This PR contains the following updates: | Package | Update | Change | |---|---|---| | [k9s](https://github.com/derailed/k9s) | minor | `0.50.7` → `0.51.0` | --- ### Release Notes <details> <summary>derailed/k9s (k9s)</summary> ### [`v0.51.0`](https://github.com/derailed/k9s/releases/tag/v0.51.0) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.51.0 #### Notes Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by big corporations with deep pockets, thus if you feel K9s is helping in your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) *** #### ♫ Sounds Behind The Release ♭ - [Aprieta - Vincen Garcia](https://www.youtube.com/watch?v=ldQ6hpg9BD0\&list=RDldQ6hpg9BD0\&start_radio=1) - [Graham Chapman - John Cleese](https://www.youtube.com/watch?v=Bm2XPkqENaw) - [Kill the pain - SYZGYX](https://www.youtube.com/watch?v=5XuvMhHZorw\&list=RD5XuvMhHZorw\&start_radio=1) *** #### Maintenance Release! Please help me welcome [Ümüt Özalp](https://github.com/uozalp) as a core contributor to K9s! Ümüt has been instrumental in helping this project grow. I trust you will help Ümüt triage issues and prs reviews and show him the kindness and patience all k9sers are famous for! Sponsorships are dropping at an alarming rate which puts this project in the red. This is becoming a concern and sad not to mention unsustainable ;( If you dig `k9s` and want to help the project, please consider `paying it forward!` and don't become just another `satisfied, non paying customer!`. K9s does take a lot of my `free` time to maintain, enhance and keep the light on. Many cool ideas are making it straight to the `freezer` as I just can't budget them in. I know many of you work for big corporations, so please put in the word/work and have them help us out via sponsorships or other means. Thank you! *** #### Contributed PRs Please be sure to give `Big Thanks!` and `ATTA Girls/Boys!` to all the fine contributors for making K9s better for all of us!! - [#​4026](https://github.com/derailed/k9s/pull/4026) fix(xray): disable edit/delete actions in XRay view when readonly mode is enabled - [#​4024](https://github.com/derailed/k9s/pull/4024) Fix 'J'umping to owner of cluster scoped resources - [#​4005](https://github.com/derailed/k9s/pull/4005) Fix pod status for sidecar init containers - [#​4001](https://github.com/derailed/k9s/pull/4001) Adjust namespace handling for RBAC checks in CanForResource and CanForInstance - [#​3997](https://github.com/derailed/k9s/pull/3997) chore: fix wrong function name in comment - [#​3993](https://github.com/derailed/k9s/pull/3993) fix(browser): show syncing status instead of spurious no-resources warning - [#​3989](https://github.com/derailed/k9s/pull/3989) perf: skip reconcile cycle when informer data is unchanged - [#​3988](https://github.com/derailed/k9s/pull/3988) perf: raise default client QPS from 5 to 50 - [#​3987](https://github.com/derailed/k9s/pull/3987) fix: paginate metrics API calls to prevent timeout on large clusters - [#​3986](https://github.com/derailed/k9s/pull/3986) perf: batch Hydrate workers to eliminate per-item goroutine overhead - [#​3917](https://github.com/derailed/k9s/pull/3917) Respect wide columns in default view - [#​3911](https://github.com/derailed/k9s/pull/3911) fix: reset styles before loading skin on context switch - [#​3908](https://github.com/derailed/k9s/pull/3908) fix: populate pod count in Node.Get() for single-node view - [#​3902](https://github.com/derailed/k9s/pull/3902) Add OSC52 clipboard backend with native fallback - [#​3888](https://github.com/derailed/k9s/pull/3888) feat: add One Light skin - [#​3879](https://github.com/derailed/k9s/pull/3879) feat: allow users to cycle pulse grid selection forwards and backwards - [#​3873](https://github.com/derailed/k9s/pull/3873) feat: enhance pvc-shell configuration with dynamic inputs and RWO support - [#​3872](https://github.com/derailed/k9s/pull/3872) Add default confirm:true for plugins with inputs - [#​3871](https://github.com/derailed/k9s/pull/3871) internal/render: prevent index out of range panic in initContainerStats - [#​3865](https://github.com/derailed/k9s/pull/3865) Handle blank PVC capacities for the purpose of sorting - [#​3854](https://github.com/derailed/k9s/pull/3854) feat: enhance debug container configuration with input fields - [#​3851](https://github.com/derailed/k9s/pull/3851) Use \*grey instead of grey in black-and-wtf.yaml - [#​3839](https://github.com/derailed/k9s/pull/3839) fix: optimize context switching to reduce redundant API calls - [#​3823](https://github.com/derailed/k9s/pull/3823) feat: add resize PVC plugin for dynamic storage resizing - [#​3821](https://github.com/derailed/k9s/pull/3821) feat: add support for plugin input fields - [#​3817](https://github.com/derailed/k9s/pull/3817) Fix Readme: Ubuntu installation command not working - [#​3798](https://github.com/derailed/k9s/pull/3798) Fix boom on Jumping Owner in rare cases - [#​3797](https://github.com/derailed/k9s/pull/3797) feat: add extra hints for column navigation in table view - [#​3792](https://github.com/derailed/k9s/pull/3792) fix: adjust resource access checks for namespace resources - [#​3783](https://github.com/derailed/k9s/pull/3783) fix: avoid logging errors when no context is configured - [#​3780](https://github.com/derailed/k9s/pull/3780) feat: add selected color to table header - [#​3736](https://github.com/derailed/k9s/pull/3736) feat: add custom resource jump support - [#​3634](https://github.com/derailed/k9s/pull/3634) Add shell detection for Windows NanoServer containers *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2026 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# ### [`v0.50.18`](https://github.com/derailed/k9s/releases/tag/v0.50.18) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.50.18 #### Notes 🥳🎉 Happy new year fellow k9ers!🎊🍾 Hoping 2026 will bring good health and great success to you and yours... Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by big corporations with deep pockets, thus if you feel K9s is helping in your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) *** #### ♫ Sounds Behind The Release ♭ - [A cool new way - Joe Satriani](https://www.youtube.com/watch?v=4apA948yOF0) - [Song for you - Ray Charles](https://www.youtube.com/watch?v=CzAkTrDiXxg) - [Kill the pain - SYZGYX](https://www.youtube.com/watch?v=5XuvMhHZorw\&list=RD5XuvMhHZorw\&start_radio=1) *** #### Maintenance Release! Oops! I've missed a PR in the v0.50.17 excitement ;( Dropping v0.50.18 with feelings... Sponsorships are dropping at an alarming rate which puts this project in the red. This is becoming a concern and sad not to mention unsustainable ;( If you dig `k9s` and want to help the project, please consider `paying it forward!` and don't become just another `satisfied, non paying customer!`. K9s does take a lot of my `free` time to maintain, enhance and keep the light on. Many cool ideas are making it straight to the `freezer` as I just can't budget them in. I know many of you work for big corporations, so please put in the word/work and have them help us out via sponsorships or other means. Thank you! *** #### A Word From Our Sponsors... To all the good folks and orgs below that opted to `pay it forward` and join our sponsorship program, I salute you!! - [Philomena Yeboah](https://github.com/PhilomenaYeboah1989) - [Kilian](https://github.com/kaerbr) - [TVRiddle](https://github.com/TVRiddle) - [Tom Morelly](https://github.com/FalcoSuessgott) - [Nikhil Narayen](https://github.com/nnarayen) - [Andrew Aadland](https://github.com/DaemonDude23) - [Radek](https://github.com/radvym) - [Timothée Gerber](https://github.com/TimotheeGerber) - [Matthias](https://github.com/maetthu) - [DKB](https://github.com/dkb-bank) ❤️ - [Kraken Tech](https://github.com/kraken-tech) - [Daniel](https://github.com/sherlock7402) - [Fred Loucks](https://github.com/fullmetal-fred) - [Patricia Mascaros](https://github.com/ccong2586) - [Qube Research & Technologies](https://github.com/qube-rt) - [Michel Jung](https://github.com/micheljung) - [Ümüt Özalp](https://github.com/uozalp) - [Nathan Papapietro](https://github.com/npapapietro) - [Oleksandr Podze](https://github.com/dasdy) - [Lee Jones](https://github.com/leejones) - [tsahlif](https://github.com/tshalif) - [Jean-Christophe Amiel](https://github.com/jcamiel) - [Lightspark](https://github.com/lightsparkdev) - [egs-hub](https://github.com/egs-hub) ❤️ - [Sergey](https://github.com/malsatin) - [Wynter Inc](https://github.com/copytesting) - [Jen Norris](https://github.com/tnorris) - [Joakim-Byg](https://github.com/Joakim-Byg) - [Oleksandr Podze](https://github.com/dasdy) - [Lee Jones](https://github.com/leejones) > Sponsorship cancellations since the last release: **17!