Kubernetes troubleshooting from the on-call rotation.

Incident walkthroughs, diagnosis patterns, Kubernetes playbooks, and product notes from Hadi Farnoud.

KubeAgent is now free forever — and it moved into your cluster

Monitoring and alerts are now free with no time limit, every account gets 200K AI credits that never expire, and the agent runs in your cluster.

Why an npm supply-chain attack can't reach your cluster

npm faces constant supply-chain attacks. Here's how KubeAgent's architecture and release hardening keep a compromised dependency away from your cluster.

Anatomy of an auto-remediated CrashLoopBackOff

From the third pod restart to a stabilised memory limit — the kubectl calls, safety classification, terminal approval, and verification in order.

Running KubeAgent in CI: gate deploys on real cluster health

kubectl rollout status confirms Kubernetes accepted your deploy — not that your system is healthy. The new kubeagent check command closes that gap.

Detect cluster-wide CVEs in 30 seconds with kubeagent scan-apps

Most CVE scanners want a sidecar and a registry hook. kubeagent scan-apps reads what's already in the cluster and cross-checks OSV.dev + endoflife.date.

Inside KubeAgent's three-tier action safety model

KubeAgent classifies Kubernetes actions as Safe, Risky, or Never in code, keeping destructive operations outside the model's control.

Why KubeAgent doesn't ask for your kubeconfig

Most Kubernetes monitors want a service account or an in-cluster agent. KubeAgent runs locally and uses your existing kubectl context — here's why that matters.

Why we built KubeAgent — and what's on this blog

Most Kubernetes monitoring tools wake you at 2 AM and leave you to diagnose. KubeAgent investigates, fixes safe issues itself, and pages you only for the rest.