Clusters · Web and Desktop · Pro and Team

Kubernetes AI diagnosis

On the pod screen, Kubepier’s AI diagnosis explains a CrashLoopBackOff or another failure from the pod status, recent events and the latest log lines, after removing secrets. On Pro and Team (14-day free trial included), each user gets 7 days of AI with no key to set up; after that, they keep going with their own Anthropic or OpenAI key. The AI analyses screen lists the cluster’s failing pods so you can diagnose them in one place. Free has no AI. It works on Kubepier Web and Kubepier Desktop (on desktop, the 7-day trial and the AI analyses screen arrive in version 2.7.0).

Where
Web and Desktop (AI from 2.2.0; trial and AI analyses from 2.7.0)
Plans
Pro and Team (7 days with no key, then your own)
Role
Web: admins set the key; anyone who sees the client can diagnose

What the AI does in a pod diagnosis

When you ask for a diagnosis, Kubepier builds the pod context, removes secrets and personal data and asks the model for a short explanation of what is probably wrong and what to look into.

7-day trial on Pro and Team

  • In a Pro or Team organization, including during the plan’s 14-day free trial, each user gets 7 days of AI diagnosis with no key to set up: Kubepier uses TR’s OpenAI key, with the gpt-4o-mini model.
  • The Free plan has no AI diagnosis: the button shows a lock and the upgrade notice.
  • The 7 days belong to each user and start with the first diagnosis that reaches the provider.
  • During the trial, each user can run up to 30 diagnoses a day (São Paulo time, web and desktop combined), on top of the general cap of 20 per hour.
  • The trial has a monthly quota shared by all users. If it runs out, the trial pauses until the next month, with the notice "The AI trial monthly quota is used up and comes back next month. Pro and Team subscribers can use their own API key."
  • A Pro or Team organization with its own key set uses that key and does not use up the trial.
  • It works on the web and, from version 2.7.0, on desktop. On desktop 2.7.0, signed in to a Pro or Team organization without your own key, the diagnosis goes through the Kubepier API, with the context already redacted in the app and redacted again on the server.
  • During the trial, the pod status always goes to OpenAI with TR’s key. Events and logs only go after the preview, which has a "Send without events and logs" option. Kubepier neither stores the text sent nor the answer.
  • After the 7 days, just add your own Anthropic or OpenAI key: the organization’s on the web, your own on desktop (from 2.7.0, without your own key, the desktop app uses the organization’s through the Kubepier API). If the organization goes back to Free, AI is locked again.

AI analyses screen

  • In the cluster menu, on the web and, from 2.7.0, on desktop, the AI analyses screen lists the cluster’s failing pods, each with a Diagnose with AI button.
  • It also shows the history of your analyses. That history stays only in your browser (web) or on your computer (desktop): Kubepier does not store the text sent or the answer.
  • Clearing browser data or switching machines deletes the history; it is not shared with the team.

What is sent

  • Always: the pod name, namespace, phase, conditions, owner (Deployment, Job…) and node; for each container, the image as name:tag only (no registry), the state, reason, message, exit code, last termination, restarts and whether it is ready.
  • The names of each container’s environment variables, never the values.
  • Only after the preview (during the trial) or with consent on and the preview (with your own key): pod events from the last 60 minutes, up to 20; the last 100 log lines of up to 3 containers; and the last 50 lines of the previous instance when the container restarted.
  • Events and logs fit in 16 KB after redaction; the oldest lines are cut first.
  • Environment variable values, Secrets and the kubeconfig are not sent.

What is removed before sending

Web and desktop use the same list, in the same order. Each match becomes [REDACTED:<type>]:

  • 1. A whole PEM private key (RSA, EC, OpenSSH, PKCS#8, encrypted), even when cut off.
  • 2. JWTs (eyJ… with three parts).
  • 3. The token after Bearer (the word Bearer stays).
  • 4. AWS access key IDs (AKIA…, ASIA…) and the secret access key after aws_secret….
  • 5. Azure keys in connection strings (AccountKey=, SharedAccessKey=, SharedAccessSignature=) and the sig= signature of SAS URLs.
  • 6. Password= and Pwd= in key=value; connection strings.
  • 7. User and password inside URLs (scheme://user:password@host).
  • 8. Values of fields whose name looks like a secret (password, secret, token, api key, access key, private key, client secret), in JSON, env, YAML, query strings or headers.
  • 9. E-mail addresses.
  • 10. IPv4 and IPv6 addresses.
  • 11. Hexadecimal strings of 32 characters or more.
  • 12. Base64-looking strings of 40 characters or more.

Consent and preview

  • During the 7-day trial, events and logs only go after the preview of the exact text, already redacted; the "Send without events and logs" option sends only the status.
  • With the organization’s key or your own, the "Send events and logs to the AI" option starts off: without it, only the status goes.
  • With it on, the first time shows a preview of the exact text that will be sent, already redacted, with the options to send everything, send only the status or cancel.
  • Web: consent belongs to the organization (an admin turns it on) and the preview shows on each person’s first time. The text sent is the same as the preview.
  • Desktop: consent is yours, in the AI preferences; ticking "do not show again" when sending skips the preview next time.

The key

  • 7-day trial: no key is needed. The diagnosis uses TR’s OpenAI key, which stays on Kubepier’s server.
  • Web, after the trial: the organization sets the provider (Anthropic or OpenAI) and the key; only admins configure it. The key is encrypted with AES-256-GCM and never comes back to the screen.
  • Desktop, after the trial: your key lives in the OS keychain; without your own key, from 2.7.0, the desktop app uses the organization’s through the Kubepier API. Without a keychain, it stays in memory until the app closes. Keys earlier versions kept unencrypted in the preferences are moved into the keychain, and the unencrypted copy is deleted.

Limits and timeouts

  • 20 diagnoses per person per hour.
  • During the 7-day trial, also 30 per user per day (São Paulo time, web and desktop combined) and a monthly trial quota shared by all users.
  • With your own key, the call is billed to your provider account. During the trial, TR pays for it.

Audit and privacy

  • Each diagnosis goes to the audit log (database on the web; kubepier-audit.log on desktop), with who, when, cluster and pod, no content. During the trial, the entry is marked as using the trial key, with its origin (web or desktop).
  • Kubepier neither stores nor logs the text sent or the answer.
  • Web: the request goes through Kubepier’s server to the provider.
  • Desktop: with your own key in the OS keychain, the request goes straight from your machine to the provider. From 2.7.0, signed in to a Pro or Team organization without your own key, it goes through the Kubepier API to OpenAI (during the trial) or to the organization’s provider (with its key), with the context redacted in the app and again on the server.

What is not accepted

  • The Free plan: AI diagnosis is for Pro and Team.
  • Pro and Team with no key set for the chosen provider, after the 7-day trial.
  • More than 20 diagnoses per hour or, during the trial, more than 30 in a day.
  • During the trial, with the monthly quota used up: it pauses until the next month.
  • On desktop, the 7-day trial needs a signed-in account and version 2.7.0 or newer. Versions before 2.2.0 only send the status, with the key in the preferences.