k13d

module
v1.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 24, 2026 License: MIT

README

k13d

The all-in-one Kubernetes dashboard for terminal and browser, with AI built in.

kubeaidashboard = k+ 13 letters + d = k13d

One binary, one command.
Get a full Kubernetes dashboard in TUI or Web UI, plus an AI assistant that can actually take action.

Release Go K8s License AI

Official Docs · Download · Web UI Guide · TUI Guide · 한국어


[!WARNING] Current support status k13d currently supports and recommends local single-binary usage for the TUI and Web UI. Docker, Docker Compose, Kubernetes, Helm, and other containerized/in-cluster deployment paths are still Beta / in preparation and are not officially supported yet. There is also no official public Docker image repository for end users at this time, so the deployment docs should be treated as roadmap/reference material, not a supported install path.

Web UI

Web UI Dashboard

TUI

TUI Dashboard


Get Started in 30 Seconds

1. Download from Releases — single binary, no dependencies.

tar xzf k13d_*.tar.gz && chmod +x k13d

macOS: if blocked, run xattr -d com.apple.quarantine ./k13d

2. Run.

TUI mode — terminal dashboard with Vim navigation + AI panel
./k13d

Opens a full-featured terminal dashboard. Use j/k to navigate, Enter or to open related resources, Ctrl+E to toggle the AI panel, Alt+F to temporarily expand the AI panel to full size, and Enter on a selected row while the AI panel is open to attach that row as AI context.

Web UI mode — browser dashboard (local / desktop)
./k13d --web --auth-mode local
# Open http://localhost:8080 — Username: admin / Password: printed in terminal

The Web UI is responsive on smaller screens and now renders Kubernetes lists with a stale-first dashboard flow, so recently viewed data appears immediately while fresh data is revalidated in the background.

--auth-mode local uses simple username/password authentication stored in memory — ideal for local development and desktop use. No Kubernetes tokens or external auth providers required. Just start and log in.

If --admin-user and --admin-password are not specified, the username defaults to admin and a secure random password is generated and printed to the terminal on startup. You can also set credentials via environment variables: K13D_USERNAME and K13D_PASSWORD.

CLI REPL mode — interactive shell
./k13d --cli

Opens an interactive command-line REPL for Kubernetes resource management with AI assistance. Useful for scripting and quick queries without the full TUI or Web UI.

Both modes — Web UI + TUI simultaneously
./k13d --web --auth-mode local &   # Web UI in background
./k13d                            # TUI in foreground

Run the Web UI as a background process, then launch the TUI in the foreground. Both share the same kubeconfig.

You can also run the CLI REPL mode alongside either interface:

./k13d --web --auth-mode local &   # Web UI in background
./k13d --cli                       # CLI REPL in foreground
Authentication Modes
Mode Flag Status / Use Case
Local --auth-mode local Supported. Recommended for local desktop Web UI use
Token --auth-mode token Preview only. Deployment-oriented path is not officially supported yet
LDAP --auth-mode ldap Preview only. Provider wiring is still incomplete
OIDC --auth-mode oidc Preview only. Provider wiring is still incomplete
No Auth --no-auth Development/testing only (not recommended)

--auth-mode ldap and --auth-mode oidc select those login paths, but the current stock binary does not yet expose every provider-specific LDAP/OIDC field as dedicated CLI flags. The Web UI auth settings page currently shows runtime status rather than persisting provider config.

If you're evaluating k13d today, focus on:

Flags
Flag Description
--web Start Web UI server (default port 8080)
--tui Start TUI mode explicitly (default when --web is not specified)
--cli Start CLI REPL mode (interactive shell)
--mcp Start MCP server mode (stdio transport)
--port <N> Custom port for Web UI
--config <path> Use a non-default config.yaml path
--auth-mode <mode> Auth mode: local, token, ldap, oidc
--admin-user <name> Admin username for local auth (env: K13D_USERNAME)
--admin-password <pw> Admin password for local auth (env: K13D_PASSWORD)
--no-auth Disable auth (dev only)
-n <namespace> Start in a specific namespace
-A Start with all namespaces
--version Show version information
--completion <shell> Generate shell completion (bash, zsh, fish)
--storage-info Show storage configuration and data locations
--db-path <path> Custom SQLite database path
--no-db Disable database persistence entirely
--experimental Enable experimental features (unstable, subject to change)

That's it. Your kubeconfig is auto-detected.

Configuration

k13d stores config.yaml in the platform config directory by default and creates it on the first successful save from Web UI, TUI, or any internal Save() path.

