Skip to content

About

A fast, open-source Kubernetes desktop client (.NET + Avalonia, NativeAOT)

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Repository files navigation

kubeNimbus logo: a ship's helm riding a broom

kubeNimbus

A fast, open-source Kubernetes desktop client.
The Kubernetes sibling of pgNimbus, and an alternative to Lens.

CI Latest release Microsoft Store MIT licensed .NET 10 NativeAOT


Why another one? The 2026 Kubernetes GUI market is thin in one specific place. Lens is subscription-gated for commercial use and heavy Electron; OpenLens is dead; FreeLens is still Electron, and so is Headlamp's desktop app; Aptakube is polished but closed and paid; k9s is a keyboard TUI. KubeUI is the closest thing to kubeNimbus — also MIT, also Avalonia — and is the comparison worth making: kubeNimbus is NativeAOT, opens in ~150 ms rather than ~650 ms, ships a ~62 MB payload rather than 382 MiB, and sends no telemetry at all.

Screenshots

Applications list: every app with a health verdict and a one-line reason, what needs attention first

Application page: findings quoting the fields they came from, a timeline, and the crashing pod's last run
One Enter to the why — findings that quote the field they came from, the last hour on a timeline, and the crashing pod's last run.
Pod detail docked along the bottom with container chips and live logs
Pod detail docks along the bottom — full-width logs, not a cramped sidecar.
top running full-screen inside the exec pane's terminal emulator
A real terminal in the exec pane — vi, top and mc draw, with colour and cursor addressing, and Ctrl+C still reaches the container.
YAML editor with syntax highlighting
YAML editing with syntax highlighting and server-side apply.
Searchable cluster switcher with pinned clusters and environment labels
Cluster switcher (Ctrl/Cmd+P) — fuzzy search over every context, pinned favourites, and prod/staging/dev colour so you always know where you are.
One list aggregating a resource kind across several clusters
All clusters — one list across the whole fleet, honest about partial coverage.
Pod list with live status pills and CPU/memory sparklines
Resources — every kind the cluster serves, CRDs included, with live status and CPU/memory sparklines.
RBAC access review showing which subjects can perform a verb
Who can do X? — every subject a binding grants a verb, verifiable against the API server.

Rendered from the repo's own headless harness (tools/Screenshot) against fixture data — real views, synthetic clusters.

Download

On Windows, install from the Microsoft Store. It is the same app, re-signed by Microsoft during certification, so it installs and updates with no SmartScreen prompt and no unsigned-binary workaround.

Everywhere else — and on Windows if you would rather not use the Store — grab the installer or the portable archive for your platform from the latest release. Builds are self-contained NativeAOT binaries — no .NET runtime to install.

Platform Installer Portable
Windows x64 the Store kubeNimbus-<version>-win-x64.zip
macOS Apple Silicon kubeNimbus-<version>-osx-arm64.dmg kubeNimbus-<version>-osx-arm64.tar.gz
Linux x64 kubeNimbus-<version>-linux-x64.deb or .AppImage kubeNimbus-<version>-linux-x64.tar.gz
Linux arm64 kubeNimbus-<version>-linux-arm64.deb or .AppImage kubeNimbus-<version>-linux-arm64.tar.gz

The installers add a desktop launcher and an icon; the portable archives are the same binary with nothing to install. Every package is launched by CI on its own platform before the release is created.

Intel Macs aren't published yet — build from source, it's one command.

Downloads from this page are unsigned — code signing needs certificates this project doesn't have, so your OS will object the first time. (The Store build above is signed by Microsoft and does none of this.)

Windows

Store. winget install --id 9MZ3C28M65PB --source msstore or the listing — signed, and nothing below applies.

Zip. Unblock it before extracting (Properties → Unblock, or Unblock-File kubeNimbus-<version>-win-x64.zip in PowerShell), then run kubeNimbus.exe. Nothing is installed: your settings live in %AppData%\kubeNimbus, so updating is replacing the folder with the new one. Up to 0.5.0 there was also an MSI; if you installed it, uninstall it from Settings → Apps.

SmartScreen shows "Windows protected your PC" the first time — click More info → Run anyway.

Linux

Debian/Ubuntu (.deb) — pulls in the X11 and fontconfig libraries it needs and registers a desktop launcher:

sudo apt install ./kubeNimbus-<version>-linux-x64.deb
kubenimbus

AppImage — nothing to install, runs on any distribution:

chmod +x kubeNimbus-<version>-linux-x64.AppImage
./kubeNimbus-<version>-linux-x64.AppImage

Tarball:

tar -xzf kubeNimbus-<version>-linux-x64.tar.gz
cd kubeNimbus-<version>-linux-x64
./kubeNimbus

All three need a desktop session (X11, or Wayland via XWayland). Outside the .deb, a minimal image may be missing libx11-6, libsm6, libice6 and fontconfig.

macOS

DMG. Open it and drag kubeNimbus to Applications. The app is signed ad-hoc rather than with a Developer ID, so the first launch has to be right-click → Open → Open (double-clicking gives a dialog with no way past it). After that it opens normally.

