Foredeck
Foredeck is a client for Kubernetes clusters you already have access to. It runs entirely on your device and talks to exactly one kind of server: the API server of a cluster you added yourself. Everything Foredeck stores — the list of clusters, their addresses, their credentials, your preferences — stays on this device.
• The clusters you add: the name you give them, the server address, the certificate authority from the kubeconfig, and your display preferences. These are written to Foredeck's own folder, which is protected by iOS file protection and included in your device backup if you take one. • Cluster credentials: bearer tokens, usernames and passwords, and client certificates with their private keys. These are held in the iOS Keychain, marked so they stay on this device and are excluded from iCloud backups. Removing a cluster in Foredeck deletes both, including the keychain entries.
Foredeck sends requests to the Kubernetes API servers you configure, over TLS, carrying the credentials you provided. That is the whole of its network activity, and every destination is one you typed in. The cluster's replies — the state of your workloads, your logs, your events — are shown on screen and held in memory while you look at them. They are not written to disk and not sent anywhere else.
Foredeck writes to the system log through Apple's unified logging, which stays on your device unless you deliberately capture and share a sysdiagnose. Values that could identify your infrastructure are marked private and are redacted in those logs. The developer has no way to see any of it.
Foredeck contains no analytics, no advertising and no third-party software development kits. Its only dependency is a YAML parser, which runs on your device and reads text. Apple provides the App Store and TestFlight and independently collects the information described in Apple's own privacy policy — for example, whether the app was downloaded or crashed. The developer receives only aggregate figures.
Because Foredeck holds your information only on your own device, requests to access, correct or erase it are satisfied by using the app: remove a cluster, or delete the app. Questions about this policy: kozlovskyaid@icloud.com. Last updated: 31 August 2026. Material changes will appear here and in a release note.
Kubernetes is a registered trademark of The Linux Foundation. Foredeck is an
independent client and is not affiliated with, endorsed by or sponsored by
The Linux Foundation or the Kubernetes project.
© 2026 Andrew Kozlowskiy