** 🥹 #### Resolved Issues - [#​3765](https://github.com/derailed/k9s/issues/3765) quay.io docker images not up to date but referenced in README.md - [#​3762](https://github.com/derailed/k9s/issues/3762) Copy multiple selected items - [#​3751](https://github.com/derailed/k9s/issues/3751) Improve visual distinction for cordoned nodes in Node view - [#​3735](https://github.com/derailed/k9s/issues/3735) Cannot decode secret if there is no get permissions for all secrets - [#​3708](https://github.com/derailed/k9s/issues/3708) Editing a single Namespace opens the editor with a list of all Namespaces - [#​3731](https://github.com/derailed/k9s/issues/3731) feat: add neat plugin - [#​3735](https://github.com/derailed/k9s/issues/3735) Cannot decode secret if there is no get permissions for all secrets - [#​3708](https://github.com/derailed/k9s/issues/3708) Editing a single Namespace opens the editor with a list of all Namespaces - [#​3649](https://github.com/derailed/k9s/issues/3649) Improved Column Sorting *** #### Contributed PRs Please be sure to give `Big Thanks!` and `ATTA Girls/Boys!` to all the fine contributors for making K9s better for all of us!! - [#​3763](https://github.com/derailed/k9s/pull/3763) feat: enable copying multiple resource, namespace names to clipboard - [#​3760](https://github.com/derailed/k9s/pull/3760) fix: Editing a single Namespace opens the editor with a list of all Namespaces - [#​3756](https://github.com/derailed/k9s/pull/3756) feat: Add reconcile plugin for Flux instances - [#​3755](https://github.com/derailed/k9s/pull/3755) fix: panic on 'jump to owner' of reflect.Value.Elem on zero Value - [#​3753](https://github.com/derailed/k9s/pull/3553) feat: add plugins for argo workflows - [#​3750](https://github.com/derailed/k9s/pull/3750) fix: Flux trace plugin shortcut conflict by changing to Shift-Q - [#​3749](https://github.com/derailed/k9s/pull/3749) feat: add dark/light theme inversion using Oklch - [#​3739](https://github.com/derailed/k9s/pull/3739) chore: refine LabelsSelector comment to match function behavior - [#​3738](https://github.com/derailed/k9s/pull/3738) feat: add symlink handle for plugin directory - [#​3720](https://github.com/derailed/k9s/pull/3720) fix(internal/render): ensure object is deep copied before realization in Render method - [#​3704](https://github.com/derailed/k9s/pull/3704) Allow k9s to start without a valid Kubernetes context - [#​3699](https://github.com/derailed/k9s/pull/3699) feat(pulse): map hjkl to navigate as help shows - [#​3697](https://github.com/derailed/k9s/pull/3697) Issue 3667 Fix - [#​3696](https://github.com/derailed/k9s/pull/3696) fix for scale option appearing on non-scalable resources - [#​3690](https://github.com/derailed/k9s/pull/3690) feat: add support for scaling HPA targets - [#​3671](https://github.com/derailed/k9s/pull/3671) fix fails to modify or delete namespaces using RBAC - [#​3669](https://github.com/derailed/k9s/pull/3669) feat: logs column lock - [#​3663](https://github.com/derailed/k9s/pull/3663) Map Q to "Back" - [#​3661](https://github.com/derailed/k9s/pull/3661) refactor: remove unused sorting key bindings from various views - [#​3859](https://github.com/derailed/k9s/pull/3859) fix: update busybox image version to 1.37.0 in configuration files - [#​3650](https://github.com/derailed/k9s/pull/3650) Sort all columns - [#​3458](https://github.com/derailed/k9s/pull/3458) Document how to install on Fedora *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2026 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# ### [`v0.50.16`](https://github.com/derailed/k9s/releases/tag/v0.50.16) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.50.16 #### Notes Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by big corporations with deep pockets, thus if you feel K9s is helping in your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) #### Maintenance Release! Sponsorships are dropping at an alarming rate which puts this project in the red. This is becoming a concern and sad not to mention unsustainable ;( If you dig `k9s` and want to help the project, please consider `paying it forward!` and don't become just another `satisfied, non paying customer!