What it connects to
TelemetryNone
AccountsNone
CredentialsStay on your computer
LicenseApache 2.0
- The clusters in your kubeconfig, with the credentials in it.
- The Prometheus or VictoriaMetrics you use for usage history, reached through the cluster’s API server with your own credentials. Nothing is port-forwarded or exposed for it.
- Artifact Hub, only when you search it for a chart to install.
- The chart repositories and registries you choose, when you upgrade or install a Helm release from one.
- GitHub, to look for new versions of KubeStacks. Help → Check for Updates Automatically turns that off.
Your credentials
Kubeconfig credentials stay in the app’s main process: tokens, client keys and the output of credential plugins. The page you see never has them. Every request to a cluster is made by the main process, after it checks what the page asked for. KubeStacks reads your kubeconfig and never changes it. Managing kubeconfig files, like adding contexts or signing in to a cloud provider, is left to the tools made for it.How the app is built
- The page is sandboxed. It runs with context isolation, no Node.js integration and a strict Content Security Policy. It can’t navigate away or open new windows.
- Every request is checked. The main process only answers calls from the app’s own page, and validates every argument.
- Changes go through a small set of operations. Each is checked against what you’ve made read-only, and refused for those clusters, or for all of them with
KUBESTACKS_READ_ONLY. See Read-only mode. - Links are limited. Only
https://links, andhttp://localhost:<port>for your own port forwards, are handed to the operating system. - Updates are verified. New versions come from the project’s GitHub releases over HTTPS. Each download is checked against the SHA-512 checksum the release lists, and on macOS the new version must carry the same Developer ID signature.
Secrets on screen
KubeStacks is careful with what it shows:- Lists of Secrets carry only the names of their keys. Values are blanked before they reach the page.
- Values stay hidden until you reveal them. An open Secret shows each key with its size, and
••••••••for its value. Reveal one key, or all of them, when you need to. Copying a value works without revealing it. - The YAML is hidden too. The YAML tab hides values until you choose Reveal values, and so does the
last-applied-configurationannotation, which holds a copy of them.