Skip to main content
KubeStacks runs in a cluster as a dashboard for that cluster. It’s the same app as the desktop one, in a browser: people open its address, sign in, and see and change what their own Kubernetes permissions allow. Nobody installs anything, and a link to any page (a pod, its logs, a Helm release) can be shared.
KubeStacks in a browser, showing a cluster's overview, with the account menu open: who is signed in, and their groups.KubeStacks in a browser, showing a cluster's overview, with the account menu open: who is signed in, and their groups.

KubeStacks served from a cluster, with the menu of who's signed in open.

Install it

One Helm chart, then a port-forward or an ingress. A few minutes.

Joining a team that runs it?

Nothing to install. Here’s how signing in works.

How it works

KubeStacks runs as one pod with a Service in front of it. Each page in a browser keeps one WebSocket open to it, and KubeStacks makes every request to the API server as the person who signed in, so the API server applies their RBAC. KubeStacks never gives anyone more than their own permissions. It reaches the API server as that person in one of two ways:
  • With their own token. Their requests carry a token the cluster checks itself. KubeStacks’ service account needs no permissions at all.
  • By impersonating them. KubeStacks sends its service account’s credentials with Impersonate-User and Impersonate-Group headers. The API server checks that the service account may impersonate, then applies the person’s RBAC.
Which one depends on how people sign in.

Ways to sign in

When people’s own tokens reach the cluster, its audit log names them directly. When KubeStacks impersonates them, the audit log records KubeStacks’ service account acting as them. The chart grants the impersonation permission only in the modes that need it.
Signing in with a token needs Kubernetes 1.28 or later: KubeStacks asks the cluster whose token it is with a SelfSubjectReview. Single sign-on and the proxy work from Kubernetes 1.25, like the rest of KubeStacks.

What’s different from the desktop app

It shows the cluster it runs in. There’s no list of clusters to switch between.
There’s no computer of the user’s to forward a port to, so Forward a port… isn’t offered. See Port forwarding for the desktop app.
Never from files on anyone’s computer. KubeStacks fetches charts only from public addresses unless helm.allowPrivateCharts allows private ones, such as a ChartMuseum or Harbor in your network. Otherwise anyone signed in could make it reach services inside the cluster’s network. See Security.
The theme, whether the cluster is read-only for you, and where your usage history comes from are kept in your browser. Each person can make KubeStacks read-only for themselves; readOnly: true makes it read-only for everyone.
The server doesn’t update itself. See Upgrade.
Keyboard shortcuts are the same, except ⌘N and ⌘1…⌘6 (Ctrl on Windows and Linux), which browsers keep for themselves. The command palette (⌘K) has those commands. See Keyboard shortcuts.

Pages you can share

In a browser, every page has a real address: a list with its filters and sort order, an object’s detail panel, a Helm release. Copy the address bar and send it. Whoever opens it signs in, then lands on the same page, seeing what their own permissions allow.

The image

Imageghcr.io/kubestacks/kubestacks
Platformslinux/amd64, linux/arm64
Runs asNon-root, no shell
Writes to/tmp only
The image has Node.js, helm and KubeStacks, and nothing else. Each release is signed with a build provenance attestation, which the GitHub CLI checks:
The Helm chart is oci://ghcr.io/kubestacks/charts/kubestacks. It’s released with KubeStacks itself, so the chart’s version is the app’s.

Requirements

  • Kubernetes 1.25 or later, and 1.28 or later to sign in with tokens.
  • Helm, to install the chart. Helm 3.8 and later read charts from OCI registries.
  • An ingress controller, if you want KubeStacks at an address of its own. A kubectl port-forward is enough to try it.

Install it

Helm install, open it, sign in.

Security

What KubeStacks can do, and how to keep it contained.