`. K9s does take a lot of my `free` time to maintain, enhance and keep the light on. Many cool ideas are making it straight to the `freezer` as I just can't budget them in. I know many of you work for big corporations, so please put in the word/work and have them help us out via sponsorships or other means. Thank you! ##### Warp Speed Scotty! As of this drop, we are introducing `namespace warp` via shortcut `w`. This affords to view all resources of that type based on the currently selected resource namespace. This command is only available on namespaced resources. For example, if you are in pod view and select pod-xxx in namespace `bozo`, hitting `w` will `warp` you to view all pods in namespace `bozo`. #### Resolved Issues - [#​3629](https://github.com/derailed/k9s/issues/3629) vulnerability in k9s project - [#​3621](https://github.com/derailed/k9s/issues/3621) Switching to ":Deploy" sends you to deployments from namespace "deploy" - [#​3620](https://github.com/derailed/k9s/issues/3620) Trying to show pod yaml using custom views.yaml crashes k9s - [#​3608](https://github.com/derailed/k9s/issues/3608) k9s crashes when :namespaces used - [#​3601](https://github.com/derailed/k9s/issues/3601) Can't delete namespace - [#​3595](https://github.com/derailed/k9s/issues/3595) Toggle Namespace Filter in Pods View with 'n' Key - [#​3576](https://github.com/derailed/k9s/issues/3576) Custom alias/view not working anymore since v0.50.10 *** #### Contributed PRs Please be sure to give `Big Thanks!` and `ATTA Girls/Boys!` to all the fine contributors for making K9s better for all of us!! - [#​3625](https://github.com/derailed/k9s/pull/3625) fix: debug-container plugin when KUBECONFIG has multiple files - [#​3623](https://github.com/derailed/k9s/pull/3623) bugfix: fix panic in BenchmarkPodRender by using NewPod() constructor - [#​3619](https://github.com/derailed/k9s/pull/3619) feat: plugin to list all resources by namespace - [#​3605](https://github.com/derailed/k9s/pull/3605) browser: do not prevent redraw when connection unavailable - [#​3600](https://github.com/derailed/k9s/pull/3600) fix(shell): set linux when OS detection fails - [#​3588](https://github.com/derailed/k9s/pull/3588) fix: do not error out of shellIn if OS detection fails *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2025 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# ### [`v0.50.15`](https://github.com/derailed/k9s/releases/tag/v0.50.15) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.50.15 #### Notes Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by big corporations with deep pockets, thus if you feel K9s is helping in your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) #### Maintenance Release! Sponsorships are dropping at an alarming rate which puts this project in the red. This is becoming a concern and sad not to mention unsustainable ;( If you dig `k9s` and want to help the project, please consider `paying it forward!` and don't become just another `satisfied, non paying customer!`. K9s does take a lot of my `free` time to maintain, enhance and keep the light on. Many cool ideas are making it straight to the `freezer` as I just can't budget them in. I know many of you work for big corporations, so please put in the word/work and have them help us out via sponsorships or other means. Thank you! #### Resolved Issues - [#​3591](https://github.com/derailed/k9s/issues/3591) REVERTED! Accept suggestion with enter (without having to "tab") *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2025 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# ### [`v0.50.13`](https://github.com/derailed/k9s/releases/tag/v0.50.13) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.50.13 #### Notes Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by corps with deep pockets, thus if you feel K9s is helping your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) #### Maintenance Release! #### Resolved Issues - [#​3587](https://github.com/derailed/k9s/issues/3587) UI doesn't show any updates when restarting a Deployment - [#​3585](https://github.com/derailed/k9s/issues/3585) abbreviation sec for secret not working - [#​3584](https://github.com/derailed/k9s/issues/3584) Show managed fields doesn't show them - [#​3583](https://github.com/derailed/k9s/issues/3583) Cannot open shell to pods without node read access as of 0.50.12 - [#​3577](https://github.com/derailed/k9s/issues/3577) Log view is broken as of v0.50.10 - [#​3574](https://github.com/derailed/k9s/issues/3574) Aliases for pods with label filters not working *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2025 