The Kubernetes control plane for platform teams

Run shared Kubernetes infrastructure
without the operational grind

EntKube is a multi-tenant developer portal that turns a fleet of clusters into self-service infrastructure. Register clusters, deploy a curated catalog of production services in one click, manage secrets, ship applications, and watch everything through a built-in observability stack — all from a single pane of glass.

30+
One-click infrastructure components
Multi-tenant
Isolated tenants, customers & environments
Built-in
Logs, traces, metrics, RUM & alerting
Self-hosted
Your clusters, your data, your registry

One platform, the whole lifecycle

Most teams stitch together a dozen tools to run internal infrastructure — GitOps for delivery, a secrets manager, a monitoring stack, an incident tool, a status page, a pile of Helm charts. EntKube brings all of it into one opinionated portal built on the Kubernetes ecosystem you already trust.

Multi-tenant control plane

Model your world as tenants, customers, environments and groups with role-based access at every level. Teams get self-service without stepping on each other.

Cluster fleet management

Register any Kubernetes cluster, then watch nodes, health, capacity and workloads across the fleet. Kubeconfigs are stored encrypted in the vault, never on disk.

One-click service catalog

Deploy Postgres, Keycloak, MinIO, Harbor, RabbitMQ, Kafka, Redis and more as managed Helm releases — with ingress, TLS and credentials wired up for you.

Application delivery

Ship apps per environment with plain YAML deployments, apply-or-recreate sync, and import wizards that adopt live cluster workloads into managed apps.

Encrypted secrets vault

A built-in vault scopes secrets per app and environment: certificates, OAuth/OIDC client secrets, kubeconfigs and more — with expiry tracking and safe sync to clusters.

Native observability

Logs, distributed traces / APM, metrics, real-user monitoring and dashboards ship in the box — powered by a self-built S3 + Lucene telemetry engine and Prometheus.

Governance & connectivity

Enforce Kyverno admission policies and author a least-privilege connectivity model that generates NetworkPolicies and Istio rules — previewed before they ever apply.

Incidents, on-call & SLAs

Alert rules and routing, notification channels, on-call schedules, incident management, SLA targets and maintenance windows — the operations layer, built in.

Customer-facing portal

Give your customers a self-service view: status dashboards, SLA reports, observability, maintenance notices and incident history — scoped strictly to their data.

Autoscaling & caching

Manage KEDA ScaledObjects and ScaledJobs per app and environment, and provision Redis caches — event-driven scale and low-latency data without leaving the portal.

Networking & VPN

Bridge clusters and operators to your network with Tailscale, Headscale, WireGuard, StrongSwan IPsec and Submariner — managed alongside everything else.

Backup & restore

Export the full platform state and restore it on new hardware. Migrate servers or recover from disaster without hand-rebuilding your configuration.

A curated catalog of production services

Pick a component, fill in a short form, and EntKube installs and wires up the Helm release for you — ingress, TLS, storage, credentials and all. Every service is vaulted, monitored, and lifecycle-managed from the same portal. Assemble ordered Cluster Blueprints to bootstrap a brand-new cluster end to end.

Explore the catalog
TraefikIstiocert-managerLet's EncryptPrometheusGrafanaLokiMimirTempoOpenTelemetryeBPF tracingMinIOCloudNativePGMongoDBKeycloakHarborRabbitMQStrimzi KafkaRedisKyvernoKEDATailscaleHeadscaleWireGuardStrongSwanSubmarinerGateway API

Ready to tame your clusters?

Sign in to your workspace, or create an account to get started.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.