Quick reference: limits and rules
Every number from the other pages, in one place. Web and desktop follow the same limits; rows marked (web) or (desktop) only exist in one of them.
Limits and rules
The same numbers apply on the web and on desktop, unless the row says otherwise.
| Rule | Value |
|---|---|
| Messages per peek (RabbitMQ and Service Bus) | 20 by default, max 100 |
| Message body shown | up to 64 KB |
| Service Bus purge | batches of 250, up to the starting count, at most 50,000 messages or 5 minutes per run, partial result reported; ends after 2 empty 3 s waits |
| Service Bus purge: what stays | scheduled messages and messages locked by a consumer; on a session-enabled entity, only the DLQ is purged |
| Purges per client and service | 5 every 10 minutes |
| Purge confirmation | type the queue name, or topic/subscription |
| Service Bus listing | up to 1,000 queues, 1,000 topics and 1,000 subscriptions per topic |
| RabbitMQ DLQ | x-dead-letter-routing-key on the default exchange, or suffixes .dlq, -dlq, _error |
| Redis keys deleted | 20 per minute per client; several at once ask you to type the count |
| Redis database | 0 to 1023 |
| Redis TTL | positive integer, up to 10 years; editing a string keeps the TTL (PTTL + PX) or sets a new one |
| Redis browser | 100 keys per page (1 to 500); string up to 64 KB; hash and set up to 200 items; list and sorted set 100 per page; stream 50 entries; each item up to 4 KB |
| Redis diagnosis | SLOWLOG: last 25; big keys: 1,000-key sample, shows the 20 largest |
| MongoDB down | no ping answer within 5 s |
| MongoDB slow | ping ≥ 100 ms, operation ≥ 5 s, replica lag ≥ 10 s or cache ≥ 95% |
| MongoDB panel | up to 30 slow operations; top 10 collections; the 10 largest collections in the saved database |
| Timeouts | RabbitMQ and Service Bus (REST API): 15 s per call; Redis: 5 s to connect and 10 s per command; MongoDB: 5 s ping |
| Logs: recent lines (web) | 300 by default, up to 5,000 |
| Live logs (web) | 500 initial lines (up to 5,000), 30 min per session, 5 per person |
| Pod shell (web) | 2 h per session, 3 per person, admin only |
| Node shell (web) | admins of Pro or Team organizations only; type the node name; 1 per person per cluster; counts toward the 3-terminal limit; 2 h per session; pod deleted on close, error, dropped connection or if it does not start within 120 s; Windows, Fargate and virtual-kubelet nodes rejected |
| Node shell (desktop) | waits up to 2 min for the pod to be Running; from 2.7.0, admins only, typed node name, alpine image pinned by digest and at most 2 h |
| AI diagnosis | 20 per person per hour; a 7-day trial per user (on desktop, from 2.7.0), from their first diagnosis that reaches the provider, with up to 30 a day (São Paulo time, web and desktop combined) and a monthly trial quota |
| Bastion (web) | waits up to 120 s for the pod to be Running; at most 2 h; 1 per cluster per person; counts toward the 3-terminal limit; SSH key up to 16 KB; admin only |
| Secure tunnel (desktop) | up to 5 tunnels per mode per cluster; 1 relay per cluster per person, deleted on the last tunnel, at 2 h or when the app quits; 120 s wait; local port on 127.0.0.1 only |
| Scale (web) | 0 to 1,000 replicas |
| Invites (web) | valid for 7 days |
| Leaving the team | on the web, access ends right away; on desktop, paid features stay until the next licence check (within 6 h) |
| Paid plan trial | 14 days, once per organization (on the first subscription) |
| Typed confirmation | web: delete a resource, node shell and purge; desktop: purge and, from 2.7.0, delete, force, finalize, drain, node shell and Helm uninstall |
| Licence (desktop) | checked on sign-in and every 6 hours |
| Offline licence (desktop) | a confirmed Pro or Team licence lasts until the date the server set (7 days after the last check), for every paid feature |
| Dependencies panel (desktop) | Kafka, SQS, PostgreSQL, MySQL and Redis from the container variables (plain value or ConfigMap key); shows only host, port and database; Secret values are never read; envFrom is not included |
| Audit log (web) | 50 entries at a time; up to 90 days per query; CSV up to 10,000 rows (Pro and Team); on Free, your own entries from the last 7 days, no CSV; nothing is deleted automatically |
| Local audit (desktop) | kubepier-audit.log; past 5 MB it becomes kubepier-audit.log.1 (only the previous file is kept); viewer with 100 per page |
| Updates (desktop) | every 12 hours (Windows and Linux) |
| Route through the cluster (web) | 1 relay per organization, cluster and namespace; up to 10 targets; 120 s on first use; 10 s to connect to the service; listeners close after 5 min idle; relay deleted after 10 min idle or at 2 h; retried 30 s after a failure |
| Egress IP list cache | 5 minutes |
| Queue dashboard | refreshes every 15 s (15, 30 or 60 s, or paused); 10 s cache per client and service; up to 1,000 queues; 60 min of history in memory only; after 3 errors in a row, every 60 s |
| Queue dashboard alerts | DLQ 1 to 99 attention, 100 or more critical; DLQ growing over 5 min; a +200 spike between samples less than 60 s apart; no consumption over 10 min; backlog above the queue threshold (1,000 by default) attention, 10 times the threshold critical |
Redis commands
Web and desktop use the same allowlist, checked before every command leaves. Any command outside it is refused. There is no free-form command console.
