K8s
Kubernetes adds a Kubernetes item to the Paseo sidebar: a panel for browsing clusters, with sortable and searchable resource tables, a detail drawer, pod logs, a Flux (GitOps) tab, and a command bar. You can attach a pod or workload to an agent's composer as context, or start a new agent from a resource with an editable instruction. Resource status, events and log tails become part of the agent prompt.
Nothing is configured out of the box. Add a cluster under Settings in the panel by giving it a kubeconfig. If no config exists, the panel offers kubeconfigs it finds under ~/.kube and ~/.config/kubernetes-mcp. Cluster config is stored in ~/.config/paseo-k8s/clusters.json.
The daemon reads the kubeconfig you configure, including referenced certificate, key and token files, and connects to that cluster's API server with the credential. Browsing, logs and Flux status use GET requests only. Bearer tokens, token files, client certificates and basic auth work. exec and auth-provider credentials are rejected, because the panel does not run external binaries to get credentials. Kubernetes RBAC on the credential decides what the panel can list, and anything it cannot read is reported as partial data.
The panel can also change the cluster. The command bar runs commands on the daemon host with KUBECONFIG set to the selected cluster. By default it only allows the programs you list (kubectl, helm and kustomize), runs them without a shell, and refuses pipes, redirects and wildcards. The Full bash setting runs the whole line in bash -lc with anything on your PATH. It is not a terminal, so kubectl exec -it does not work. The Flux tab's Reconcile, Suspend and Resume buttons run fixed kubectl commands that set the reconcile annotation or spec.suspend, and need kubectl installed. Comparing the deployed revision with a local Flux checkout needs git and reads that checkout.
This plugin entry was imported from paseo.cafe.
