K9s
Browse and inspect any connected Kubernetes cluster from an interactive terminal inside the Facets dashboard, scoped to your own Facets permissions.
What it is
K9s is a Praxis app that embeds an interactive, k9s-style terminal for Kubernetes inside the Facets dashboard. You pick a running environment, and a live terminal opens against that environment's cluster, ready for you to browse and inspect what is running.
It is built for one job: interactive inspection. It is the place to look around a cluster yourself, in real time, without leaving Facets or wiring up your own kubectl access. If you already know k9s as a local tool, this is the same experience, hosted in the browser and wired into your Facets environments.
K9s is generally available. Unlike the other Praxis apps, which are in beta, it is ready for everyday use. Turn it on per organization from Apps in settings. It needs a connected Facets account and a connected Kubernetes cluster, and it runs under your own Facets permissions, which for most roles means read-only.
What you can do
K9s shows you one cluster at a time. Choose the Facets environment you want to look at, each one is backed by a Kubernetes cluster, and the terminal opens against that cluster. From there you navigate the way you would in a local k9s session: move between Kubernetes object types, drill into a specific object, and read its details, logs, and events. The view is live, reflecting the state of the cluster as it is right now.
Because the terminal runs in the browser and works against your existing Facets environments, there is nothing to install and no cluster credentials to manage yourself. To move to a different cluster, switch to another environment and the terminal reopens against it. That per-environment focus keeps the view scoped to exactly the system you are troubleshooting.
This matters for teams. No one needs a local kubeconfig or their own cluster tooling; everyone opens the same clusters through Facets, in the browser. Bringing a new person into cluster visibility becomes a matter of their Facets access rather than a credential handoff.
Reach for K9s to confirm a rollout landed, check why a pod is unhealthy, read recent logs and events, or get a quick read on a cluster's state during a release. Once the app is enabled, it appears in your navigation; open it and choose an environment to start.
K9s vs K8s Inspector vs Incident Responder
Facets gives you three ways to look at Kubernetes, and each suits a different moment.
| Tool | What it is | How you use it |
|---|---|---|
| K9s | An interactive terminal that browses a live cluster | You drive it, navigating and inspecting the cluster yourself |
| K8s Inspector | Conversational Kubernetes Q&A in chat | You describe a symptom; the agent runs the read-only commands and answers |
| Incident Responder | Autonomous incident investigation | It starts on its own when an alert fires, then diagnoses the root cause |
Reach for K9s when you want to look around yourself. Ask K8s Inspector when you would rather describe a problem and let Praxis run the commands for you. Incident Responder you do not drive at all: it triggers on alerts and investigates without being asked. K9s and K8s Inspector complement each other well: browse to a resource yourself, then ask K8s Inspector to reason about what you are seeing. K8s Inspector and Incident Responder run only read-only commands and never change the cluster. K9s is bounded instead by your Facets role, which for most people means read-only as well.
Access and safety
Access to K9s runs through your own Facets permissions. When you open an environment, Praxis uses your Facets session to load that environment's kubeconfig and starts the terminal against it. You only ever see the environments and clusters your Facets role already allows. If you do not have permission for an environment, K9s tells you so and does not open a terminal. Access is tied to you, not to a shared service account, so what you can reach in K9s matches what you can reach in Facets.
Within an environment you can open, what you can do is set by that kubeconfig, which carries your own Facets permissions. You can run exactly what your Facets role allows. Most roles are read-only, so they can browse objects, describe them, and read logs and events. If your role cannot change a resource in Facets, it cannot change it in K9s either. K9s adds no separate read-only lock of its own, so your Facets role is what bounds each session.
Beyond these limits, K9s runs under the same permission, credential, and isolation model as every Praxis feature. See How Praxis works.
Related
- K8s Inspector - Ask read-only questions about a Kubernetes cluster in chat
- Incident Responder - Autonomous, read-only investigation that starts when an alert fires
- How Praxis works - The shared permission, credential, and isolation model behind every Praxis app
K8s Inspector
Query and troubleshoot Kubernetes clusters through natural language: pod states, resource utilisation, CrashLoopBackOffs, no kubectl required.
Facets CLI v1.0.9 [not supported]
Legacy command reference for facetsctl v1.0.9, no longer supported. Covers login, register, push, refresh, and upload; use the current Praxis CLI instead.