The self-hosted Kubernetes SRE platform

See what's broken.
Know why.
Fix it safely.

A full Kubernetes management console — visibility, diagnosis, an in-browser k9s terminal, and approval-gated fixes — running entirely inside your cluster. No SaaS backend, no data leaving your network. Installs with one Helm command.

Explore the platform
k9s terminal
kubectl in your browser
Prometheus + Grafana
plugs into your stack
Full management
workloads · Helm · security
Why SRE teams need this

One alert. Ten tools. Too many tabs.

When something breaks at 2 a.m., the answer is scattered and the clock is running. KubeManta pulls the whole loop — see, understand, fix — into one place you run yourself.

The 2 a.m. reality
The KubeManta way
The 2 a.m. reality

An alert fires and the answer is scattered — kubectl for logs, k9s for pods, one dashboard for metrics, another for events.

The KubeManta way

One incident-first screen: what broke, where, when it started, and for how long — click any failing pod for the full story.

The 2 a.m. reality

You grep YAML and events under pressure, guessing which pod is the root cause and which policy is blocking the call.

The KubeManta way

A graph-grounded copilot and failure-cascade map name the exact root cause and cite the resources — no guessing.

The 2 a.m. reality

Fixing means risky hand-typed kubectl, or waiting for the one engineer who knows the cluster.

The KubeManta way

Approval-gated fixes any admin can apply from the UI — single-use token, blast-radius cap, full audit. Nothing auto-runs.

The 2 a.m. reality

SaaS observability ships your cluster's telemetry to a vendor's cloud — a non-starter for regulated or air-gapped teams.

The KubeManta way

Runs entirely inside your own cluster. Self-hosted, air-gap ready — nothing leaves your network.

The platform

Everything an SRE team needs, inside your own cluster.

Triage

Incident-first overview

One screen answers what is broken, where, when it started, and for how long. Click any crashing pod for the full story — exit reason, events, log tail, CPU/mem vs limits.

Ask

Graph-grounded AI copilot

A Claude-powered copilot that retrieves over a real topology graph and cites the exact nodes it reasons from — not logs pasted into a chatbot. Every answer is traceable.

Act

Safe-acting, never autonomous

The agent proposes fixes; you approve each one. Writes run through an isolated admin pod behind a single-use token, circuit breaker, blast-radius cap, and full audit. Nothing auto-applies.

See

Failure cascade + topology

Exactly which pods block which services — root cause → blocked → indirect — plus Ingress→Service→Pod topology and multi-cloud VPC/subnet views for AWS, GCP, and Azure.

Scan

Container security posture

CVE + misconfiguration findings with an A–F posture grade and trend. Read your own trivy-operator, run on-demand self-scans, or point at your Trivy server — your choice.

Govern

RBAC · SSO · guardrails

Viewer/admin roles, SSO via SAML, OIDC, or LDAP, per-actor audit, and DB-durable AI guardrails — kill switch, cost caps, egress allowlist, redaction. Self-hosted; nothing leaves your network.

Alert

Alert rules engine

Ten condition types — restarts, node conditions, unbound PVCs, failed jobs, metric + scan-severity thresholds. 30-second evaluator, cooldown dedup, real-time push.

Build

Resource Builder + Helm

PLAN → APPLY → OBSERVE with server-side dry-run diffs validated against your live cluster, and full Helm lifecycle — install, upgrade, rollback, uninstall — every write approval-gated and audited.

Preview

Not a mockup. The actual product.

Every screen below is a live capture from a running cluster — the in-browser k9s terminal, the Mobula cluster map, your own Prometheus, incident triage, and approval-gated writes.

k9s + kubectl, in your browser
k9s + kubectl, in your browser
A real terminal in the console — k9s, kubectl and Helm preinstalled, running as a separate unprivileged user, with every command audited to the account that ran it.
Pricing

Pay for people who can act. Everyone else watches free.

No node counting — ever. An admin is someone who can restart, scale, apply, run Helm, or open the terminal; viewers see everything and change nothing, and they're free and unlimited at every tier. Pro is $49 per admin seat per month; Enterprise is for SSO, AI governance, white-labeling, air-gap, and an SLA.

Free
$0/ month
one cluster · 1 admin seat · unlimited viewers

The full read-only platform plus one admin. No credit card, no trial clock.

