Connect to Amazon EKS from your Mac

KubeEyes finds every EKS cluster your AWS profiles can see, in every enabled region, and connects with aws eks get-token — no copying kubeconfig snippets.

KubeEyes is a Kubernetes desktop app for macOS. Besides the clusters already in your kubeconfig, it can find your Amazon EKS clusters by itself and connect to them with the same credentials the AWS CLI uses.

How EKS discovery works

  1. It reads your AWS profiles. Every profile in ~/.aws/config and ~/.aws/credentials: AWS IAM Identity Center (SSO), assumed roles and static keys. Profiles that land in the same AWS account are merged, so each account shows once.
  2. It lists EKS clusters in every enabled region, grouped by account, in the cluster switcher. Discovery is read-only, runs when you expand an account, and is cached for five minutes (↻ scans again).
  3. Connect adds a context that signs in with aws eks get-token under that profile. It goes into KubeEyes’ own kubeconfig, ~/Library/Application Support/KubeEyes/kubeconfig — your ~/.kube/config is never edited. The trash icon removes it again.

Clusters that are already in your kubeconfig open as usual. Helm sees the same contexts, so Helm releases work on discovered clusters too.

What you need

When an AWS SSO session expires

SSO sessions run out while you work. When a watch reconnects and the credential plugin fails, KubeEyes shows one banner for the cluster instead of an error on every screen, keeps retrying, and offers Sign in with AWS SSO: it runs aws sso login for that context’s profile and reconnects.

Production clusters

Mark a cluster Protected and every change asks you to type the cluster’s name first; mark it Read-only and changes and shells are refused while browsing, logs and port forwarding still work. Clusters whose name looks like production (prod, production, prd, live) get a suggestion to protect them.

Questions

Does KubeEyes change my ~/.kube/config?

No. Clusters you connect from EKS discovery are added to KubeEyes’ own kubeconfig in ~/Library/Application Support/KubeEyes. Your ~/.kube/config is only read.

Does EKS discovery work with AWS SSO?

Yes. Profiles that use AWS IAM Identity Center (SSO), assumed roles or static keys are all scanned, and an expired SSO session can be renewed from KubeEyes with aws sso login.

Which regions does KubeEyes search for EKS clusters?

Every region enabled for the account. Discovery is read-only and cached for five minutes.