KubeGlass compared with other Kubernetes tools
These pages compare KubeGlass with the tools people most often weigh it against. Every claim about another tool comes from that tool’s own documentation, release notes or source code, linked in the notes below the table and on each tool’s page. We checked them on 5 October 2026. If something has changed since, open an issue and we will correct the page.
In the table, Yes means built in, Plugin means a plugin or extension you install (the note says whose), Paid means a paid plan, and Partial says what is there. Not documented means we found nothing either way.
Features
Section titled “Features”| KubeGlass | Headlamp | k9s | Lens | Freelens | Kubernetes Dashboard | |
|---|---|---|---|---|---|---|
| License | AGPL-3.0 | Apache-2.01 | Apache-2.02 | Proprietary3 | MIT4 | Apache-2.05 |
| Free, with no account | Yes | Yes6 | Yes2 | Partial (paid above $10M revenue; Lens ID required)7 | Yes4 | Yes |
| Maintained | Yes | Yes | Yes | Yes | Yes | No (archived in early 2026)8 |
| Runs as | Local binary with a browser UI, or in a cluster | Desktop app, or in a cluster9 | Terminal UI | Desktop app10 | Desktop app | In a cluster |
| Shared install with per-user sign-in | Yes (auth proxy or OIDC token)11 | Yes (built-in OIDC)12 | No | No13 | No | Yes (bearer token)14 |
| Several clusters | Yes (from a kubeconfig)15 | Yes16 | Partial (one at a time)17 | Yes18 | Yes | No (one per install)19 |
| Live updates (watches) | Yes | Yes20 | Yes21 | Yes22 | Yes | No (polls every 10 s)23 |
| Logs of a workload’s pods in one view | Yes | Yes24 | Yes25 | No (one pod at a time)26 | Plugin (third-party)27 | No (one container at a time)28 |
| Shell in a container | Yes | Yes | Yes | Yes | Yes | Yes29 |
| Port forward | Partial (when it runs on your computer)30 | Partial (desktop app only)31 | Yes | Yes32 | Yes | No |
| Edit YAML | Yes, with dry run and diff | Yes, with dry run and diff33 | Yes (in your editor)2 | Yes (diff view Paid)34 | Yes | Yes |
| Helm releases | Yes | Plugin (bundled with the desktop app)35 | Partial (no install or upgrade)36 | Yes37 | Yes38 | No |
| Argo CD and Flux | Yes | Plugin (Argo CD in alpha)35 | Plugin (community)39 | Paid40 | Plugin (Argo CD third-party)41 | No |
| Custom resources | Yes | Yes | Yes | Yes | Yes | Yes |
| Who can do what | Yes (access matrix, who can) | No (role and binding lists)42 | Partial (one subject’s rules)43 | No (role and binding lists)42 | No (role and binding lists)42 | No (role and binding lists)42 |
| Prometheus metrics | Yes | Plugin (bundled with the desktop app)35 | No44 | Yes45 | Yes46 | No (metrics-server only)47 |
| Plugins or extensions | Partial (links, commands, columns, aliases)48 | Yes49 | Yes (commands bound to keys)39 | Not documented50 | Yes41 | No |
| Keyboard-driven | Yes (k9s keys, command palette) | Partial (search, a few shortcuts)51 | Yes | Partial (command palette, shortcuts)52 | Partial (command palette, shortcuts) | No |
| Relationship map | Partial (tree on each object’s page) | Yes (Map view)53 | Partial (XRay tree)21 | Not documented | Plugin41 | Partial (related objects on detail pages)28 |
| Change history with undo | Yes54 | No55 | No55 | No55 | No55 | No55 |
| AI | Partial (read-only MCP server)56 | Plugin (alpha)35 | Plugin (community)39 | Paid (Ask AI, MCP server)40 | Plugin41 | No |
| Vulnerability reports | Partial (from the Trivy Operator)57 | Plugin (third-party)35 | Yes (opt-in image scans)58 | Paid (needs the Trivy Operator)40 | Not documented | No |
Rancher isn’t in the table because it does a different job: it creates and manages clusters as well as showing them. It has a page of its own.
