FAQ

Frequently asked questions

Everything you need to know about Kubexer — the desktop Kubernetes IDE. Can't find an answer? Reach us any time.

Kubexer is a modern desktop Kubernetes IDE. It lets you browse, manage, and debug every resource across your clusters from one fast native app — pods, deployments, services, ingresses, config, and more — with live logs, an interactive topology graph, security scanning, and monitoring built in.

It is built for the engineers who work with Kubernetes every day — platform and DevOps teams, backend and SRE engineers, and anyone who wants a faster, friendlier way to operate clusters than juggling kubectl tabs and YAML by hand.

Kubexer ships as a native desktop app for macOS (Apple Silicon) and Windows (x64). You can download the latest build straight from the Kubexer website. Sign in with your account to unlock Pro features after installing.

There's no separate signup step — you never fill out a registration form. The first time you log in (with an email login code or with Google), an account is created for you automatically, and every login after that signs you back into that same account. Just log in and you're ready to go.

Sign in with the same account on each device and your kubeconfigs follow you everywhere. Add or change a cluster on one machine and it becomes available on the others — so you set up your clusters once and connect from anywhere.

Yes. Kubeconfigs that Kubexer manages are encrypted on your device before they ever leave it and stored encrypted at rest. The encryption is tied to your account credentials, so your cluster credentials stay protected in transit and on disk.

Topology renders the resources in a namespace as an interactive graph — pods, services, ingresses, and the relationships between them — so you can see how everything connects at a glance instead of piecing it together from separate lists.

Kubexer scans your workload container images for known CVEs using Trivy, then lets you triage findings by severity — right from the pod or deployment you are inspecting. Scanning a Deployment covers all of its images.

Yes. The Compare Namespaces view diffs resources and capacity across namespaces side by side, so you can spot drift, missing configuration, and resource gaps before they cause problems.

Scoped kubeconfigs let you provision a least-privilege service account with the RBAC you choose, then download a ready-to-use kubeconfig to share access safely. You can revoke the access at any time, and the minted token is never persisted.

The Security Matrix aggregates all of your cluster RBAC — ServiceAccounts, users, groups, Roles, ClusterRoles, and their bindings — into a single grid so you can see who can do what, and where, at a glance. It offers two views: By Namespace (effective access per namespace, with a pinned cluster-wide column) and By Resource (effective access per resource kind like Pods, Secrets, or Deployments). Cells are color-coded by access level, flag subjects that can read Secrets or hold cluster-admin-like rules, and surface ServiceAccounts that have no RBAC at all. Click any cell to drill into the exact roles, bindings, and policy rules behind it. It is a read-only, on-demand snapshot derived from your bound roles and never changes anything in your cluster. Security Matrix is a Pro feature.

Yes. You can stream live logs across pods and containers with search, filtering, and a log histogram, exec an interactive shell into a container, and port-forward to reach a service locally — all from within the app.

While the desktop app is running it watches your workloads in the background and can notify you when pods, deployments, jobs, nodes, or events cross the conditions you define — delivered to desktop push and email.

The Free plan covers all the core Kubernetes management — browsing and managing every resource in your clusters, live logs and an exec shell into pods, the topology graph, port-forwarding, comparing namespaces, and more — at no cost. Pro adds the advanced, premium capabilities for power users on top of that. Teams is our seat-based plan for organizations: buy seats, assign members by email, and manage billing centrally.

Kubexer has a free tier for exploring and smaller clusters, plus a Pro plan that unlocks every feature, billed monthly or yearly. For organizations there are seat-based team subscriptions, so you can buy seats and assign them to teammates by email. See the pricing section on the home page for current rates.

Payments are processed securely through Stripe, so Kubexer never stores your card details. You can manage your subscription and cancel anytime from your account billing settings. When you cancel, you keep your paid features until the end of the billing period you have already paid for — there is no mid-period cutoff — and the subscription simply lapses after that.

Your account works across your machines with a per-product two-device limit, and a single active session at a time keeps your account secure. Your kubeconfigs sync between those devices automatically.

Kubexer is a desktop app that talks to your clusters directly using your own credentials. Your account is used for things like syncing your encrypted kubeconfigs and your settings — and managed kubeconfigs are encrypted before they leave your device. We designed it to keep your cluster access in your hands.

You can reach the team any time at support@kubexer.com. There is also an in-product help center and knowledge base with guides and feature docs to get you started.

Yes. Kubexer can spin up a local demo cluster with minikube in one click — it downloads the required tooling, starts the cluster, and configures the connection for you. It is the fastest way to explore every feature before pointing Kubexer at a real cluster.

Yes. When Kubexer detects Argo CD or Flux in your cluster it unlocks native, typed views for GitOps resources such as Applications, Kustomizations, and HelmReleases. You can follow each deployment's managed-resource tree and trigger sync, refresh, reconcile, or suspend directly from the app. GitOps is a Pro feature.

Yes. Kubexer auto-detects OpenShift clusters and adds first-class, typed views for OpenShift-specific resources — Routes, Projects, DeploymentConfigs, ImageStreams, BuildConfigs, Builds, and Security Context Constraints — alongside the standard Kubernetes resources.

Beyond listing releases, Kubexer visualizes all of the resources a release manages as an interactive graph, shows revision history and value diffs between revisions, and lets you upgrade or roll back releases with a clear preview of the outcome.

Kubexy is the AI assistant built into the Kubexer desktop app. Ask it about your cluster in plain English and it explains pod errors and crashes like CrashLoopBackOff, OOMKilled, and ImagePullBackOff, investigates namespace health, surfaces failing pods, checks requests and limits against live usage, and diagnoses scheduling, endpoint, and PVC issues. You can even export a conversation to PDF. Kubexy is a Pro feature.

Kubexy is bring-your-own-key (BYOK): you connect your own AI provider key, so you choose and pay for the model you use. It works with Anthropic, OpenAI, and Google, as well as any OpenAI-compatible endpoint such as Ollama, OpenRouter, or Azure. Pro unlocks the Kubexy feature; the AI usage costs are billed directly by your chosen provider.

Yes. Kubexy runs locally inside the desktop app. Your API key is stored encrypted on your device and is never sent to Kubexer's servers — it goes only to the AI provider you chose. Secret values are redacted before anything is sent to the model, so sensitive data stays protected.

Kubexy is a Pro feature, so a Pro subscription unlocks it. Because it is BYOK, you bring and pay for your own AI provider key — Kubexer does not charge for AI usage on top of Pro; those costs are billed by your provider.

By default Kubexy is read-only. It can also act on your cluster — restart, scale, edit, or delete resources — but only with your explicit confirmation: every change shows a confirmation card before it runs, so nothing happens without your approval.

Yes. Kubexer lists your Custom Resource Definitions and lets you browse their instances with the same live tables and detail drawers as built-in resources, including CRD printer columns. A Lens-style sidebar adapts automatically to the CRDs installed in each cluster.

Still have questions?

We're here to help

Reach the team directly and we'll get back to you.

support@kubexer.com