Get started with Kubepier Web
Kubepier Web runs at app.kubepier.com.br, in the browser and on your phone, with nothing to install. Your first cluster is on screen in a few minutes.
1. Sign in with GitHub
Open app.kubepier.com.br and sign in with your GitHub account. No new password. On first access, you fill in company, role and team size.
2. Your organization is created on first sign-in
Data lives in an organization, created automatically on your first sign-in; you are its admin and decide who joins later. The plan (Free, Pro or Team) applies to the whole organization.
3. Add the first client
A client owns clusters: the company you serve or an internal team. Give it a name, a color and, optionally, a keyword: a cluster whose name contains the keyword goes to that client.
4. Connect the clusters
- Paste a kubeconfig: works with a token or certificate embedded in the file. Tokens and certificates are encrypted and never come back to the screen.
- Cloud account: add an Azure Service Principal or an AWS IAM key and Kubepier discovers the account’s AKS and EKS clusters, no kubeconfig to copy.
- A context with an exec plugin (kubelogin, aws, gcloud) or a credential in a local file is not imported from the kubeconfig: the screen explains why.
Read-only kubeconfig with a ServiceAccount
To start by just looking, create a ServiceAccount with the view role and a token for it, then build the kubeconfig with that token (the app shows the full script on the clusters screen):
kubectl create namespace kubepier
kubectl -n kubepier create serviceaccount kubepier-leitura
kubectl create clusterrolebinding kubepier-leitura \
--clusterrole=view --serviceaccount=kubepier:kubepier-leitura
kubectl -n kubepier apply -f - <<'EOF'
apiVersion: v1
kind: Secret
metadata:
name: kubepier-leitura-token
annotations:
kubernetes.io/service-account.name: kubepier-leitura
type: kubernetes.io/service-account-token
EOF The Kubernetes view role cannot read Secrets. With it, the Secrets list and the Helm releases (which Helm stores in Secrets) are empty or show a permission error.
5. Open the network, if needed
If the cluster API only accepts some IPs, allow Kubepier Web’s egress IPs. Fully private clusters cannot be reached from the web; use the desktop app for those.
6. Add the client services (optional)
In the client form, enter the access to RabbitMQ, Azure Service Bus, MongoDB and Redis. Each service you add becomes a client menu.