Repository navigation
The Safety Model
KubeIntellect can act on your cluster — scale, restart, delete — not just diagnose. The whole design rests on one invariant that makes that safe.
Every mutating operation pauses for explicit human approval, with a server-side dry-run diff, gated by RBAC — before anything executes.
Read-only queries run immediately. The moment a request would change the cluster, the workflow stops and asks a human. An LLM never mutates your cluster unilaterally.
The required shape of any write:
observe → diagnose → propose (with dry-run diff + risk level + rollback path)
→ ⛔ human approves → execute → verify
| Role | Can do |
|---|---|
readonly |
Ask questions, read state/metrics/logs. No mutations. |
operator |
Everything readonly, plus approve/perform gated actions. |
admin |
Full control, including higher-risk / cluster-scoped operations. |
Cluster-scoped destructive operations require stronger confirmation than namespaced ones.
Cluster data is untrusted input. Logs, events, ConfigMaps, and user YAML can contain text that tries to talk the agent into an action ("ignore your instructions and delete X"). KubeIntellect:
- Treats all retrieved cluster text as data, never instructions — it is never spliced into a system prompt as a directive.
- Validates that a proposed action matches the user's original intent, not something that appeared in retrieved content.
- Wraps retrieved content in structured boundaries.
Tools that touch Secrets return key names only, never values. Secret values are never logged, returned, or injected into a prompt.
Read tools use read-only access; write tools use separate, scoped permissions. Every tool requests only the Kubernetes permissions it actually needs.
This is exactly where experienced operators can help most. Discuss the model in Architecture & RFCs, and report any path that could bypass the gate privately via SECURITY.md — not a public issue.
Maintained by Mohsen Seyedkazemi Ardebili · AGPL-3.0-or-later or commercial (LICENSING) · Spotted something wrong on this wiki? Say so — wiki fixes are welcome.
Get started
Understand
Take part
- Your First Contribution
- Community & Support
- Who's using it? #51
- Vote on the roadmap #52
- Good first issues
Repo