Skip to content
Docs · Kubeconfig editor

Clusters

Kubeconfig editor

Create, edit, test and import kubeconfigs without leaving Kubyl.

The kubeconfig editor is a form and a raw YAML view of the same file. Comments in the file are preserved, the YAML tab is schema-validated and secrets are masked with a reveal toggle.

Open it from the palette: Kubeconfig: New…, Edit Current Context, Test Current Context or Import from Cloud CLI….

The new-cluster wizard

  1. Name the context.
  2. Cluster: the server URL and its CA. Use system trust, a file, pasted PEM, or fetch it from the server after confirming its fingerprint.
  3. Credentials: client certificate, token, token file, exec plugin, OIDC provider or none. Exec presets cover AWS EKS, GKE, AKS (kubelogin) and OIDC (kubelogin).
  4. Context: user, cluster and default namespace.
  5. Test the connection.
  6. Save.

Connection test

The test walks through DNS and TCP, TLS, credentials, the API server, authentication, permissions and latency. Where it can, it offers the fix: fetching the CA, showing an install hint for a missing plugin, signing in or replacing the token.

Importing

  • From a connected cluster: create a kubeconfig for a service account using a TokenRequest, with an expiry by default.
  • From a cloud CLI: AWS (aws), Google (gcloud) and Azure (az). Kubyl shows the commands before running them.

Saving safely

  • A preview of the change is shown before saving.
  • Kubyl refuses to overwrite a file that changed on disk since it was loaded.
  • A timestamped backup goes to kubeconfig-backups/ (the last 10 are kept, mode 0600, see kubeconfig_editor.backups_kept).
  • Writes are atomic. Symlinks are followed. New files and files with inline credentials get mode 0600.

Which files you can edit

Files Kubyl owns, those under kubeconfigs/, are freely editable. External files (~/.kube/config, $KUBECONFIG files and ones you added) need a per-file opt-in via Edit this file. kubeconfig_editor.allow_external_edits (default on) controls whether the opt-in is offered at all, and editable_files remembers your choices. Save as a Kubyl copy always works.

KeysAction
CtrlSSave
CtrlShiftTTest connection
CtrlEnterTest all contexts
Ctrl1orCtrl2Form / YAML view
CtrlAltZRevert
CtrlShiftRReveal or mask secrets

Something missing or wrong? Open an issue on GitHub.