Platform Default config path
Linux ${XDG_CONFIG_HOME:-~/.config}/k13d/config.yaml
macOS ~/.config/k13d/config.yaml
Windows %AppData%\\k13d\\config.yaml

For configuration details, model profiles, storage paths, and example config.yaml files, use the official docs:


Why k13d?

k13d k9s Lens kubectl
Terminal UI Yes Yes - -
Web UI Yes - Yes -
CLI REPL Yes - - Yes
AI Assistant Yes - - -
Single binary, zero deps Yes Yes - Yes
Free & open source Yes Yes Paid Yes

Web UI — Everything in the browser

  • Dashboard — Pods, Deployments, Services, all resources with real-time status
  • AI Assistant — Ask questions, AI executes kubectl with explicit approval by default The default agentic toolset is kubectl-first. bash and MCP tools are opt-in, and unsupported interactive kubectl flows are hard-blocked instead of sent to approval.
  • GitHub Issue Automation — Receive GitHub issue webhooks, run an agent-driven dev command in an isolated worktree, optionally create a PR and attach an automated review
  • Topology — Graph & tree visualization of resource relationships
  • Reports — Cluster health, node checks, security audit, heuristic FinOps cost analysis
  • Metrics — Historical CPU/Memory/Pods/Nodes charts (SQLite-backed, 7-day retention)
  • Helm — Release management, history, rollback
  • Terminal — Full xterm.js shell into any pod
  • Logs — Real-time streaming with ANSI colors, search, download
  • Jobs & CronJobs — Local-time next run, last run, and recent execution history
  • Workload Security Context — Seccomp, non-root, token mount, host access, and privileged container checks
  • RBAC Viewer — Subject-to-role relationship map with permission details
  • Network Policy Map — Ingress/egress rule visualization
  • Event Timeline — Cluster events grouped by time windows
  • Security Scanning — Trivy CVE scanner with air-gapped support
  • Resource Templates — One-click deploy (Nginx, Redis, PostgreSQL, etc.)
  • Notifications — Slack, Discord, Teams, Email (SMTP) alerts for cluster events
  • Applications View — App-centric grouping by Helm and K8s labels
  • Validate View — Cross-resource validation with severity levels
  • GitOps Integration — ArgoCD and Flux application sync status, source repos, and revisions
  • Velero Backup Management — Backup and schedule status, expiration, and storage location
  • Access Requests — Teleport-inspired workflow for requesting elevated permissions with approval lifecycle
  • Multi-Cluster Context Switching — List kubeconfig contexts and switch between clusters
  • Port Forwarding — Start, list, and stop port-forward sessions from the browser
  • Auto-Healing Rules — Define remediation rules for crashloop, OOM, pending, or high restart conditions
  • XRay Resource Explorer — Tree-view hierarchy for Deployments, StatefulSets, Jobs, CronJobs, and DaemonSets
  • Resource Diff — Compare live resource YAML against last-applied configuration to surface drift
  • Cluster Pulse — JSON snapshot of cluster health with pod/deploy/node counts, CPU/mem usage, and recent events
  • Cost Estimation — Heuristic FinOps analysis with per-workload efficiency scores and optimization recommendations
  • Context-aware Themes — 5 built-in themes with auto-switching per Kubernetes context
    • Default (Dracula) — Dark theme for long sessions
    • Ollama — Minimalist paper-white theme (Ollama design system)
    • Production — Red alert theme for production safety
    • Staging — Orange caution theme
    • Development — Green safe theme

TUI — k9s on steroids

  • Vim navigationj/k, g/G, / filter, : commands
  • AI panelTab to chat, AI executes commands for you
  • Cluster Briefing — Toggleable natural-language health summary with 0-100 score and alerts
  • Node insights:nodes shows control-plane/worker role plus CPU, memory, and GPU usage bars
  • SortShift+N name, Shift+A age, Shift+T status, :sort picker
  • Autocomplete — Dropdown suggestions as you type
  • Aliases — Custom shortcuts (pp -> pods) via aliases.yaml
  • Plugins — External tool integration via plugins.yaml
  • Hotkeys — Custom keyboard shortcuts via hotkeys.yaml
  • Model switching:model to switch saved AI model profiles at runtime
  • i18n — English, Korean, Chinese, Japanese

AI Setup (Optional)

Configure in Settings > AI in the Web UI, or via environment:

# OpenAI
export K13D_LLM_PROVIDER=openai
export K13D_LLM_MODEL=gpt-4o
export K13D_LLM_API_KEY=sk-...
./k13d --web --auth-mode local

# Anthropic
export K13D_LLM_PROVIDER=anthropic
export K13D_LLM_MODEL=claude-sonnet-4-6
export K13D_LLM_ENDPOINT=https://api.anthropic.com
export K13D_LLM_API_KEY=sk-ant-...
./k13d --web --auth-mode local

# Ollama (local, free, no API key)
ollama pull gpt-oss:20b && ollama serve
./k13d --web --auth-mode local
# Set Provider: "ollama" in Settings > AI

For Ollama, choose a model that explicitly supports tools/function calling. Some Ollama models can connect and generate text, but k13d's AI Assistant will not work correctly unless the model supports tools. gpt-oss:20b is the recommended default.