| Command | Used for | Status |
|---|---|---|
| PING, INFO, DBSIZE | Status, latency, memory, clients, keyspace and the INFO tab | Accepted (read) |
| SELECT | Pick the connection’s database | Accepted (read) |
| SCAN … MATCH … COUNT | Key browser and the big-key sample | Accepted (read) |
| TYPE, TTL, PTTL | Type and expiry of each key | Accepted (read) |
| MEMORY USAGE, MEMORY STATS | Per-key memory and the overview (only these two subcommands) | Accepted (read) |
| STRLEN, GET, GETRANGE | String value; big strings only up to 64 KB | Accepted (read) |
| HLEN, HSCAN | Hash fields, up to 200 | Accepted (read) |
| LLEN, LRANGE | List items | Accepted (read) |
| SCARD, SSCAN | Set members, up to 200 | Accepted (read) |
| ZCARD, ZRANGE … WITHSCORES | Sorted set members, always with scores | Accepted (read) |
| XLEN, XRANGE | Stream entries, up to 50 | Accepted (read) |
| SLOWLOG GET | SLOWLOG tab (command and key, never the values); GET subcommand only | Accepted (read) |
| SET | Write a string: plain SET, or with EX for a new TTL, or with PX to keep the key’s existing TTL (works on any Redis version) | Accepted (write, admin) |
| HSET, HDEL | Write and delete a hash field | Accepted (write, admin) |
| EXPIRE, PERSIST | Set or remove the TTL | Accepted (write, admin) |
| RENAMENX | Rename without overwriting another key | Accepted (write, admin) |
| UNLINK | Delete keys without blocking the server | Accepted (write, admin) |
| FLUSHALL, FLUSHDB | Would wipe the whole database at once | Refused |
| KEYS | Blocks the server on large databases; Kubepier uses SCAN | Refused |
| DEL, RENAME | Have safe versions on the list (UNLINK, RENAMENX) | Refused |
| CONFIG, DEBUG, SHUTDOWN, MIGRATE | Change the configuration, move data or bring the server down | Refused |
| EVAL, EVALSHA, FUNCTION, SCRIPT | Would run arbitrary code on the server | Refused |
| MONITOR | Would show every client’s traffic and values | Refused |
| ACL, CLIENT (including CLIENT KILL) | Touch the server’s users and connections | Refused |
| Other MEMORY and SLOWLOG subcommands (DOCTOR, RESET…) | Beyond what the screen needs | Refused |
| Any other command | There is no free console | Refused |
Write commands only pass in write mode: on the web, in the paid-plan admin routes; on desktop, on the Pro and Team plans (from 2.7.0, admins only). A refused command comes back as "command not allowed" (403 on the web) and never reaches Redis.
On connect, the Redis client also sends AUTH (password or ACL user).
Who can do what
| Action | Plan | Role |
|---|---|---|
| Read clusters, counts and status | Free | Admin and member |
| Live logs, peek messages, panels, Redis browser | Pro and Team | Admin and member |
| Edit, scale, restart, delete, pod and node shell, bastion | Pro and Team | Admin |
| Purge queues, edit and delete keys | Pro and Team | Admin |
| Queue dashboard: counts | Free | Admin and member |
| Queue dashboard: rates, charts and alerts; AI diagnosis | Pro and Team | Admin and member |
| AI diagnosis: 7-day trial per user, no key | Pro and Team | Admin and member |
| A queue’s backlog threshold; the organization’s AI key | Pro and Team | Admin |
| Add clusters, accounts and access | All | Admin |
| Team and invites | Team | Admin |
| Audit log: a 7-day preview of your own entries, no CSV | Free | Admin and member |
| Audit log: the whole organization and CSV | Pro and Team | Admin |
| Audit log: your own entries, on granted clients, and CSV | Pro and Team | Member |
The Role column applies on the web and, from 2.7.0, on desktop; per-client access is web only. On desktop, from 2.7.0, Free also locks the local terminal, creating resources, Helm and Lens Metrics.