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# ### [`v0.50.12`](https://github.com/derailed/k9s/releases/tag/v0.50.12) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.50.12 #### Notes Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by corps with deep pockets, thus if you feel K9s is helping your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) #### Maintenance Release! #### Resolved Issues - [#​3570](https://github.com/derailed/k9s/issues/3570) 0.50.11 could not display any resources - [#​3562](https://github.com/derailed/k9s/issues/3562) Can't delete namespace - [#​3547](https://github.com/derailed/k9s/issues/3547) Error message from admission controller *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2025 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# ### [`v0.50.9`](https://github.com/derailed/k9s/releases/tag/v0.50.9) <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/k9s.png" align="center" width="800" height="auto"/> ### Release v0.50.9 #### Notes Thank you to all that contributed with flushing out issues and enhancements for K9s! I'll try to mark some of these issues as fixed. But if you don't mind grab the latest rev and see if we're happier with some of the fixes! If you've filed an issue please help me verify and close. Your support, kindness and awesome suggestions to make K9s better are, as ever, very much noted and appreciated! Also big thanks to all that have allocated their own time to help others on both slack and on this repo!! As you may know, K9s is not pimped out by corps with deep pockets, thus if you feel K9s is helping your Kubernetes journey, please consider joining our [sponsorship program](https://github.com/sponsors/derailed) and/or make some noise on social! [@​kitesurfer](https://twitter.com/kitesurfer) On Slack? Please join us [K9slackers](https://join.slack.com/t/k9sers/shared_invite/zt-3360a389v-ElLHrb0Dp1kAXqYUItSAFA) #### Maintenance Release! *** #### Resolved Issues - [#​3459](https://github.com/derailed/k9s/issues/3459) Update the tablewriter dependency + implementation - [#​3458](https://github.com/derailed/k9s/issues/3458) Unable to switch namespaces with 0.50.8 *** #### Contributed PRs Please be sure to give `Big Thanks!` and `ATTA Girls/Boys!` to all the fine contributors for making K9s better for all of us!! - [#​3460](https://github.com/derailed/k9s/pull/3460) update to tablewriter v1 apis *** <img src="https://raw.githubusercontent.com/derailed/k9s/master/assets/imhotep_logo.png" width="32" height="auto"/> © 2025 Imhotep Software LLC. All materials licensed under [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0)# </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/35 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> Co-committed-by: gitea_admin <admin@forteapps.net>
Kubernetes Cluster - GitOps Configuration
Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)
📚 Complete Documentation
New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:
🎯 START HERE: Documentation Index
| Document | Description | Audience |
|---|---|---|
| GitOps Architecture | System architecture, repository structure, GitOps workflows, security model | Everyone (start here) |
| Developer Guide | Local setup, deploying apps, managing secrets, troubleshooting | Developers |
| Operations Runbook | Cluster bootstrap, day-to-day operations, incident response, maintenance | Platform Engineers, SREs |
| Technical Reference | Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs | Everyone (reference) |
🚀 Quick Start
For New Developers
# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git
# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md
# 3. Deploy your first app (see Developer Guide)
For Operators
# 1. Bootstrap new cluster
./bootstrap.sh
# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces
# 3. Read Operations Runbook for day-to-day tasks
📋 Overview
This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.
What's Inside
- Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
- Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
- Policies: Kyverno security policies for secret management, namespace controls, pod verification
- Monitoring: Full observability stack with metrics, logs, traces, and alerting
- Secrets: Sealed Secrets for secure Git storage
Key Features
✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration
🗂️ Repository Structure
.
