Overview
KubeBolt is an open-source Kubernetes operations platform — see, understand and operate your clusters. Start with just a kubeconfig; add the optional agent when you want history, network flows and cost.
What is KubeBolt?
KubeBolt is an open-source Kubernetes operations platform: one place to
see, understand and operate your clusters — health, topology, day-2
operations, cost and security — with Kobi, an AI SRE that reasons over the
same context and acts only when you approve. It is built for the SREs,
platform engineers and hands-on engineering leads who already run Kubernetes
with Prometheus, Grafana and kubectl, and want the context of an incident in
one place instead of five.
Start small: only a kubeconfig — no YAML to write, no CRDs to install.
Add the lightweight agent when you want historical metrics, network flows and
cost, or to reach clusters whose API server isn’t reachable from KubeBolt. It
connects outbound and installs with one helm command.
What you get
- See
- Two altitudes — Home and Fleet answer “how is everything?” across clusters; a cluster’s own dashboard answers “how is this one?”
- Cluster dashboard — Overview (KPIs, resource efficiency band, workload health), Capacity (trends, peaks, rightsizing, OOMKills), Reliability (golden signals from Hubble, shown when flow data exists) and Cost (beta, from OpenCost, shown when cost data exists)
- 26 resource list views with live CPU/memory — including Gateway API, Cilium policies, cert-manager, Argo CD and VPA — plus Namespaces, Events, cluster RBAC and read-only Helm Applications
- Cluster Map in Grid, Flow and Traffic (observed Hubble flows) layouts
- Global search — ⌘K across resource types, fleet-wide when you want it
- Understand
- 24-rule insights engine with a lifecycle — durable episodes, flap damping, mutes, and a per-rule policy layer
- Security & Compliance — vulnerability, misconfiguration and runtime findings from Trivy, Kyverno and Falco, in one place (KubeBolt reads the scanners you run; it doesn’t scan)
- Kobi Copilot — bring your own key (Anthropic or any OpenAI-compatible endpoint). 39 tools: 30 that read live data and 9 that propose an action you approve before anything runs. Off until you configure it. Twenty-nine of those read tools are available to your own agents through a read-only MCP server
- Operate
- Cluster actions — pod terminal, file browser, logs, port-forward, restart, scale, roll back, drain, YAML edit, delete, and an audited Secret reveal — within the cluster credentials’ RBAC, with an audit trail
- Multi-cluster — kubeconfig contexts, agent-connected clusters (outbound-only), and a metrics-only tier, in one persistent registry
- Built-in authentication — Admin / Editor / Viewer roles enforced by the backend, API tokens for automation
- RBAC-aware — probes what its credentials may do and shows restricted resources as restricted, not as errors
KubeBolt Cloud
Prefer not to self-host? KubeBolt Cloud is the managed offering at app.kubebolt.io — Free and Team available today. It adds Kobi Autopilot, which investigates an incident and, within the policy your team sets, remediates it and reverts if verification fails; it is Cloud-only and in open beta. Kobi Copilot comes with AI credits there instead of your own key. The open-source edition stays Apache 2.0, with no feature limits on what it ships.
Performance
The backend is a single Go process that answers API reads from in-process informer caches instead of calling the API server on every request. That is the kubeconfig-only setup; the optional agent and the metrics store add footprint proportional to what you enable.
Compatibility
| Provider | Metrics Server | Notes |
|---|---|---|
| Amazon EKS | Not installed by default | Install it — see the EKS guide, which also covers AWS credentials outside the cluster; managed Prometheus (AMP) supported |
| Google GKE | Pre-installed | Works out of the box, Autopilot included; managed Prometheus (GMP) supported — GKE guide |
| Azure AKS | Pre-installed | Works out of the box; Azure Monitor managed Prometheus supported — AKS guide |
| OpenShift | Cluster monitoring | The web image needs a workaround under the default restricted-v2 SCC — see the OpenShift guide |
| k3s / k0s | Pre-installed | Works out of the box |
| Docker Desktop | Manual install | Live usage bars need it; see the Docker Desktop guide |
| Minikube | Addon | minikube addons enable metrics-server |
Version floors, and which agent pairs with which backend, live in Compatibility.
Next
Quick Start — one helm command and a port-forward,
and you are looking at a cluster.