Tarball. The same binary without a bundle, for launching from a terminal:

tar -xzf kubeNimbus-<version>-osx-arm64.tar.gz
cd kubeNimbus-<version>-osx-arm64
xattr -dr com.apple.quarantine .
./kubeNimbus
Verifying the download

Every release ships SHA256SUMS.txt:

sha256sum -c SHA256SUMS.txt --ignore-missing     # shasum -a 256 -c on macOS

Then point it at a cluster — kubeNimbus reads your $KUBECONFIG chain and ~/.kube/config and lists what it finds. If neither turns anything up, the first screen has an Open kubeconfig file… button: pick the file and it's added — or Add folder…, and every kubeconfig in that folder is read, including ones added to it later. Only the path is remembered — the file is re-read through the normal kubeconfig chain every time, so nothing is ever copied into app storage.

Note on $KUBECONFIG: an app launched from Explorer, Finder or a shortcut doesn't inherit environment variables set in your shell. That's what the file picker is for; kubeNimbus also tells you exactly which paths it searched. The same goes for $PATH: a credential plugin named bare in the kubeconfig (command: aws) is also looked for where a login shell would find it — /usr/local/bin, /opt/homebrew/bin, ~/.local/bin and friends.

No cluster yet? Try the demo

The same first screen has Explore demo cluster (also Ctrl/Cmd+K → "Explore the demo cluster"). It opens a full sample workload set that ships inside the binary — pods in every interesting state, live-looking logs, environment variables and secrets, events, usage graphs, Helm releases and a realistic CRD catalog — with no cluster, no credentials and no network involved. It's there so you can see what the app does before wiring anything up.

It is labelled as sample data throughout: the tab reads Demo cluster, and a banner sits above the content for as long as the tab is open. Exec, port-forward and applying/deleting YAML genuinely need a real API server, so those panes say so instead of pretending; everything else is the real UI over sample objects.

What it does

Connect — every $KUBECONFIG entry plus ~/.kube/config, with exec-plugin auth (EKS, GKE, AKS) resolved through the kubeconfig at connect time, and the cluster's proxy-url (HTTP or SOCKS5, for a bastion) honoured. A connect that fails says which step failed, why, and with what, with Retry; an expired session is picked up again without closing the tab. Multi-cluster tabs, drag-reorderable, restored with your workspace. Credentials are never persisted — see SECURITY.md.

Triage — a cluster opens on Applications: every Argo CD Application and every workload Argo does not track, with a health verdict and a one-line reason read from the cluster's own status ("Crash-looping (exit 1) · 2 pods not created: namespace quota"), what needs attention first. Enter opens the application: the facts behind the verdict, each quoting the field it came from; its pods; what it is wired to; a timeline of the last hour; what the last deploy changed, with a compare link to your Git host; and the logs, opened on the crashing pod's last run. Works under narrow RBAC, and says what it could not read. The explorer below is one click away as Resources.

Browse — a discovery-driven sidebar covering built-in kinds and CRDs, filterable by name, API group or kubectl short name (svc, po), with a pinned Recent section. Lists are informer-style list + watch, so they update live rather than polling, and reconnect on their own with resourceVersion resume and a relist on 410 Gone.

Inspect — pod detail docks along the bottom, full width: live logs with follow, search, severity colouring and a previous-container fetch; environment variables with per-key on-demand reveal for Secret and ConfigMap refs; events as a card feed; owner-chain navigation from pod to replica set to deployment. Exec into a container — a real VT terminal, so vi, top, mc and less work rather than unspooling escape codes — and port-forward, both over websockets. An image with no shell (distroless, .NET chiseled) gets a debug container in one click, kubectl debug's ephemeral container sharing the target's processes; a pod on a Windows node gets powershell or cmd.

Edit — YAML view and edit for any resource with syntax highlighting, server-side apply through a field manager, conflicts surfaced with a force-apply offered, and a two-step delete.

Measure — live CPU and memory from metrics.k8s.io in the list and per container, plus usage graphs over the session's rolling 30-minute window. A cluster with no metrics-server simply hides those columns instead of erroring.

Operate — read-only Helm release browsing (values, rendered manifest, notes, revision history) read straight from release Secrets with no Helm binary involved; and RBAC access review in all three directions: your effective permissions via SelfSubjectRulesReview, where a ServiceAccount's access comes from, and cluster-wide who can do X with one-click SubjectAccessReview confirmation.

GitOps — a cluster running Argo CD gets its own sidebar section with a dashboard over every Application: the cluster-wide counts, a list ordered by what needs attention, and sync status and health as two separate pills, because an Application can be perfectly synced and still degraded. Open one for its source, destination, managed resources, conditions and deployment history — and Sync or Refresh from Git it from the row, with an explicit confirm and prune off by default. It reads and writes Argo's own custom resources over the Kubernetes connection you already have: no Argo API server, no URL to paste, no argocd binary, no second login.

