For SRE & platform teams

The Kubernetes SRE console that runs inside your cluster.

See what's broken, understand why, and fix it with approval-gated actions — real-time visibility, AI diagnosis, and an in-browser k9s terminal. Self-hosted: no SaaS backend, nothing leaves your network. One Helm command to install.

See it in action
k9s terminal
kubectl in your browser
Prometheus + Grafana
plugs into your stack
Full management
workloads · Helm · security
Latest v1.2.0
Why this exists

Letting developers see their own logs means handing out kubeconfigs — and owning the scoping, the rotation, and the record of what was run. Most teams don’t. So the tickets come to you.

One platform where SREs and developers troubleshoot the same appswith the access each role allows.

Admins keep the cluster and the troubleshooting. Developers read their own logs and app metrics, save what they need, and change nothing.

Both teams end up looking at the incident instead of at each other.

Usual Workflow

An alert, not a question

The alert names the application, not a pod. The developer who owns it opens it themselves.

See how applications work
Applications — storefront · viewer
The Applications view filtered to storefront, signed in as a viewer: feature-store Pending, image-optimizer OOMKilled with 143 restarts, recommendations in CrashLoopBackOff, notifications-worker stuck, the rest healthy.

Logs without a ticket

They read the failure in their own service. REDIS_URL was never set. You are not in this conversation.

See the log workspace
Log Workspace — recommendations · viewer
The whole Log Workspace window as the same viewer: the imported recommendations tail with the errors-only view on, ending on FATAL recommendations: required config REDIS_URL is not set — refusing to start. No Fix, Apply or Edit control in frame.

One incident, two owners

The cascade splits it in two. Upstream, a feature-store pod no node will take — yours. Downstream, the crash they are already reading, and a worker waiting behind it — theirs.

See the failure cascade
Diagnose — failure cascade · storefront
The failure cascade for storefront: a feature-store pod that cannot be scheduled as the root cause, recommendations blocked behind it, and notifications-worker held in Init:0/1 as indirectly affected.
Pro · your own LLM key

The one that is yours

image-optimizer is OOMKilled, exit 137. You ask why. The answer names the limit it hit and proposes the patch that would raise it.

See AI diagnosis
Pro

Nothing applies itself

You read the patch, then approve it. It is the only change to the cluster today, and it has your name on it.

See approval-gated writes

What it recorded

Every write, every approval, every sensitive read. Hash-chained, kept a year. The developer’s morning is in there too, by name and source address.

See the audit trail
Activity Feed — timeline · storefront
The Activity Feed timeline filtered to storefront: the viewer’s log workspace reads attributed by name and source IP beside the cluster’s own warnings, with Verify chain and Export in frame.

Developers watch their own apps — the logs, the metrics, how each release behaves.Now and then that surfaces the cause: a pod out of memory, a ConfigMap that never mounted.

You keep the cluster. All of it.One platform, two teams — each looking at the half that’s theirs.

Also in the box
  • Cluster map
  • Browser terminal with k9s
  • Image scanning with Trivy
  • Network policy view
  • Node operations
  • Resource Builder
The platform

Everything an SRE team needs, inside your own cluster.

Triage

Incident-first overview

One screen answers what is broken, where, when it started, and for how long. Click any crashing pod for the full story — exit reason, events, log tail, CPU/mem vs limits.

Ask

Graph-grounded AI copilot

A copilot on your own LLM key — Anthropic, OpenAI, Google, Groq, or a local Ollama — that retrieves over a real topology graph and cites the exact nodes it reasons from, not logs pasted into a chatbot. Every answer is traceable.

Act

Safe-acting, never autonomous

The agent proposes fixes; you approve each one. Writes run through an isolated admin pod behind a single-use token, circuit breaker, blast-radius cap, and full audit. Nothing auto-applies.

See

Failure cascade + topology

Exactly which pods block which services — root cause → blocked → indirect — plus Ingress→Service→Pod topology and multi-cloud VPC/subnet views for AWS, GCP, and Azure.

Scan

Container security posture

CVE + misconfiguration findings with an A–F posture grade and trend. Read your own trivy-operator, or run on-demand self-scans — your choice, and you can remove the scanner KubeManta deploys.

Govern

RBAC · SSO · guardrails

Viewer/admin roles, SSO via SAML, OIDC, or LDAP, per-actor audit, and DB-durable AI guardrails — kill switch, cost caps, egress allowlist, redaction. Self-hosted; nothing leaves your network.

Alert

Alert rules engine

Ten condition types — restarts, node conditions, unbound PVCs, failed jobs, metric + scan-severity thresholds. 30-second evaluator, cooldown dedup, real-time push.

Build

Resource Builder + Helm

PLAN → APPLY → OBSERVE with server-side dry-run diffs validated against your live cluster, and full Helm lifecycle — install, upgrade, rollback, uninstall — every write approval-gated and audited.

Plugs into what you already run.

KubeManta runs inside your cluster and connects to the sign-in, paging, metrics and scanning you already have, so none of it has to leave.

  • Enterprise
  • Pro
  • Free
  • MCP and the REST API are how agents and scripts reach KubeManta. Free on every plan.
  • Compare plans

Bring your own model. Anthropic, OpenAI, or a local Ollama. Your key stays in the cluster, and with Ollama it runs fully air-gapped.

Pricing

Pay for people who can act. Everyone else watches free.

No node counting — ever. An admin is someone who can restart, scale, apply, run Helm, or open the terminal; viewers see everything and change nothing, and they're free and unlimited at every tier. Pro is $49 per admin seat per month; Enterprise is for SSO, AI governance, white-labeling, air-gap, and an SLA.

