Read-only Kubernetes viewer

Your cluster as a
living city.

Namespaces are plots, workloads are halls, pods are the machines in front of them. Requests leave as boxes on trucks, failing pods smoke and burn. You see what happens, at a glance, and KubeYard can never change a thing.

Live: this city is simulated right now

Read the city

Every thing in the city is something in the cluster, and everything that moves is something that happens.

PlotA namespace. The oldest ones sit next to the harbor, new ones grow at the edge.
HallA workload. Factories, data works, relay stations, clock towers: every kind has its own.
MachineA pod, in front of its hall. Its lamp is the pod state, it works as hard as its CPU.
BoxRequests. Green ones go to the loader and onto a truck, failed ones into the scrap bin.
Power plantA node, by the river. Steam follows CPU; click it for a cable to every pod it runs.
Smoke and fireHealth. Dark smoke when a workload is degraded, fire when it is critical.
DroneAn image pull, flying in from the harbor and landing when the pull is done.
HarborThe world outside the cluster. Every truck starts and ends here.
Halls and machines

Halls and machines

One hall per workload, one machine per pod in front of it. The machines make boxes at the real request rate; the forklift takes them to the loader, where the ingress is, and trucks take them away. Under overload the stack grows.

Trouble you can see

Trouble you can see

A workload without a ready pod burns and its machines blink red. The card says why, the rollout tracker shows where it is stuck, and a fire truck is on its way.

Kiosk mode for the wall

Kiosk mode for the wall

Full screen, no panels. The camera flies over the city like a helicopter, hovers over what is broken, shows other problems in small live views and runs the news along the bottom.

Your city, your look

Your city, your look

Halls in blue or in one color per namespace, light or dark theme. The city can follow the clock: dusk, glowing windows and street lamps at night.

Power cables

Power cables

Nodes are power plants by the river. Select one and a cable runs to every pod on it.

One namespace at a time

One namespace at a time

Pick a namespace and the rest of the city makes room for forest. Only its plot and its traffic stay.

Read only, by design

Whatever happens inside KubeYard, nothing can happen to your cluster. Four layers make sure of it.

RBACThe account may only get, list and watch. No secrets, configmaps, logs, exec or proxy.
Self checkAt start KubeYard asks the API server what it may do, and refuses to run if it could write anything.
Request guardEvery request passes a guard that lets only GET on the exact paths it needs through.
Hardened podNon-root, read-only file system, no capabilities, default-deny network policy, lowest priority.

Up in a minute

One small pod, one Helm chart. Or run it on your laptop with a short-lived read-only token.

# in the cluster
kubectl create namespace kubeyard
kubectl label namespace kubeyard pod-security.kubernetes.io/enforce=restricted
helm install kubeyard oci://git.lixsl.net/lixsl/charts/kubeyard -n kubeyard
kubectl -n kubeyard port-forward svc/kubeyard 8011:80