Kubernetes troubleshooting from the on-call rotation.
Incident walkthroughs, diagnosis patterns, Kubernetes playbooks, and product notes from Hadi Farnoud.
KubeAgent is now free forever — and it moved into your cluster
Monitoring and alerts are now free with no time limit, every account gets 200K AI credits that never expire, and the agent runs in your cluster.
Why an npm supply-chain attack can't reach your cluster
npm faces constant supply-chain attacks. Here's how KubeAgent's architecture and release hardening keep a compromised dependency away from your cluster.
Anatomy of an auto-remediated CrashLoopBackOff
From the third pod restart to a stabilised memory limit — the kubectl calls, safety classification, terminal approval, and verification in order.
Running KubeAgent in CI: gate deploys on real cluster health
kubectl rollout status confirms Kubernetes accepted your deploy — not that your system is healthy. The new kubeagent check command closes that gap.
Detect cluster-wide CVEs in 30 seconds with kubeagent scan-apps
Most CVE scanners want a sidecar and a registry hook. kubeagent scan-apps reads what's already in the cluster and cross-checks OSV.dev + endoflife.date.
Inside KubeAgent's three-tier action safety model
KubeAgent classifies Kubernetes actions as Safe, Risky, or Never in code, keeping destructive operations outside the model's control.
Why KubeAgent doesn't ask for your kubeconfig
Most Kubernetes monitors want a service account or an in-cluster agent. KubeAgent runs locally and uses your existing kubectl context — here's why that matters.
Why we built KubeAgent — and what's on this blog
Most Kubernetes monitoring tools wake you at 2 AM and leave you to diagnose. KubeAgent investigates, fixes safe issues itself, and pages you only for the rest.