├── bootstrap.sh # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/ # Infrastructure provisioning (OpenTofu)
│ ├── platforms/ # Per-platform IaC (one dir per cloud)
│ │ ├── aks/ # Azure AKS (modules/ + dev/ + prod/ + workload/)
│ │ ├── eks/ # AWS EKS
│ │ ├── gke/ # GCP GKE
│ │ └── upc/ # UpCloud
│ ├── configs/ # Platform credentials (git-ignored)
│ │ └── *.env.example # Template for each platform
│ └── scripts/ # Cluster lifecycle scripts
│ ├── setup-cluster.sh # Create cluster: ./setup-cluster.sh aks-dev
│ ├── teardown-cluster.sh
│ └── get-kubeconfig.sh
│
├── clusters/ # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/ # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│ ├── base/ # Base ArgoCD Application manifests (one dir per component)
│ │ ├── kustomization.yaml # Aggregates all component subdirectories
│ │ ├── traefik-application/
│ │ │ ├── kustomization.yaml
│ │ │ └── traefik-application.yaml
│ │ ├── keycloak/
│ │ │ ├── kustomization.yaml
│ │ │ └── keycloak.yaml
│ │ ├── grafana/
│ │ ├── prometheus/
│ │ ├── ... # Each component in its own subdirectory
│ │ └── secrets/
│ ├── overlays/ # Per-cluster overrides (Kustomize)
│ │ ├── upc-dev/ # UpCloud Dev — includes all base components
│ │ ├── upc-prod/ # UpCloud Prod — all components + patches
│ │ ├── aks-dev/ # Azure AKS Dev — selective components only
│ │ ├── aks-prod/ # Azure AKS Prod
│ │ ├── eks-dev/ # AWS EKS Dev
│ │ ├── eks-prod/ # AWS EKS Prod
│ │ ├── gke-dev/ # GCP GKE Dev
│ │ └── gke-prod/ # GCP GKE Prod
│ ├── dashboards/ # Grafana dashboard ConfigMaps
│ └── values/ # Helm value overrides
│ ├── base/ # Shared cloud-agnostic values
│ ├── upc-dev/ # UpCloud Dev (storage, LB, pricing)
│ ├── upc-prod/ # UpCloud Prod
│ ├── eks-dev/ # AWS EKS Dev
│ ├── eks-prod/ # AWS EKS Prod
│ ├── aks-dev/ # Azure AKS Dev
│ ├── aks-prod/ # Azure AKS Prod
│ ├── gke-dev/ # GCP GKE Dev
│ └── gke-prod/ # GCP GKE Prod
│
├── apps/ # Business Applications (Kustomize, same pattern as infra)
│ ├── base/ # One subdirectory per app
│ │ ├── kustomization.yaml
│ │ ├── musicman/
│ │ ├── mcp10x/
│ │ ├── dot-ai-stack/
│ │ ├── ts-mcp/
│ │ └── argo-mcp/
│ └── overlays/ # Per-cluster: cherry-pick or include all
│ ├── upc-dev/ # All apps
│ ├── upc-prod/ # All apps + patches
│ └── aks-dev/ # Selective apps only
│
├── cluster-resources/ # Cluster-wide Kubernetes resources
│ ├── letsencrypt-issuer.yaml
│ ├── kyverno-config.yaml
│ ├── *-sealed.yaml # Sealed secrets
│ └── policies/ # Kyverno policies
│ ├── secret-cloner.yaml
│ ├── default-ns-blocker.yaml
│ ├── bare-pod-cleaner.yaml
│ └── auth-sidecar-injector.yaml
│
├── secrets/ # Application secrets (sealed)
│ └── *-credentials-sealed.yaml
│
├── private/ # Local-only files (Git-ignored)
│ └── *.yaml # Unsealed secrets (never committed)
│
└── docs/ # 📚 Comprehensive documentation
├── README.md # Documentation index
├── GITOPS-ARCHITECTURE.md # Architecture guide
├── DEVELOPER-GUIDE.md # Developer onboarding
├── OPERATIONS-RUNBOOK.md # Operations procedures
└── REFERENCE.md # Technical reference
See GitOps Architecture - Repository Structure for detailed explanation.