The tools
Section titled “The tools”Headlamp
Section titled “Headlamp”Headlamp is a Kubernetes UI from Kubernetes SIG UI that runs as a desktop app or in a cluster, with a plugin system and a map of the cluster. It is ahead of KubeGlass on plugins, the desktop app, built-in OIDC sign-in and languages; KubeGlass has Helm, GitOps, access reviews and a change history built in.
k9s is a terminal UI, one program per person, with plugins that run commands. KubeGlass uses the same keys in a browser and adds a team deployment, several clusters at once, history and access reviews; k9s needs no server or browser at all.
Lens and Freelens
Section titled “Lens and Freelens”Lens is a desktop app from Mirantis that needs a Lens ID and, for organizations above $10 million in revenue or funding, a paid plan; its GitOps, AI and security features are paid. Freelens is the MIT-licensed fork of its open-source core, free and with extensions.
Kubernetes Dashboard
Section titled “Kubernetes Dashboard”Kubernetes Dashboard was archived in early 2026 and is no longer maintained. The Kubernetes project suggests Headlamp instead; KubeGlass is another way to replace it.
Rancher
Section titled “Rancher”Rancher creates clusters, signs people in and deploys with Fleet across many clusters. KubeGlass works with clusters you already have and can read the kubeconfig Rancher gives you.
Sources for the table, checked on 5 October 2026:
Footnotes
Section titled “Footnotes”-
License, key bindings and
eto edit in your editor: derailed/k9s. The README says “K9s will always remain OSS and therefore free”. ↩ ↩2 ↩3 -
Built on Open Lens (MIT), but the app itself may not be modified or reverse engineered: Lens Desktop additional terms ↩
-
freelensapp/freelens. Installing it takes no account. ↩ ↩2
-
“Headlamp is a 100% open source project … available at no charge”, and it can switch between several clusters: Headlamp FAQ ↩
-
The Personal plan is free for “students, hobbyists, and engineers at small organizations”; “organizations with over $10 million in annual revenue or funding” need Plus, Pro or Enterprise: Lens pricing. Activation needs a Lens ID: Lens subscription FAQ ↩
-
“This project is now archived and no longer maintained”: kubernetes/dashboard. SIG UI decided to discontinue it in December 2025: SIG UI annual report 2025 ↩
-
Linux, macOS and Windows desktop apps, and a Helm chart for a cluster: Headlamp installation ↩
-
In
impersonationmode a proxy such as OAuth2 Proxy or Pomerium signs people in; inoidcmode KubeGlass checks the OIDC token the proxy passes on. KubeGlass has no sign-in page of its own, and an install in a cluster shows only that cluster. See Running for a team. ↩ -
A Sign in button for OIDC: Headlamp OIDC ↩
-
There is no web version. Teamwork, on the Pro and Enterprise plans, gives remote access to clusters from each person’s app: Lens cluster connect ↩
-
A bearer token on the login page, or an
Authorizationheader from a proxy: Dashboard access control ↩ -
Every context in the kubeconfig KubeGlass reads. Installed in a cluster, KubeGlass shows only that cluster. See Clusters. ↩
-
Every kubeconfig context on the desktop; in a cluster, extra clusters from mounted kubeconfig files: Headlamp in-cluster ↩
-
:ctxswitches context;:pod @ctx1“Switches out your current k9s context”: k9s commands ↩ -
“Kubernetes Dashboard was designed to work with one cluster at a time”: From Kubernetes Dashboard to Headlamp ↩
-
Real-time tracking and XRay: k9scli.io. XRay covers Pods, Services, Deployments, ReplicaSets, StatefulSets and DaemonSets. ↩ ↩2
