Foredeck
Foredeck has one built in. On the Clusters screen, tap Explore a Demo Cluster: it runs entirely on your device, is connected to nothing, and has a few things going wrong in it on purpose — a crash-looping pod, a node under memory pressure, a rollout half finished — so every screen has something real to show.
Email kozlovskyaid@icloud.com. Include your iOS version, the Foredeck version from Settings → About, and what the cluster is — a managed service, kubeadm, k3s, Talos — because that usually explains it.
Check the VPN first. A Kubernetes control plane is normally reachable only from inside its own network, and from a phone an unreachable network and a wrong address look identical. Connect the VPN or join the same network, then open the cluster again.
Your kubeconfig asks a command-line tool to produce a token each time it is used —
aws eks get-token, gke-gcloud-auth-plugin, kubelogin,
doctl, yc k8s create-token. iOS has no way to run one, so that
context is refused at import rather than failing later as a connection error.
The remedy is the same everywhere: a ServiceAccount token, which is self-contained. Foredeck → Settings → Credentials writes the whole file for you and lets you copy it — pick your provider there. The commands are below too.
Azure AKS: if the cluster still has local accounts enabled,
az aks get-credentials --admin gives a client certificate, which works on iOS
as it is. Try that first.
DigitalOcean: doctl kubernetes cluster kubeconfig show <cluster>
prints a config with the token already inside — that one imports directly. Add
--expiry-seconds 0 or it stops working after a week.
Two steps everywhere. First the account:
kubectl create serviceaccount foredeck -n default
kubectl create clusterrolebinding foredeck --clusterrole=view --serviceaccount=default:foredeck
Use --clusterrole=edit instead of view if you want to be able to
scale, restart, delete and edit from the phone. view is the safer default for
something that lives in a pocket.
Then the cluster's address and CA, which is the only part that differs:
SERVER=$(aws eks describe-cluster --name <cluster> --query cluster.endpoint --output text)
CA=$(aws eks describe-cluster --name <cluster> --query cluster.certificateAuthority.data --output text)
A cluster with a private-only endpoint is not reachable from a phone at all — it needs the public endpoint enabled, or a VPN into the VPC.
SERVER=https://$(gcloud container clusters describe <cluster> --zone <zone> --format='value(endpoint)')
CA=$(gcloud container clusters describe <cluster> --zone <zone> --format='value(masterAuth.clusterCaCertificate)')
Use --region instead of --zone for a regional cluster. A private
cluster answers only inside its VPC: either authorise your address in the control plane's
authorised networks, or reach it over a VPN.
SERVER=https://$(az aks show -g <resource-group> -n <cluster> --query fqdn -o tsv)
CA=$(kubectl config view --raw --minify -o jsonpath='{.clusters[0].cluster.certificate-authority-data}')
CLUSTER_ID=<cluster-id>
SERVER=$(yc managed-kubernetes cluster get --id $CLUSTER_ID --format json | jq -r .master.endpoints.external_v4_endpoint)
CA=$(yc managed-kubernetes cluster get --id $CLUSTER_ID --format json | jq -r .master.master_auth.cluster_ca_certificate | base64 | tr -d '
')
The cluster needs a public endpoint, or nothing outside the VPC — including your phone — can reach it. This is the same thing Yandex's own documentation calls a “static configuration file”.
kubeadm, k3s, Talos and hand-built clusters usually hand out a client certificate, which works as it is. If you would rather use a scoped token, take the address and CA from the config you already have:
SERVER=$(kubectl config view --minify -o jsonpath='{.clusters[0].cluster.server}')
CA=$(kubectl config view --raw --minify -o jsonpath='{.clusters[0].cluster.certificate-authority-data}')
TOKEN=$(kubectl create token foredeck -n default --duration=8760h)
and put $SERVER, $CA and $TOKEN into a kubeconfig —
Foredeck's Credentials screen prints the exact document, ready to copy.
The kubeconfig references paths like /home/you/.kube/client.crt. Re-export
it with the contents inline:
kubectl config view --raw --minify --flatten
Clusters reached by IP usually present a certificate for the name
kubernetes. Add tls-server-name: kubernetes to the cluster
entry in your kubeconfig.
iOS asks permission before an app may reach addresses on your local network. Allow it when prompted, or turn it on in iOS Settings → Foredeck → Local Network.
Two possible reasons, both deliberate. The cluster may be marked read-only in Foredeck — swipe it in the cluster list and open Settings. Otherwise your credential does not have permission: Foredeck asks the cluster what you may do before offering to do it.
Feature requests are welcome at kozlovskyaid@icloud.com. Exec into a container and port-forward are the two most asked for, and both are on the way.
Kubernetes is a registered trademark of The Linux Foundation. Foredeck is an
independent client and is not affiliated with, endorsed by or sponsored by
The Linux Foundation or the Kubernetes project.
© 2026 Andrew Kozlowskiy