🏗️ Architecture
Three-Repository Pattern
| Repository | Purpose | Who Edits | How Often |
|---|---|---|---|
| launchpad (this repo) | ArgoCD Applications, cluster resources | Platform / DevOps engineers | ✅ Often |
| forte-helm | Generic Helm chart templates | Platform engineers | ❌ Rarely |
| helm-prod-values | App-specific configuration & versions | Developers / CI pipelines | ✅ Sometimes |
GitOps Workflow
Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster
Learn more: GitOps Architecture - GitOps Workflow
🔧 Common Tasks
Deploy a New Application
See detailed guide: Developer Guide - Deploying Your First Application
Quick version:
- Create
apps/myapp.yaml(ArgoCD Application manifest) - Create
helm-prod-values/myapp/values.yaml(configuration) - Create sealed secrets if needed
- Commit and push - ArgoCD auto-syncs!
Update an Existing Application
See detailed guide: Developer Guide - Updating an Existing Application
Quick version:
- Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
- Update config: Edit
helm-prod-values/myapp/values.yaml→ commit → push
Manage Secrets
See detailed guide: Developer Guide - Working with Secrets
# Create plain secret
kubectl create secret generic myapp-creds \
--from-literal=KEY=value \
--dry-run=client -o yaml > private/myapp-creds.yaml
# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
< private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml
# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push
Enable Authentication
See detailed guide: Developer Guide - Enabling Authentication
Quick version:
# In helm-prod-values/myapp/values.yaml
# Token-based auth (simple)
auth:
enabled: true
type: token
tokens:
- your-secret-token-here
# OIDC auth (SSO)
auth:
enabled: true
type: oidc
oidc:
authority: https://auth.example.com/realms/master
clientId: myapp
Then create OIDC secret (if using OIDC):
kubectl create secret generic auth-oidc \
--from-literal=client-secret=your-oidc-secret \
--from-literal=cookie-secret=$(openssl rand -hex 32) \
--namespace=myapp | \
kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
kubectl apply -f -
Bootstrap Cluster
See detailed guide: Operations Runbook - Cluster Bootstrap
# Initialize new cluster
./bootstrap.sh
# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces
🛠️ Quick Reference
Monitor Applications
# List all ArgoCD applications
kubectl get applications -n argocd
# Watch sync status
kubectl get applications -n argocd -w
# Check specific application
kubectl describe application myapp -n argocd
# View application logs
kubectl logs -n myapp <pod-name>
Access UIs
# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)
# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000
# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090
Troubleshooting
# Check pod status
kubectl get pods -n myapp
# View pod logs
kubectl logs -n myapp <pod-name>
# Check pod events
kubectl describe pod -n myapp <pod-name>
# Check ArgoCD sync errors
kubectl describe application myapp -n argocd
# Force sync
kubectl patch application myapp -n argocd \
--type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'
Full troubleshooting guide: Developer Guide - Troubleshooting
🔐 Security
Secret Management
- ✅ Sealed Secrets for Git storage
- ✅ Kyverno auto-clones secrets to namespaces
- ❌ Never commit plain secrets
Network Security
- ✅ All traffic TLS-encrypted (Let's Encrypt)
- ✅ HTTP → HTTPS redirect
- ✅ Traefik IngressRoute per application
Policy Enforcement
- ✅ Kyverno policies for security
- ✅ Default namespace blocked
- ✅ Bare pods not allowed
- ✅ Optional authentication sidecar injection
Learn more: GitOps Architecture - Security Model
📊 Infrastructure Components
| Component | Purpose | Namespace | Replicas |
|---|---|---|---|
| ArgoCD | GitOps controller | argocd |
1 |
| Traefik | Ingress controller | traefik |
2 |
| Cert-Manager | TLS certificates | cert-manager |
1 |
| Kyverno | Policy engine | kyverno |
1 |
| Sealed Secrets | Secret encryption | kube-system |
1 |
| Prometheus | Metrics | monitoring |
1 |
| Grafana | Dashboards | monitoring |
1 |
| Loki | Logs | monitoring |
1 |
| Tempo | Distributed tracing | monitoring |
1 |
| Fluent-Bit | Log shipping | monitoring |
DaemonSet |
| OpenCost | Cost monitoring | monitoring |
1 |
| Renovate | Dependency updates | renovate |
CronJob |
Full specs: Technical Reference - Infrastructure Components
🌐 Domains & Networking
- Local development:
*.127.0.0.1.nip.io - Production:
*.forteapps.net - DNS: Manual configuration (contact platform team)
- TLS: Automatic via Let's Encrypt
📖 Key Concepts
App-of-Apps Pattern
_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.