Fleet — an "All clusters" toggle aggregating any kind across every connected cluster into one list, with a Cluster column and an honest "n of m clusters serve X" when a kind isn't available everywhere.

Switch — a Ctrl/Cmd+P cluster switcher that fuzzy-searches every context by name, cluster or kubeconfig file, so a 200-entry kubeconfig full of generated EKS ARNs is three keystrokes away rather than a scroll. Pin the clusters you live in. Every cluster is colour-coded prod / staging / dev — a red band sits under the command bar whenever you're pointed at production, and you can correct the guess by right-clicking a tab.

Plus a Ctrl/Cmd+K command palette, an F1 shortcut cheat sheet, and light/dark themes.

Full detail, including why each piece is built the way it is, lives in CLAUDE.md. Release history is in CHANGELOG.md.

Privacy

kubeNimbus has no telemetry, no account and no update check, and it talks only to the clusters you open. It stores your preferences and window layout in your profile folder, and never a password, token or certificate. The privacy policy lists every file it writes and every connection it makes; the same page is linked from the About box and from the Microsoft Store listing.

Known limitations

kubeNimbus is pre-1.0, and the first public release is honest about where it's been exercised:

  • Binaries and installers downloaded from Releases are unsigned (see above), and there is no auto-update — a new version is a new download. The Microsoft Store build is signed and updates itself; it is Windows-only.
  • Windows has had the most hands-on use. The Linux and macOS builds are produced and AOT-verified by CI but have seen much less real-world testing.
  • The demo cluster is a fixed sample set, not a simulator: nothing in it changes, scales or can be edited, and exec/port-forward/apply/delete are unavailable there by nature. It's for seeing the app, not for practising against.
  • Helm is read-only — install, upgrade and rollback stay Helm's job.
  • Argo CD support covers browsing, syncing and refreshing Applications. Creating or editing them is a YAML edit like any other custom resource, and terminating a sync that is already running is not offered.
  • Usage history is session-scoped and capped at 30 minutes by design. Long-range metrics is Prometheus's job, and a permanent non-goal here.

Permanent non-goals: cluster provisioning, in-cluster agents, and telemetry. kubeNimbus makes no network connection other than to the clusters you point it at.

Bugs and gaps are worth reporting — the issue templates ask for the two things that make a Kubernetes-client bug tractable.

Tech stack

  • .NET 10, with NativeAOT as the shipping configuration — not an afterthought. Every dependency is chosen to survive trimming and AOT.
  • KubernetesClient.Aot (source-generated serialization) as the only cluster dependency in the engine.
  • Avalonia 12 — Fluent theme, Inter, DataGrid, AvaloniaEdit — with CommunityToolkit.Mvvm and compiled bindings only.
  • TUnit on Microsoft.Testing.Platform, run against a real cluster rather than mocks.

Architecture

Project
src/KubeNimbus.Core The engine: kubeconfig, ClusterClient (discovery, watch, logs, exec, port-forward, apply, metrics, Helm, RBAC). Zero UI dependencies — reusable for a future CLI.
src/KubeNimbus.App The Avalonia desktop shell.
tests/KubeNimbus.Core.Tests TUnit integration tests against a live cluster; they skip cleanly without one.
tools/Screenshot Headless visual-verification harness — renders real views to PNG with no display. Dev-only.

Building from source

Requires the .NET 10 SDK.

git clone https://github.com/Shman4ik/kubeNimbus.git
cd kubeNimbus
dotnet build KubeNimbus.slnx
dotnet run --project src/KubeNimbus.App

For a release-shaped binary (needs a native toolchain — MSVC on Windows, clang + zlib1g-dev on Linux, Xcode CLT on macOS):

dotnet publish src/KubeNimbus.App -c Release -r linux-x64 -p:PublishAot=true -o publish/app

A cluster to try it against

scripts/sandbox-up spins up a throwaway single-node k3s cluster in Docker, preloaded with demo workloads picked to light up every part of the UI — healthy and deliberately-broken pods, CRDs, Helm releases, RBAC subjects, PVCs, and jobs that keep firing so the live watch is visibly live:

./scripts/sandbox-up.sh                     # sandbox-up.ps1 on Windows
export KUBECONFIG=.sandbox/kubeconfig.yaml
dotnet run --project src/KubeNimbus.App

The same kubeconfig is what the integration tests auto-discover. Flags — a second cluster for the fleet views, custom port, bare cluster — are in scripts/README.md; tear down with ./scripts/sandbox-down.sh.

Contributing

Contributions are welcome. CONTRIBUTING.md covers the setup, what to verify before opening a PR, and the handful of rules a change is most likely to trip over. CLAUDE.md is the full engineering contract and the best thing to read first.

Security issues go through private reporting, not the issue tracker — see SECURITY.md.

By participating you agree to the Code of Conduct.

License

MIT — free for commercial use, no subscription, no seat count.

About

A fast, open-source Kubernetes desktop client (.NET + Avalonia, NativeAOT)

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages