Kply is the Kubeply CLI for giving AI coding agents safe Kubernetes sessions instead of raw cluster access.
The CLI is the first open-source surface for the larger Kubeply product: a control boundary where agents can inspect workloads, create sandbox sessions, run checks, and produce auditable reports before any production change is promoted.
Implementation in progress. The workspace now includes real session planning, Kubernetes discovery, sandbox create/cleanup, early runtime check support, and Gateway API routing groundwork.
Session mutation commands require explicit --apply confirmation.
Install the latest released binary with the shell installer:
curl --proto '=https' --tlsv1.2 -LsSf \
https://github.com/kubeply/kply/releases/latest/download/kply-cli-installer.sh \
| shThe installer places kply under CARGO_HOME when that environment variable is
set, otherwise under the default cargo home directory.
Release archives are also published for Linux, portable Linux, and macOS on x86_64 and aarch64. Each release includes SHA-256 checksums and GitHub artifact attestations.
Review the release notes before upgrading, especially for CLI output contract, config schema, RBAC, routing, or generated Kubernetes resource changes.
Upgrade to the latest released binary by rerunning the installer:
curl --proto '=https' --tlsv1.2 -LsSf \
https://github.com/kubeply/kply/releases/latest/download/kply-cli-installer.sh \
| shVerify the installed version:
kply --versionRollback to a known-good release by installing from its release tag. Replace
v0.1.0 with the version listed in the release notes or deployment record:
curl --proto '=https' --tlsv1.2 -LsSf \
https://github.com/kubeply/kply/releases/download/v0.1.0/kply-cli-installer.sh \
| shVerify the rollback installed the expected version before running cluster workflows:
kply --versionA Kply session is a temporary, scoped workspace for an agent:
- target workload
- proposed image or config change
- sandbox deployment and service
- optional route rule for agent/test traffic
- runtime checks
- cleanup plan
- audit report
Start from a read-only cluster scan instead of writing config by hand:
kply init --from-cluster
kply --config kply.yaml app list
kply --config kply.yaml app inspect <app>kply init --from-cluster discovers Deployments and deterministic Service
selector matches, writes a starter kply.yaml, and prints next commands. It
does not create, update, delete, patch, or read Secret values.
cargo fmt --all -- --check
cargo check --all-targets --all-features --locked
cargo clippy --all-targets --all-features --locked -- -D warnings
cargo test --all-targets --all-features --lockedSee docs/cli.md for command contract notes, including exit codes.
See docs/gateway-api.md for Gateway API routing permissions, ownership constraints, and fallback guidance when Gateway API is unavailable.
See docs/rbac.md for least-privilege Kubernetes RBAC examples for read-only inspection, sandbox-only sessions, and optional route mutation.
See docs/github-actions.md for running Kply plan reports in pull-request workflows.
See docs/terminal-agents.md for using kply with
Codex, Claude Code, Cursor, and other terminal coding agents.
See docs/demo-kind.md for the current manual Kind setup guide. A short asciinema-compatible cast is available at docs/demo-terminal-cast.md.
See SECURITY.md for private vulnerability reporting.
Apache-2.0. See LICENSE.