K8s Inspector
Query and troubleshoot Kubernetes clusters through natural language: pod states, resource utilisation, CrashLoopBackOffs, no kubectl required.
K8s Inspector is a built-in Praxis capability for exploring and troubleshooting your Kubernetes clusters in plain language. Ask Praxis a question and it runs the read-only kubectl and helm commands needed to answer, then explains what it found. It is strictly read-only: it never restarts, scales, deletes, or deploys anything.
What you can do
- Resource inspection: Get details on pods, deployments, services, nodes, namespaces, and other cluster objects.
- Log analysis: Fetch and search logs from a specific pod or container.
- Event-based debugging: Read Kubernetes events to trace the cause of a failure, such as a pod eviction or an image pull error.
- Resource usage: Report CPU and memory requests, limits, and actual usage across a pod, namespace, or node.
- Health checks: Summarize the status of deployments, pods, and services.
- Network troubleshooting: Inspect service endpoints, ingress rules, and network policies.
- Container inspection: Run a non-interactive command inside a container with
execto read a config file, list environment variables, or check disk usage in a pod. - Port forwarding: Open a local tunnel to a pod or service with
port-forward. - Helm release inspection: Review a release's revision history, the values applied in a specific revision, the rendered manifests, and its notes and hooks.
- Permission checks: Confirm what the connected credential can do with
auth can-i.
How it works
You ask a question in plain language. Praxis interprets it, chooses the read-only Kubernetes commands that answer it, and runs them server-side. The result comes back as readable text, tables, or log snippets. Praxis connects through your organization's Kubernetes integration, so you need no separate credentials.
Example prompts
- "Why is the pod
frontend-xyz-12345in the production namespace crash-looping?" - "Show me the recent events for the
database-maindeployment." - "Get the last 100 lines of logs from the
api-gatewaycontainer in podgateway-abc-67890." - "List all pods in the staging namespace with the label
app=backend." - "Show me CPU and memory usage for every node."
- "What changed in the last two revisions of the
checkouthelm release?" - "Read
/etc/resolv.confinside podweb-abc-12345."
Access
Use K8s Inspector by chatting with Praxis: in the web app, from the Praxis CLI, or in a connected Slack channel. Access comes from an org-level Kubernetes integration, set up once under Settings > Integrations > Kubernetes. Its stored credentials resolve on the server for each request, so no individual user supplies their own. Praxis stays within that integration credential's Kubernetes RBAC and reads only what the credential is allowed to read, including any Secrets and ConfigMaps that role can view. Every request is read-only. The exec and port-forward operations run under that same read-only gate, but they can read inside a container or open a tunnel to it, so treat them as read access to container internals. For how Praxis stores credentials and keeps actions read-only across every capability, see How Praxis works.
K8s Inspector, K9s, and Incident Responder
Three Praxis surfaces touch Kubernetes. They do different jobs:
| Surface | What it is | How you use it |
|---|---|---|
| K8s Inspector | Read-only cluster inspection through conversation | Ask Praxis a question |
| K9s | An interactive terminal UI for browsing clusters | Browse objects in the terminal |
| Incident Responder (beta) | Autonomous, read-only investigation of alerts and incidents | Runs on its own when an alert arrives |
Reach for K8s Inspector when you have a quick, ad-hoc question about a running cluster.
Troubleshooting
Praxis says it can't answer the question. The request may be ambiguous or outside what read-only inspection can retrieve. Rephrase it to name the specific object, namespace, or cluster you mean.
Praxis reports it lacks permission. The Kubernetes integration credential does not have the RBAC rights the request needs. For example, reading pod logs requires get on pods and their log sub-resource. Grant the credential those rights, or work within the access it already has.
Related
- K9s - Interactive cluster browser app
- Incident Responder - Autonomous incident investigation
- How Praxis works - Credentials, read-only default, and the safety model