Skip to content

KubeGlass vs Headlamp

Headlamp is a Kubernetes UI from Kubernetes SIG UI that runs as a desktop app or in a cluster and is extended with JavaScript plugins. KubeGlass is a web console that runs as one binary on your computer or in a cluster, with Helm, GitOps, access reviews and a change history built in.

Both are free, need no account of their own, work with your kubeconfig, and leave permissions to Kubernetes RBAC. Since the Kubernetes Dashboard was archived, Headlamp is the UI the Kubernetes project points people to (see KubeGlass vs Kubernetes Dashboard).

KubeGlass Headlamp
License AGPL-3.0 Apache-2.0
Project The KubeGlass maintainers A subproject of Kubernetes SIG UI; latest release v0.45.0, 20 August 2026
Runs as A binary that opens the UI in your browser, a container, or a Helm chart in a cluster A desktop app for Linux, macOS and Windows, or a Helm chart or manifest in a cluster
Team sign-in in a cluster An auth proxy such as OAuth2 Proxy, or an OIDC token the proxy passes on; every request runs as the person Built-in OIDC sign-in, or a token
Several clusters Every kubeconfig context in one list with its problem counts; installed in a cluster, it shows only that cluster Every kubeconfig context, with a cluster switcher and an experimental view of several clusters together; installed in a cluster, it can show more clusters from mounted kubeconfig files
Live updates Watches over WebSocket Watches over WebSocket
Logs Merged across a workload’s pods, previous run, search, JSON expansion All pods of a workload in one dialog, previous container, search, severity filter
Shells Pod exec, node shells (opt-in), a shell on your computer (opt-in); split panes, broadcast, recording Pod exec, node shells, ephemeral debug containers
Port forward Pods and Services, when KubeGlass runs on your computer In the desktop app only
YAML Edit with a server-side dry run and a diff Edit with a dry run and a Review changes diff; forms for some kinds
Helm Built in: releases, history, values, upgrade, rollback, uninstall and a chart catalog The app-catalog plugin, bundled with the desktop app and listed as desktop only
Argo CD Built in: applications, sync, refresh, stop, roll back An official plugin in alpha
Flux Built in An official plugin
Argo Rollouts Built in: promote, abort, retry, restart Not documented
Custom resources Yes Yes
Metrics CPU and memory from metrics-server or Prometheus, PromQL, Alertmanager alerts and silences, rightsizing CPU and memory from metrics-server; Prometheus charts through a plugin bundled with the desktop app
Access review An access matrix for any user, group or ServiceAccount, who can do something, and a form for roles and bindings Lists of roles and bindings; a ServiceAccount’s page shows the bindings that name it; buttons you may not use are hidden
Relationships A tree on each object’s page: owners, what it owns, the Services that select it, its node and what it mounts A Map view of the cluster, which plugins can extend
Change history Changes to Deployments, StatefulSets, DaemonSets, CronJobs, Services, Ingresses, ConfigMaps, Secrets and autoscalers while KubeGlass runs, field by field, with who made them, and revert after a dry run Roll back Deployments, DaemonSets and StatefulSets to an earlier revision
What is broken An Overview of every object with a problem, worst first, with the likely cause and the change before it A diagnostics section on Pod and workload pages
Grouping Applications: workloads grouped by Helm release, Argo CD application or labels Projects: namespaces across clusters grouped as one
Extending it An extensions file for links, commands to copy, list columns and palette names Plugins in JavaScript or TypeScript, published on Artifact Hub, with a plugin catalog in the desktop app
Keyboard k9s-style keys in every list, and a command palette with : for any kind Global search on / and a few shortcuts you can change
AI An MCP server with 41 read-only tools for AI clients The AI Assistant plugin (alpha), with your own model provider
UI languages 8 25, including right-to-left scripts
  • You want a desktop app that installs like any other, or a UI governed by a Kubernetes SIG with a long release history.
  • You want to add your own views. Headlamp plugins are React code that can add pages, sidebar entries and relations on the map, and there are official plugins for cert-manager, Cluster API, KEDA, Karpenter, Knative, Kyverno, OpenCost and others. KubeGlass has no plugin system.
  • You want one in-cluster install to show several clusters. Headlamp can read extra kubeconfig files mounted into its pod; KubeGlass in a cluster shows only that cluster.
  • You want sign-in built into the UI. Headlamp has an OIDC Sign in button; KubeGlass expects an auth proxy in front of it.
  • You need a language KubeGlass doesn’t have. Headlamp has 25 locales.
  • You want a graphical map of the cluster, or Projects that span namespaces and clusters.
  • You want to create a local cluster from the UI. Headlamp’s Local Cluster feature sets one up with Minikube.
  • You prefer the Apache-2.0 license.
  • You want Helm, Argo CD, Flux and Argo Rollouts without installing plugins, including in a shared deployment in a cluster. Headlamp’s plugin list marks its Helm plugin as desktop only.
  • You want to see what changed before something broke and who changed it, and to revert that change after a dry run.
  • You review access: what a user, group or ServiceAccount may do, and who may do something.
  • You work from the keyboard the way you do in k9s.
  • You compare clusters, check them for drift on a schedule, or check what blocks the next Kubernetes upgrade.
  • You want an MCP server, so AI clients can query your clusters without being able to change them.
  • You want a read-only switch for the whole server or for one cluster, and production marks that make deleting or scaling to zero ask for the name.
  1. Install KubeGlass and start it. It reads ~/.kube/config, or every file in KUBECONFIG, the way Headlamp’s desktop app does, so the same contexts appear:

    Terminal window
    brew install kubeglass/tap/kubeglass
    kubeglass
  2. For a shared deployment, install the Helm chart. Headlamp signs people in with OIDC itself; KubeGlass leaves sign-in to a proxy such as OAuth2 Proxy or Pomerium (impersonation mode), or checks the OIDC token the proxy passes on (oidc mode). Either way every request runs as the signed-in person. See Running for a team.

  3. Replace plugins. Helm, Flux and Prometheus are built in. cert-manager Certificates are under Security › Certificates, Kyverno and Gatekeeper violations under Security › Policies, and other custom resources such as KEDA’s or Karpenter’s get the same list as built-in kinds. For links to Grafana or commands to copy, use the extensions file.

  4. Run both against the same clusters while you try KubeGlass. Neither needs anything installed in the cluster to read it.

Checked on 5 October 2026.