Multi-Source Pattern
Applications reference both:
- Helm charts from
forte-helm(templates) - Values from
helm-prod-values(configuration)
This separates reusable templates from environment-specific config.
Sync Waves
Applications deploy in order using argocd.argoproj.io/sync-wave:
- Wave
-1: Namespaces - Wave
0: Kyverno (policies) - Wave
1: Infrastructure - Wave
2+: Applications
Auto-Sync & Self-Heal
- Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
- Self-Heal: Manual cluster changes are reverted to match Git
- Prune: Deleted resources in Git are removed from cluster
Learn more: GitOps Architecture - GitOps Workflow
⚙️ Configuration
ArgoCD Settings
- Reconciliation: Every 60 seconds
- Sync timeout: 5 minutes per application
- Retry policy: 5 attempts with exponential backoff
- Authentication: Disabled (internal use only)
Application Defaults
- Auto-sync: Enabled
- Self-heal: Enabled
- Prune: Enabled
- Validation: Server-side validation enabled
- Server-side apply: Enabled
Full configuration: Technical Reference - ArgoCD Configuration
🆘 Getting Help
Documentation
- Start here: Documentation Index
- For development: Developer Guide
- For operations: Operations Runbook
- For reference: Technical Reference
Support
- Slack: #platform-support
- Issues: Contact platform team
- Emergencies: Escalate via Slack
Common Questions
| Question | Answer |
|---|---|
| How do I deploy an app? | Developer Guide - Deploying Your First Application |
| How do I manage secrets? | Developer Guide - Working with Secrets |
| App won't sync? | Developer Guide - Troubleshooting |
| How do I bootstrap a cluster? | Operations Runbook - Cluster Bootstrap |
| Where are the logs? | Operations Runbook - Monitoring & Alerting |
🤝 Contributing
Adding a New Application
- Read Developer Guide - Deploying Your First Application
- Create ArgoCD Application manifest in
apps/ - Create Helm values in
helm-prod-values/ - Create sealed secrets if needed
- Commit and push - ArgoCD handles the rest!
Modifying Infrastructure
- Read Operations Runbook
- Update relevant files in
infra/orcluster-resources/ - Test changes in isolated namespace if possible
- Commit and push
- Monitor sync status in Slack/ArgoCD UI
Updating Documentation
Documentation lives in docs/. To update:
- Edit relevant markdown file
- Update "Last Updated" date
- Submit PR or push directly
- Notify team of significant changes
📝 Notes
Current Environment
- Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
- Active clusters: UpCloud (upc-dev, upc-prod)
- Environment: Production (internal use only)
- Auth: Disabled for ArgoCD (internal access)
- Backup: Gitea daily backup to S3-compatible storage
Known Limitations
- Secret rotation not automated
- DNS management is manual
Future improvements: See Operations Runbook - Disaster Recovery
📚 Additional Resources
External Documentation
- ArgoCD Documentation
- Kyverno Documentation
- Traefik Documentation
- Cert-Manager Documentation
- Grafana Tempo Documentation
- Sealed Secrets
Related Repositories
- forte-helm - Helm chart templates
- helm-prod-values - Application values
📄 License
Internal use only. Not for public distribution.
👥 Maintainers
Platform Team
- Contact: #platform-support on Slack
- Issues: Create issue in repository or contact team directly
Last Updated: 2026-04-22 Documentation Version: 1.0.0
🚀 Ready to get started? Check out the Documentation Index!