Kubius · RBAC & security

See exactly who can do what - without sending your cluster anywhere

Audit RBAC both directions, simulate network policies, and reveal secrets behind Touch ID - all from a native Mac app that never sends your cluster to anyone's cloud.

Works with Google GKE, Amazon EKS, Azure AKS, DigitalOcean, self-managed & more · macOS Sonoma (14) or later

Answers your security team actually asks for

RBAC Explorer, both ways

What can this subject do? Who can run this action? Every effective rule resolved from Roles and ClusterRoles, with the binding path behind each grant.

Network Policy Simulator

Can pod A reach pod B? A clear allowed or blocked verdict with per-direction explanations and the NetworkPolicies responsible.

Secrets behind Touch ID

Reveal Secret values per-key, on demand, gated by biometric auth - and see exactly which workloads consume each Secret and ConfigMap.

No agent, no cloud

Nothing runs in your clusters and nothing leaves your Mac - ideal where a cloud dashboard or in-cluster agent is a non-starter.

Audit-ready answers

Resolve effective permissions in seconds instead of grepping RoleBindings - answers you can take straight into a review.

Every resource, live

ServiceAccounts, Roles, ClusterRoles and their bindings, kept live by watch streams, with a full CRD browser alongside.

Built for security teams

The cluster visibility you need, on a machine you control

No SaaS to approve, no agent to deploy, no data egress to explain.

  • Nothing installed in-cluster
  • Cluster and secret data never leave your Mac
  • Effective-permission resolution, both directions
  • Network reachability simulated from your policies
  • Biometric-gated secret reveal
  • Connects with the auth your kubeconfig already uses

Simple, one-time pricing

Pay once. No subscription.

One-time licence from €49 - no subscription. 14-day free trial, no card required.

Free 14-day trial · macOS Sonoma (14) or later · No agents, nothing to install in-cluster

Questions, answered

Does any cluster data leave my machine?

No. Kubius talks directly to the cluster API from your Mac. There are no agents and no telemetry - nothing about your clusters or secrets is sent to Kubius or any third party.

How does the RBAC Explorer work?

It resolves effective permissions from your Roles, ClusterRoles and their bindings - both 'what can this subject do' and 'who can do this action' - and shows the binding path behind each grant.

Are secret values exposed by default?

No. Secrets are masked; you reveal values per-key on demand, gated by Touch ID or your device's biometric auth.

Do I need to install anything in the cluster?

No agents, no Helm charts. Read access via your existing kubeconfig is all it needs.

Audit your clusters without shipping them to the cloud