KUBERNETES
Every cluster, one console, no cloud keys.
Connect EKS, AKS, GKE, DOKS and your own clusters through a connector that runs inside each one. See every object, the logs, the risk and what each namespace costs, and hear about problems before your customers do.
THE USUAL WAY
Five clusters, five consoles, one laptop with cluster-admin.
console
console
console
Example data.
Your clusters
kubectl apply -f -
<masked installation block>
namespace/beam-system created
deployment.apps/beam-connector created
Node Health Map · 5 healthy · 1 needs attention
Pods · namespace shop
Zaysa
Keyless · beam-connector · outbound HTTPS 443
Read-only access inside the cluster. No cloud key stored.
Connect cluster
Connection · Keyless ✓
Cluster name · prod-eu
Connector · beam-connector
- 01Install once, read-only
- 02Connect & Discover
- 03Risk, in one number
- 04What each namespace costs
- 05An alert fires
- 06Follow the logs
- 07Resolved on its own
Example data.
How it works
Connect, see, act
Install the connector
In Beam → Connectors → Add connector → Kubernetes, copy the kubectl apply block. It installs into beam-system and connects out over HTTPS 443.
kubectl apply -f -
<masked block>
namespace/beam-system created
deployment.apps/beam-connector created
Example data.
Connect & Discover
In Kubernetes → Overview → Connect cluster, pick the cloud, choose Keyless, name the cluster, select the connector and press Connect & Discover.
Example data.
Get told
Set an alert rule for failing pods or nodes. It sends a notification, then a Resolved message when the problem clears.
Example data.
Live resource view
Everything kubectl shows, in one place
Overview and Clusters show health, nodes, pods, workloads, monthly cost and top issues. Switch the example resource to see the table change.
- Cluster Risk Score explains reliability, security, cost and performance.
- Node Health Map and Namespace Heatmap show where to look.
- Refresh live metrics, Check permissions or Remove from the cluster page.
- Monitoring charts trends; Graph maps ingress to nodes.
prod-eu · Pods
Read live, like kubectl get.
Example data.
Cost
Cost per namespace, from real prices
Each node and disk is priced using the provider's current price list for its machine type and region. A missing price is left out, not guessed. See idle spend and potential savings from idle use and rightsizing.
prod-eu · monthly
Current cloud price lists by machine type and region. Unpriced nodes are left out.
Example data.
Permissions
What the connector can and cannot do
The connector runs in beam-system with its own ServiceAccount and opens outbound HTTPS 443 to Zaysa. The beam-connector-read ClusterRole can only get and list the shown resources and cannot read Secrets. The separate beam-connector ClusterRole serves team access with short-lived ServiceAccounts using built-in view, edit or admin roles; it cannot grant cluster-admin.
The beam-connector Deployment image is pinned to a version and digest. A zaysa-node-meta DaemonSet labels nodes with machine type and region for pricing. Check permissions asks the cluster what Zaysa may do and changes nothing.
✓ Can read
get/list nodes, pods, workloads, services, events, storage, autoscalers, RBAC, metrics, logs, Argo CD and Flux objects
✕ Cannot
Read Secrets, grant cluster-admin, or change workloads from these pages.
Example data.
ON THE PRO PLAN
Alerts, security and reports
The console, cost and logs are on Free. Alerts are on Pro; security, reports and the AI Assistant are on Pro.
Free includes 1 connector, Pro 5, Business unlimited.
Alerts
Rules for CrashLoopBackOff, ImagePullBackOff, OOMKilled, NotReady and Pending. Email, Slack, Microsoft Teams or webhook; a Resolved message follows when the problem clears.
Security
Findings and cluster-admin bindings, with the reason behind the risk.
Reports
Export cluster name, provider, region, version, nodes, status, CPU and memory use, monthly cost, idle spend, potential savings, open issues and last read as CSV or JSON.
AI Assistant
Ask questions about your clusters in plain language.
Want Zaysa to fix what it finds? See Autopilot.
Questions
Frequently asked questions
Amazon EKS, Azure AKS, Google GKE, DigitalOcean DOKS and self-hosted Kubernetes clusters. OpenShift uses the same connector console, with projects, routes, operators, builds and image streams.
More in Kubernetes
See what you run, and what it costs.
Free plan, no card needed.