  • One cluster · 1 admin seat · unlimited viewers
  • Incident-first overview + failure cascade
  • Read-only across every workload type
  • Cluster resource map + network topology
  • Metrics dashboards + resource trends
  • Security posture — read trivy-operator reports
  • Helm release viewing (values, history, diff)
  • Browser terminal
  • AI copilot — daily free quota
  • K8s warning-event stream
Pro14-day money-back
$49/ admin / month
per cluster — pick your seat count at checkout
how it scales
$49/ admin / month — anyone who can change things
$39/ admin / month billed annually — save 20%
$0viewers — free & unlimited, every tier
$0nodes — no node limits, any cluster size

Unlimited AI, governed agent writes, multi-cloud. Self-serve — start today.

  • Everything in Free
  • Unlimited free viewers — pay only for admins
  • Unlimited AI diagnosis, analysis & copilot
  • Alert rules engine + read-only auto-investigation
  • Root-cause runbooks — you approve every change
  • Resource Builder apply + Helm write ops
  • On-demand container self-scan
  • Multi-cloud VPC topology (AWS/GCP/Azure)
  • Expert mode — approval-gated cluster writes
  • MCP server for external AI agents
  • Professional support
Enterprise
Custom
scoped to your org & requirements

For platform teams that need SSO, AI governance, white-labeling, air-gap, or an SLA. Tell us what you need — we'll scope a plan with you.

  • Everything in Pro
  • Assisted install & onboarding — set up with our team
  • SSO — SAML, OIDC & LDAP
  • Air-gapped deployment
  • AI governance & data-residency controls
  • Audit export & compliance support
  • SLA + priority support
  • Security-review assistance

Questions people ask before buying

Short answers. If something here is unclear, email [email protected].

What counts as an admin seat?

An admin is anyone who can change the cluster — restart, scale, apply manifests, run Helm, or open the terminal. Viewers see everything and change nothing, and they are free and unlimited on every tier, including Free. You only pay for people who can act.

Do you charge per node, per pod, or per cluster size?

No. There is no node counting and no per-node overage — a 3-node cluster and a 300-node cluster cost the same. A subscription covers one cluster; the price scales with admin seats, not infrastructure.

What does the Free tier actually include?

The full read-only platform on one cluster, plus one admin seat and unlimited viewers. No credit card, no trial clock, no countdown. It is meant to be genuinely usable, not a demo.

Is there a free trial?

There is no separate self-serve trial, because the Free tier already runs the product in your own cluster for as long as you want. For paid plans there is a 14-day money-back guarantee from your first payment. If you need a time-boxed full-Pro evaluation for a team, contact us and we will issue one.

What happens if I add or remove seats mid-month?

You can change seat count at any time and your license stays valid throughout. Added seats are billed from your next billing period rather than charged mid-cycle; removed seats stop being billed from the next period. Nothing is pro-rated against you mid-month.

What happens when my subscription ends?

The software keeps running. It falls back to the Free tier feature set on that cluster — paid features re-lock, but nothing is deleted, disabled, or held hostage, and your data was never ours to hold: it lives in your cluster. There is no lockout, and nothing to uninstall.

Who processes payments, and can I get an invoice?

Paddle is the Merchant of Record. They handle payment, invoicing, and VAT/GST/sales-tax collection and remittance for your jurisdiction, so you get a proper tax-compliant invoice and we never touch your card details.

Does my cluster data leave my infrastructure?

No. KubeManta is self-hosted — it runs as two pods inside your own cluster, and we have no access to it. AI features are optional, use your own LLM key, and can be switched off entirely by an administrator; point them at a local model and there is no external egress at all.

Install

Install using Helm.

Grab a free license key, then answer three questions — we build the exact command for your cluster, with every capability switched on. Runs on any CNCF-conformant cluster: EKS, GKE, AKS, k3s, or bare metal.

EKSGKEAKSk3s / RKE
helm — kubemanta-system
Where are you installing?
Who owns the load balancer?
How much do you want switched on?
# 1. authenticate helm to the registry (one time)
echo "YOUR_LICENSE_KEY" | helm registry login registry.kubemanta.com \
--username license --password-stdin
# 2. install
helm install kubemanta \
oci://registry.kubemanta.com/kubemanta/charts/stable/kubemanta \
--version 1.0.0 \
--namespace kubemanta-system --create-namespace \
--set license.key="YOUR_LICENSE_KEY" \
--set global.hostname="your-domain.com" \
--set global.ingressClassName=alb \
--set global.tls=true \
--set rbac.allowWrites=true \
--set expertMode.enabled=true \
--set security.scanning.enabled=true \
--set metrics.kubeletScrape.enabled=true
# full reference, every flag explained:

See, understand, fix —
from one place.

Free for one cluster. Self-hosted, no credit card, two-pod install.