Embedded LLM support has been removed. For local/private inference, use Ollama instead.

Model profiles, provider-specific examples, and config ownership are documented in:

Supported AI Providers

Provider Models Notes
OpenAI GPT-4o, GPT-4, o3-mini Best tool calling support
Anthropic Claude Sonnet 4.6, Opus 4.6, Haiku 4.5 Native Messages API, strong reasoning
Google Gemini Gemini 2.5, 2.0 Multimodal capable
Upstage Solar Solar Pro2, Solar Pro Good balance of quality/cost
Azure OpenAI GPT-4, GPT-3.5 Enterprise Azure deployments
AWS Bedrock Claude, Llama, Mistral AWS-hosted models
Ollama GPT-OSS, Qwen, Llama, Mistral Local, free, no API key, choose a tools-capable model

The AI assistant can:

  • Diagnose pod crashes and suggest fixes
  • Execute kubectl commands with your approval
  • Keep read-only kubectl get style actions behind Decision Required unless you explicitly enable auto-approve
  • Prefer kubectl over bash; shell access is treated as a last resort
  • Expose bash and MCP tools only when you explicitly enable them in config.yaml
  • Hard-block unsupported interactive flows such as kubectl edit, kubectl port-forward, and kubectl exec -it

GitHub Issue Automation

k13d can also act as a lightweight GitHub issue autopilot. When GitHub sends an issues webhook to the Web server, k13d can:

  • gate execution by label, by default codex:auto
  • guide humans through a friendly Codex 개발 요청 Issue Form before automation starts
  • create or reuse one stable issue branch and worktree, for example codex/issue-123
  • run your configured development command
  • wait for GitHub checks on the pushed branch
  • optionally run a separate review command
  • auto-commit, auto-push, and create or reuse exactly one draft PR for that issue branch
  • assign the issue author and request organization members as PR reviewers
  • deploy a branch preview behind the same domain, for example /previews/codex-issue-123/
  • post an issue comment and PR review when a GitHub token is configured

This is designed for local or self-hosted operation. If you run k13d directly on a public HTTPS endpoint, GitHub can reach it without extra relay infrastructure:

https://your-domain.example/api/github/automation/webhook

Example config.yaml section:

github_automation:
  enabled: true
  webhook_secret: ${K13D_GITHUB_AUTOMATION_WEBHOOK_SECRET}
  personal_access_token: ${GITHUB_TOKEN}
  allowed_repositories:
    - cloudbro-kube-ai/k13d
  require_author_org_member: true
  mention_org_members: true
  mention_max_members: 20
  review_language: ko
  trigger_label: codex:auto
  repo_path: /absolute/path/to/k13d
  worktree_root: ~/.cache/k13d/github-automation
  development_command: ./scripts/run-agent-dev.sh
  review_command: ./scripts/run-agent-review.sh
  wait_for_ci: true
  allow_issue_merge: true
  merge_method: squash
  auto_deploy_preview: true
  deploy_preview_command: ./scripts/deploy-preview.sh
  preview_url_base: https://fingerscore.net
  preview_path_prefix: /previews

The development, review, and preview deployment commands are fully configurable so you can wire in Codex, Claude Code, Gemini CLI, or your own wrapper scripts. The included scripts/run-agent-review.sh wrapper runs codex exec review and emits a Korean PR review summary. By default, k13d comments and PR reviews in Korean, mentions organization members when a trusted issue is accepted, assigns the issue author, requests organization members as PR reviewers, and includes the branch preview link after deployment succeeds. One issue maps to one stable branch and one open PR, so re-labeling or reopening the issue continues on the same branch. Organization members can comment k13d 코드리뷰 해줘 on the issue to re-run the configured review command, and if allow_issue_merge is enabled they can comment k13d merge 해줘 to merge the linked PR into the base branch after human preview verification. After a successful issue-requested merge, k13d closes the GitHub issue as completed. k13d never forwards GitHub token env vars to development/review/deploy commands and redacts GitHub token patterns from captured output. A local preview command can start the built branch on a localhost port and print K13D_PREVIEW_TARGET=http://127.0.0.1:<port>. k13d then exposes it through the main Web server as https://fingerscore.net/previews/<branch-slug>/, which keeps preview access on a single public URL.

For the full config reference, placeholders, environment variables, and webhook flow, see:

If you use config.yaml, the safest default is:

llm:
  enable_bash_tool: false
  enable_mcp_tools: false

MCP (Model Context Protocol)

k13d supports MCP for extending AI capabilities with external tools. Run k13d as an MCP client (connects to external MCP servers) or as an MCP server (exposes k13d tools to other AI systems).