Free
$0/ month
one cluster · 1 admin seat · unlimited viewers

Triage, topology, terminal and workload actions on one cluster, plus one admin. No credit card, no trial clock.

Provided as-is; the Free feature set may change in future releases.

  • One cluster · 1 admin seat · unlimited viewers
  • Incident-first overview + failure cascade
  • Read-only across every workload type
  • Cluster resource map + network topology
  • Metrics dashboards + resource trends
  • Security posture — read trivy-operator reports
  • Helm release viewing (values, history, diff)
  • Browser terminal
  • AI copilot — daily free quota
  • K8s warning-event stream
  • Alert rules engine — unlimited rules, Slack/Telegram/Email
  • MCP server — read-only K8s tools for external AI agents
Pro14-day money-back
$49/ admin / month
per cluster — pick your seat count at checkout
how it scales
$49/ admin / month — anyone who can change things
$39/ admin / month billed annually — save 20%
$0viewers — free & unlimited, every tier
$0nodes — no node limits, any cluster size

Unlimited AI, governed agent writes, multi-cloud. Self-serve — start today.

  • Everything in Free
  • Unlimited free viewers — pay only for admins
  • Unlimited AI diagnosis, analysis & copilot
  • Alert auto-investigation, firing history & PagerDuty/Datadog/CloudWatch/webhook
  • Root-cause runbooks — you approve every change
  • Resource Builder apply + Helm write ops
  • On-demand container self-scan
  • Multi-cloud VPC topology (AWS/GCP/Azure)
  • Expert mode — approval-gated cluster writes
  • Professional support
Enterprise
Custom
scoped to your org & requirements

For platform teams that need SSO, AI governance, white-labeling, air-gap, or an SLA. Tell us what you need — we'll scope a plan with you.

  • Everything in Pro
  • Assisted install & onboarding — set up with our team
  • SSO — SAML, OIDC & LDAP
  • Air-gapped deployment
  • AI governance & data-residency controls
  • Audit export & compliance support
  • SLA + priority support
  • Security-review assistance

Want to see it against your cluster shape before picking a tier? Book a live demo →

Questions people ask before buying

Short answers. If something here is unclear, email [email protected].

What counts as an admin seat?

An admin is anyone who can change the cluster — restart, scale, apply manifests, run Helm, or open the terminal. Viewers see everything and change nothing, and they are free and unlimited on every tier, including Free. You only pay for people who can act.

Do you charge per node, per pod, or per cluster size?

No. There is no node counting and no per-node overage — a 3-node cluster and a 300-node cluster cost the same. A subscription covers one cluster; the price scales with admin seats, not infrastructure.

What does the Free tier actually include?

Day-to-day operations on one cluster: incident triage, failure cascade, the resource map and network topology, built-in metrics, Helm and scan-report viewing, the browser terminal, and workload actions — restart, scale, delete — plus one admin seat and unlimited viewers. Alerting is included: unlimited rules delivered to Slack, Telegram or email. AI diagnosis, multi-cloud topology, long-retention Prometheus, and the alerting extras — auto-investigation of a firing, retained firing history, and the PagerDuty/Datadog/CloudWatch/webhook integrations — are Pro. No credit card, no trial clock, no countdown. It is meant to be genuinely usable, not a demo. The Free tier is provided as-is and free of charge, and what it includes may change in future releases — a change never reaches a version you have already installed.

Is there a free trial?

There is no separate self-serve trial, because the Free tier already runs the product in your own cluster, with no time limit on your license key. For paid plans there is a 14-day money-back guarantee from your first payment. If you need a time-boxed full-Pro evaluation for a team, contact us and we will issue one.

What happens if I add or remove seats mid-month?

You can change seat count at any time and your license stays valid throughout. Added seats are billed from your next billing period rather than charged mid-cycle; removed seats stop being billed from the next period. Nothing is pro-rated against you mid-month.

What happens when my subscription ends?

The software keeps running. It falls back to the Free tier feature set on that cluster — paid features re-lock, but nothing is deleted, disabled, or held hostage, and your data was never ours to hold: it lives in your cluster. There is no lockout, and nothing to uninstall.

Who processes payments, and can I get an invoice?

Paddle is the Merchant of Record. They handle payment, invoicing, and VAT/GST/sales-tax collection and remittance for your jurisdiction, so you get a proper tax-compliant invoice and we never touch your card details.

Does my cluster data leave my infrastructure?

No. KubeManta is self-hosted — it runs as two pods inside your own cluster, and we have no access to it. AI features are optional, use your own LLM key, and can be switched off entirely by an administrator; point them at a local model and there is no external egress at all.

Install

One Helm command, shaped to your cluster.

Answer three questions. The command below rewrites itself as you choose — copy it, run it on any Linux box with cluster access.

Where are you installing?
Who owns the load balancer?
How much do you want switched on?
ubuntu — bash
helm install kubemanta \
  oci://registry.kubemanta.com/kubemanta/charts/stable/kubemanta \
  --version 1.2.0 \
  --namespace kubemanta-system --create-namespace \
  --set license.key="YOUR_LICENSE_KEY" \
  --set global.hostname="your-domain.com" \
  --set global.ingressClassName=alb \
  --set global.tls=true \
  --set rbac.allowWrites=true \
  --set expertMode.enabled=true

Add --set license.key=YOUR_KEY — grab a free key below. Full flag reference at docs.kubemanta.com/getting-started/install.

See, understand, fix —
from one place.

Free for one cluster. Self-hosted, no credit card, two-pod install.