-
“All the built-in Lens views utilize the Kube Watch API”: Lens cluster performance ↩
-
Resources refresh every 10 seconds by default: settings.go ↩
-
Logs of all pods of a Deployment, ReplicaSet and similar in one dialog: release v0.29.0 ↩
-
Logs for Deployments, DaemonSets, StatefulSets, Jobs and Services pick their pods by label: logs_extender.go at v0.51.0 ↩
-
“use the Pod and Container drop-down lists to switch between pods and containers”: Lens logs ↩
-
Freelens opens a workload’s logs on its first pod (source); the third-party Multi Pod Logs extension merges them (Freelens extensions list). ↩
-
A forwarded port opens on the computer KubeGlass runs on, so KubeGlass offers port forwards only when it runs outside a cluster (authz_handlers.go). ↩
-
Release v0.15.0 (“desktop only”), still the case in PortForward.tsx at v0.45.0 ↩
-
The Review changes diff in release v0.42.0 and Dry Run in release v0.43.0 ↩
-
The side-by-side diff is part of the Advanced editor, a premium feature: Lens advanced editor ↩
-
Headlamp’s plugins: app-catalog for Helm (“Desktop only. Shipped with Headlamp desktop builds by default”), Prometheus (shipped with desktop builds), Flux, Argo CD (0.1.0-alpha) and AI Assistant (alpha), plus third-party plugins such as Trivy and Kubescape. ↩ ↩2 ↩3 ↩4 ↩5
-
:helmlists releases (release notes v0.19.3), with values, history, rollback (helm_history.go) and uninstall. ↩ -
Community plugins for Argo CD, Flux, Argo Rollouts and HolmesGPT: k9s plugins folder. Plugins bind commands to keys: k9s plugins ↩ ↩2 ↩3
-
Freelens extensions: Flux, resource map and AI from the Freelens project; Argo CD from a third party (Freelens extensions list). ↩ ↩2 ↩3 ↩4
-
These tools list Roles, ClusterRoles and their bindings. Headlamp’s ServiceAccount page also lists the bindings that name it (release v0.44.0), and Lens’s paid Security Center reports risky roles (Lens premium features). None of them documents a view of who may do something. ↩ ↩2 ↩3 ↩4
-
:can u:<user>,g:<group>ors:<serviceaccount>shows that subject’s rules: command.go at v0.51.0 ↩ -
CPU and memory come from metrics-server (k9s RBAC); the docs don’t mention Prometheus. ↩
-
Lens Metrics or your own Prometheus: Lens cluster metrics ↩
-
Links to open and commands to copy on objects, extra list columns and command palette names. KubeGlass never runs the commands. See Extensions. ↩
-
Plugins in JavaScript or TypeScript: Headlamp plugins ↩
-
The documented extension API is “no longer supported in Lens Desktop starting from Lens 2024.9.300059”, and the current docs don’t describe a new one: Lens extension API ↩
-
Global search and configurable shortcuts: release v0.40.0 ↩
-
Changes to Deployments, StatefulSets, DaemonSets, CronJobs, Services, Ingresses, ConfigMaps, Secrets and autoscalers, recorded while KubeGlass runs, with revert after a dry run. See Timeline. ↩
-
None of these tools documents a record of past changes to objects that can be undone. Headlamp can roll Deployments, DaemonSets and StatefulSets back to an earlier revision (release v0.41.0), and k9s, Lens and Freelens can roll a Helm release back; both use the history Kubernetes and Helm keep themselves. ↩ ↩2 ↩3 ↩4 ↩5
-
An MCP server with 41 tools that only read, for AI clients such as VS Code or Claude Desktop. There is no assistant in the UI. See MCP server. ↩
-
KubeGlass shows the VulnerabilityReports the Trivy Operator writes; it doesn’t scan images itself. See Security and monitoring. ↩
-
imageScansin k9s configuration; marked experimental in release notes v0.29.0 ↩