Branch from main, and match the style of the code around it: TypeScript in strict mode, Prettier and ESLint, and the design tokens for anything visual.
3

Test it like a user

Add or update end-to-end tests in tests/e2e/ (and tests/web/ for what’s different when served). Tests drive the real app through its interface. A new cluster state goes in the demo fixture, tests/mock-cluster/fixtures/, when it’s realistic.
4

Check it

Run npm run verify. Screenshots help for interface changes: on a Mac, npm run screenshots -- overview pods takes those two, light and dark.
5

Open a pull request

Describe what changed and why.
A view for a popular project is a welcome first contribution. Add it to src/renderer/src/views, one file per project, with a comment linking to the project. KubeStacks checks every view it ships when it starts, and the tests fail if one has a problem.
Found a security problem? Please report it privately: see Reporting a vulnerability.