# Run as MCP server (stdio transport)
./k13d --mcp

Configure MCP servers in your active config.yaml:

mcp:
  servers:
    - name: kubernetes
      command: npx
      args: ["-y", "@anthropic/mcp-server-kubernetes"]
    - name: thinking
      command: npx
      args: ["-y", "@modelcontextprotocol/server-sequential-thinking"]

See the MCP Guide for details.


CLI Reference

./k13d                                    # TUI mode
./k13d --web --auth-mode local           # Web UI — local auth (desktop use)
./k13d --web --auth-mode token           # Web UI — token auth path (preview only)
./k13d --web --port 3000                 # Custom port
./k13d --web --no-auth                   # No auth (dev only)
./k13d --cli                             # CLI REPL mode (interactive shell)
./k13d --mcp                             # MCP server mode
./k13d -n kube-system                    # Start in specific namespace
./k13d -A                                # Start with all namespaces
./k13d --version                         # Show version
./k13d --completion bash                 # Generate shell completion
./k13d --storage-info                    # Show storage configuration

Shell Completion

# Bash
source <(./k13d --completion bash)

# Zsh
source <(./k13d --completion zsh)

# Fish
./k13d --completion fish | source

Deployment Status

Docker, Docker Compose, Kubernetes, and Helm packaging are still Beta / in preparation.

  • No official public Docker image repository is available yet
  • The deployment files in this repository are roadmap/reference material for upcoming work
  • The supported experience today is the local TUI and local Web UI

Build from Source

git clone https://github.com/cloudbro-kube-ai/k13d.git && cd k13d
make build

Documentation


License

MIT License - see LICENSE.

GitHub Stars

Directories

Path Synopsis
cmd
bench command
Package main provides the CLI for running AI benchmarks
Package main provides the CLI for running AI benchmarks
eval command
Package main provides the CLI for running LLM evaluation benchmarks.
Package main provides the CLI for running LLM evaluation benchmarks.
kubectl-k13d command
kubectl-k13d is a kubectl plugin wrapper for k13d.
kubectl-k13d is a kubectl plugin wrapper for k13d.
internal
cli
Package cli contains shared startup logic for k13d entry points.
Package cli contains shared startup logic for k13d entry points.
pkg
ai
ai/agent
Package agent provides a state-machine based AI agent following kubectl-ai patterns.
Package agent provides a state-machine based AI agent following kubectl-ai patterns.
ai/safety
Package safety provides command safety analysis using shell AST parsing.
Package safety provides command safety analysis using shell AST parsing.
ai/session
Package session provides AI conversation session persistence backed by SQLite
Package session provides AI conversation session persistence backed by SQLite
ai/sessions
Package sessions provides the original session management system.
Package sessions provides the original session management system.
bench
Package bench provides AI benchmarking capabilities for Kubernetes tasks.
Package bench provides AI benchmarking capabilities for Kubernetes tasks.
bench/cluster
Package cluster provides cluster provisioning for benchmarks
Package cluster provides cluster provisioning for benchmarks
cli
db
eval
Package eval provides AI agent benchmark evaluation framework dryrun.go implements cluster-free benchmark evaluation using tool call analysis
Package eval provides AI agent benchmark evaluation framework dryrun.go implements cluster-free benchmark evaluation using tool call analysis
k8s
log
mcp
metrics
Package metrics provides periodic metrics collection for time-series data
Package metrics provides periodic metrics collection for time-series data
security
Package security provides security scanning and compliance checking for Kubernetes clusters
Package security provides security scanning and compliance checking for Kubernetes clusters
testutil
Package testutil provides shared testing utilities and interface contracts.
Package testutil provides shared testing utilities and interface contracts.
ui
Package ui provides the terminal user interface components.
Package ui provides the terminal user interface components.
ui/actions
Package actions provides a centralized key action system following k9s patterns.
Package actions provides a centralized key action system following k9s patterns.
ui/models
Package models provides data models for the TUI following k9s patterns.
Package models provides data models for the TUI following k9s patterns.
ui/render
Package render provides resource rendering following k9s patterns.
Package render provides resource rendering following k9s patterns.
ui/resources
Package resources provides resource view generators for the TUI dashboard.
Package resources provides resource view generators for the TUI dashboard.
ui/views
Package views provides high-level view components following k9s patterns.
Package views provides high-level view components following k9s patterns.
web
tests
mocks command
Mock OpenAI API Server for Integration Testing Simulates OpenAI API responses for testing k13d without real API calls
Mock OpenAI API Server for Integration Testing Simulates OpenAI API responses for testing k13d without real API calls

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL