The Kubernetes IDE for Mac

Your clusters, at a glance. KubeCrow is a free, fast Kubernetes desktop app for macOS: browse pods and every resource, tail logs, open shells, edit YAML and manage Helm releases, with guard rails around production.

  • Free
  • Sign in with Google or GitHub
  • No telemetry
  • Native on Apple Silicon
Download for MacDownload for Mac: coming soon

v0.1.2 · Universal (Apple Silicon + Intel) · macOS 13+ · Install notes

KubeCrow Health page: three problems found, including a rollout stuck on an image that can't be pulled with a Roll back button, above CPU usage over the last hour and CPU, memory and pod capacity rings
Features

A Kubernetes GUI for everything you reach for kubectl to do

Every section of your cluster, from Workloads to Custom Resources, in a quick native-feeling app that stays out of your way.

Problems, before they page you

Crash loops, failed pulls, pending pods and rollouts stuck on a broken version, in one list with alerts. Roll a stuck rollout back in one click.

What changed

Rollouts, rollbacks, scaling, restarts and warnings on one timeline, plus ConfigMap edits with before and after values.

Search every pod’s logs

One search across a whole namespace through your cluster’s Loki, including pods that were replaced. Start from a crashing pod’s error in one click.

Right-sizing

Requests and limits against seven days of real use from Prometheus, with suggested values and the containers close to being OOM-killed.

Every resource

Cluster, Workloads, Config, Network, Storage, Access Control and Custom Resources, with the columns and actions you expect.

AWS EKS discovery

Scans your AWS profiles and lists EKS clusters in every enabled region, grouped by account. Pick one and it's connected.

Production guard

Mark clusters as protected or read-only. Risky actions ask first, and deletes need you to type the name.

Logs that read well

Follow any container with time ranges, timestamps, search and pretty-printed JSON.

Shells & port forwards

Open a terminal in any pod or node, and forward service ports to localhost with one click.

Edit YAML in place

A proper code editor for any resource, plus inline editing for ConfigMap and Secret values.

Helm releases

Browse chart repos, install with a values editor, upgrade, and roll back to any revision, using your helm CLI.

Themes & ⌘K

Ocean, Midnight or Classic, following macOS light and dark. Jump anywhere from the command palette.

Screenshots

A closer look

Real screens from the app, running against a local cluster.

A stuck rollout: the new pod fails to pull its image, with a one-click roll back to the previous revision
Fix a stuck rollout. See which new pod is failing and why, and roll back to the last good revision in one click.
Install

Opening KubeCrow the first time

KubeCrow isn't signed by Apple yet, so macOS blocks it the first time. One Terminal command clears that, and from then on it opens like any other app.

  1. Download the app

    Get the .dmg from the Download button. It runs natively on Apple Silicon and Intel Macs.

  2. Drag KubeCrow into Applications

    Open the .dmg and drag the icon onto the Applications folder.

  3. Run the command once

    Paste the command from the box into Terminal. It removes the quarantine flag macOS adds to downloaded apps.

  4. Open KubeCrow and sign in

    Launch it from Applications or Spotlight as usual, then sign in with Google or GitHub the first time. You only need the command again after installing a new version.

Run this in Terminal

Needed if macOS says “KubeCrow is damaged and can't be opened” or “cannot be opened because Apple cannot check it”. The app isn't damaged; macOS just can't verify who made it.

xattr -dr com.apple.quarantine /Applications/KubeCrow.app

Why the extra step? Apps from outside the App Store need an Apple Developer ID signature and notarisation for macOS to open them silently. KubeCrow doesn't have those yet; they're on the roadmap, and this step will go away.

Clusters

Connect the way you already do

KubeCrow reads the same kubeconfig kubectl uses, so the clusters and sign-ins you already have just work.

  • kubeconfig contextsEvery context in ~/.kube/config or $KUBECONFIG, switched from the top bar.
  • Amazon EKSSign in with AWS SSO, no AWS CLI needed, and it finds clusters in every account and region, grouped by account. AWS profiles work too.
  • Google GKEThrough the exec plugin in your kubeconfig, gke-gcloud-auth-plugin.
  • Azure AKSThrough the exec plugin in your kubeconfig, such as kubelogin.
  • Client certificatesCertificate and key from your kubeconfig, inline or as files.
  • TokensBearer and service-account tokens set in your kubeconfig.
  • Local clustersminikube, kind, Docker Desktop and any other cluster with a kubeconfig context.
Privacy

Local first. Nothing installed in your cluster.

KubeCrow runs on your Mac and talks to the Kubernetes API with your own kubeconfig and permissions.

Nothing to install

No agents, operators or add-ons. KubeCrow uses the Kubernetes API with the access your kubeconfig already has.

One exception: a node shell starts a short-lived privileged pod (busybox:1.36) in kube-system on that node, and deletes it when you close the tab.

No telemetry or analytics in the app

KubeCrow connects only to:

  • your clusters' API servers;
  • AWS, when you use EKS discovery;
  • Prometheus and Loki running in your own clusters, through the API server;
  • app.kubecrow.com, to check your KubeCrow sign-in at launch and every few hours (it keeps working offline for 7 days);
  • GitHub, where KubeCrow is published, to check for updates: a small file listing the latest version, a minute after start and every 6 hours.

Everything your KubeCrow account stores, and how to delete it: privacy policy.

FAQ

Questions about KubeCrow

Is KubeCrow free?

Yes. KubeCrow is free. You sign in once with your Google or GitHub account; there’s no password to create and nothing to pay.

What does my KubeCrow account store?

Your name, email address and profile photo (from Google or GitHub), your plan, when you last downloaded KubeCrow, and the names of the Macs you’re signed in on. Nothing about your clusters, kubeconfig or their data. You can sign a Mac out, or delete the account, at app.kubecrow.com.

Does KubeCrow run on Apple Silicon Macs?

Yes. KubeCrow is one universal app that runs natively on Apple Silicon (M1 and later) and Intel Macs, on macOS 13 Ventura or later.

Which Kubernetes clusters does KubeCrow work with?

Any cluster in your kubeconfig, the same file kubectl uses: Amazon EKS, Google GKE, Azure AKS, on-premises clusters, and local clusters such as minikube, kind or Docker Desktop. Exec authentication plugins work.

How does KubeCrow connect to Amazon EKS?

Sign in with AWS SSO or add access keys in Settings → AWS accounts, no AWS CLI needed, or let it use your ~/.aws profiles. It lists the EKS clusters in every region grouped by account and signs in to them for you.

Does KubeCrow send my cluster data anywhere?

No. There is no telemetry or analytics, and your clusters' data never leaves your Mac. KubeCrow talks only to your clusters' API servers, to AWS when you use EKS discovery, and to Prometheus or Loki running in your own clusters. Apart from that, it checks your KubeCrow sign-in with app.kubecrow.com and checks for updates by fetching a small file listing the latest version from GitHub, where KubeCrow is published.

Do I need kubectl, helm or the AWS CLI installed?

You don't need kubectl or the AWS CLI: KubeCrow talks to the Kubernetes API directly using your kubeconfig, and signs in to Amazon EKS itself through an AWS account you add in Settings. Only the Helm views use the helm CLI.

Can KubeCrow protect production clusters from mistakes?

Yes. Mark a cluster Protected and every change asks you to type the cluster's name first, or mark it Read-only to refuse changes and shells while you can still browse resources, read logs and port-forward.

Why does macOS say KubeCrow is damaged?

KubeCrow isn't signed by Apple yet, so macOS quarantines it after download. Run xattr -dr com.apple.quarantine /Applications/KubeCrow.app once in Terminal, then open KubeCrow normally.

Requirements

What you need

  • macOS 13 or laterApple Silicon or Intel, in one universal app.
  • A kubeconfigRead from ~/.kube/config or $KUBECONFIG, the same file kubectl uses.
  • For EKS: an AWS sign-inAWS SSO or access keys, added in Settings → AWS accounts. No AWS CLI needed; ~/.aws profiles work too.
  • For Helm: the helm CLIbrew install helm. Homebrew tools are found even when KubeCrow is opened from Finder.

Up and running in three steps

  1. Download KubeCrow

    One universal app for Apple Silicon and Intel Macs.

    Download for MacDownload coming soon
  2. Run one command

    Drag it into Applications, then clear macOS's quarantine flag once (until KubeCrow is signed by Apple).

    xattr -dr com.apple.quarantine /Applications/KubeCrow.app
  3. Sign in and pick a cluster

    Sign in with Google or GitHub once. Your kubeconfig contexts are listed straight away; EKS clusters from your AWS profiles appear alongside.

Free · v0.1.2 · Release notes