See exactly who can do what - without sending your cluster anywhere
Audit RBAC both directions, simulate network policies, and reveal secrets behind Touch ID - all from a native Mac app that never sends your cluster to anyone's cloud.
Works with Google GKE, Amazon EKS, Azure AKS, DigitalOcean, self-managed & more · macOS Sonoma (14) or later
Answers your security team actually asks for
RBAC Explorer, both ways
What can this subject do? Who can run this action? Every effective rule resolved from Roles and ClusterRoles, with the binding path behind each grant.
Network Policy Simulator
Can pod A reach pod B? A clear allowed or blocked verdict with per-direction explanations and the NetworkPolicies responsible.
Secrets behind Touch ID
Reveal Secret values per-key, on demand, gated by biometric auth - and see exactly which workloads consume each Secret and ConfigMap.
No agent, no cloud
Nothing runs in your clusters and nothing leaves your Mac - ideal where a cloud dashboard or in-cluster agent is a non-starter.
Audit-ready answers
Resolve effective permissions in seconds instead of grepping RoleBindings - answers you can take straight into a review.
Every resource, live
ServiceAccounts, Roles, ClusterRoles and their bindings, kept live by watch streams, with a full CRD browser alongside.
Built for security teams
The cluster visibility you need, on a machine you control
No SaaS to approve, no agent to deploy, no data egress to explain.
- Nothing installed in-cluster
- Cluster and secret data never leave your Mac
- Effective-permission resolution, both directions
- Network reachability simulated from your policies
- Biometric-gated secret reveal
- Connects with the auth your kubeconfig already uses
Simple, one-time pricing
Pay once. No subscription.
One-time licence from €49 - no subscription. 14-day free trial, no card required.
Free 14-day trial · macOS Sonoma (14) or later · No agents, nothing to install in-cluster
Questions, answered
Does any cluster data leave my machine?
No. Kubius talks directly to the cluster API from your Mac. There are no agents and no telemetry - nothing about your clusters or secrets is sent to Kubius or any third party.
How does the RBAC Explorer work?
It resolves effective permissions from your Roles, ClusterRoles and their bindings - both 'what can this subject do' and 'who can do this action' - and shows the binding path behind each grant.
Are secret values exposed by default?
No. Secrets are masked; you reveal values per-key on demand, gated by Touch ID or your device's biometric auth.
Do I need to install anything in the cluster?
No agents, no Helm charts. Read access via your existing kubeconfig is all it needs.