Read-only Kubernetes viewer

Your cluster as a
living city.

KubeYard draws your Kubernetes cluster as a small city. Every namespace gets a plot, every workload a building and every pod a machine. Requests, restarts and failures show up as they happen. It only reads from the cluster, so it can't break anything.

Live demo, running right now

Early beta. If you find a bug, please write to info@lixsl.net.

Read the city

Each part of the city stands for something in your cluster. This is what it all means.

PlotA namespace. Older namespaces sit close to the harbor, new ones are added at the edge.
HallA workload. Each kind has its own building, so a Deployment looks different from a StatefulSet or a CronJob.
MachineA pod, standing in front of its hall. The lamp shows the pod state and it works faster when the pod uses more CPU.
BoxRequests. Good ones are picked up by trucks at the loader, failed ones end up in the scrap bin.
Power plantA node, next to the river. Click it to see a cable to every pod that runs on it.
Smoke and fireHealth. Smoke means a workload is degraded, fire means none of its pods are ready.
DroneAn image pull. It flies in from the harbor and lands when the image is pulled.
HarborEverything outside the cluster. All trucks start and end their trip here.
Halls and machines

Halls and machines

Every workload has a hall, with one machine per pod in front of it. The machines produce boxes at the real request rate. A forklift brings them to the loader and trucks take them away. If a service can't keep up, the pile of boxes grows.

Trouble you can see

Trouble you can see

When a workload has no ready pod, its hall catches fire and the machines blink red. The side panel tells you why and shows where a rollout is stuck. A fire truck also drives over.

Kiosk mode for the wall

Kiosk mode for the wall

Made for a screen on the wall. The panels are hidden and the camera flies over the city by itself. When something breaks it goes there, other problems show up in small windows, and a news bar at the bottom lists what happened.

Your city, your look

Your city, your look

Pick a light or dark theme, and blue halls or one color per namespace. The city can also follow your local time, with street lights at night.

Power cables

Power cables

Nodes are power plants next to the river. Click one and you see which pods run on it.

One namespace at a time

One namespace at a time

Select a namespace and everything else is hidden. You only see its plot and its traffic.

Read only, by design

KubeYard only reads from your cluster. Four separate checks make sure it stays that way.

RBACThe service account can only get, list and watch. It has no access to secrets, configmaps, logs, exec or proxy.
Self checkOn startup KubeYard checks its own permissions and does not start if it is allowed to write anything.
Request guardEvery call to the API goes through a filter that only allows GET requests on the paths KubeYard needs.
Hardened podRuns as non-root with a read-only file system, no capabilities, a default-deny network policy and the lowest priority.

Up in a minute

KubeYard runs as a single small pod and installs with Helm. You can also run it on your laptop with a short-lived read-only token.

# in the cluster
kubectl create namespace kubeyard
kubectl label namespace kubeyard pod-security.kubernetes.io/enforce=restricted
helm install kubeyard oci://registry-1.docker.io/lixsl/kubeyard-chart -n kubeyard
kubectl -n kubeyard port-forward svc/kubeyard 8011:80