KubeEyes is a Kubernetes desktop app for macOS. Besides the clusters already in your kubeconfig, it can find your Amazon EKS clusters by itself and connect to them with the same credentials the AWS CLI uses.
How EKS discovery works
- It reads your AWS profiles. Every profile in
~/.aws/configand~/.aws/credentials: AWS IAM Identity Center (SSO), assumed roles and static keys. Profiles that land in the same AWS account are merged, so each account shows once. - It lists EKS clusters in every enabled region, grouped by account, in the cluster switcher. Discovery is read-only, runs when you expand an account, and is cached for five minutes (↻ scans again).
- Connect adds a context that signs in with
aws eks get-tokenunder that profile. It goes into KubeEyes’ own kubeconfig,~/Library/Application Support/KubeEyes/kubeconfig— your~/.kube/configis never edited. The trash icon removes it again.
Clusters that are already in your kubeconfig open as usual. Helm sees the same contexts, so Helm releases work on discovered clusters too.
What you need
- The AWS CLI, installed and configured with your profiles. If the AWS SDK can’t resolve a profile, KubeEyes falls back to
aws configure export-credentials, so anything the AWS CLI can use works in KubeEyes. - Access to the cluster itself. Your IAM user or role has to be allowed into the cluster, through an EKS access entry or the
aws-authConfigMap, like for kubectl. What you can do inside is decided by Kubernetes RBAC; see permissions KubeEyes needs.
When an AWS SSO session expires
SSO sessions run out while you work. When a watch reconnects and the credential plugin fails, KubeEyes shows one banner for the cluster instead of an error on every screen, keeps retrying, and offers Sign in with AWS SSO: it runs aws sso login for that context’s profile and reconnects.
Production clusters
Mark a cluster Protected and every change asks you to type the cluster’s name first; mark it Read-only and changes and shells are refused while browsing, logs and port forwarding still work. Clusters whose name looks like production (prod, production, prd, live) get a suggestion to protect them.
Questions
Does KubeEyes change my ~/.kube/config?
No. Clusters you connect from EKS discovery are added to KubeEyes’ own kubeconfig in ~/Library/Application Support/KubeEyes. Your ~/.kube/config is only read.
Does EKS discovery work with AWS SSO?
Yes. Profiles that use AWS IAM Identity Center (SSO), assumed roles or static keys are all scanned, and an expired SSO session can be renewed from KubeEyes with aws sso login.
Which regions does KubeEyes search for EKS clusters?
Every region enabled for the account. Discovery is read-only and cached for five minutes.