Skip to main content
kx — kubectl, indexed.

kubectl, indexed

PyPI version Python License CI

kx is a kubectl wrapper that adds index-based resource selection. Run kx get <resource> once, then reference any result by number instead of typing full resource names.

kx demo

Install

Requires Python 3.11+ and kubectl on your PATH.

With uv (recommended):

uv tool install kx-cli

With pipx:

pipx install kx-cli

With pip:

pip install kx-cli

As a kubectl plugin via krew, where kx is published as idx (no Python required):

kubectl krew install idx
alias kx="kubectl idx"

Standalone binaries (linux/macOS, amd64/arm64, no Python required) are attached to each GitHub Release.

Or try it without installing (the package is kx-cli, the command is kx):

uvx --from kx-cli kx get pods
pipx run --spec kx-cli kx get pods

Usage

kx get <resource> fetches resources and assigns each row an index; every other command takes those indexes. Extra flags pass through to kubectl (-n <namespace>, selectors, ...), and --match/-m filters rows by name substring. All-namespace listings (-A) are display-only — names aren't unique across namespaces.

Known kinds can drop the get: kx pods, kx deploy -n kube-system, kx svc --match api — kubectl shorthands (po, deploy, svc, sts, ...) included. An integer after a kind relists just that index: kx po 3. CRDs and other resource types still use kx get <resource>.

Global flags: --no-color disables styled output, -v/--version prints the installed version, and -h/--help on any command shows usage, examples, and aliases.

Commands

Command Description
kx get <resource> [--match/-m str] [--decode] [--key/-k str] [--yes/-y] [kubectl flags...] List resources and assign index numbers for use with other commands; shorthand: kx (e.g. kx pods, kx po 3).
kx secret [--match/-m str] [--decode] [--key/-k str] [--yes/-y] [kubectl flags...] List Secrets like kx get, or show an indexed Secret's data with --decode; alias: kx secrets.
kx top [--match/-m str] [--no-limits] [kubectl flags...] List CPU/memory usage for pods in the current namespace and assign index numbers, like kx get; shows usage as a percent of each pod's resource limits unless --no-limits.
kx describe <indexes>... [kubectl flags...] Show full kubectl describe output for one or more indexed resources.
kx events <indexes>... Show Kubernetes events for one or more indexed resources.
kx logs <index> [kubectl flags...] Stream logs for an indexed resource; aggregates across pods for Deployments, StatefulSets, DaemonSets, and Services.
kx scan [<index>] [--engine str] [--full] [kubectl flags...] Scan the unique container images of an indexed workload for vulnerabilities, or the whole namespace when no index is given; prints a severity summary table by default, or the raw scanner output with --full.
kx labels <indexes>... [--selector/-s] Show labels for one or more indexed resources; --selector formats output as a label selector.
kx annotations <indexes>... Show annotations for one or more indexed resources.
kx label <index> [<pairs>...] [--remove str] [--overwrite] Set or remove labels on an indexed resource.
kx annotate <index> [<pairs>...] [--remove str] [--overwrite] Set or remove annotations on an indexed resource.
kx yaml <indexes>... [--show str] Print the raw YAML manifest for one or more indexed resources; --show filters to specific top-level fields.
kx delete <indexes>... [--yes/-y] Delete one or more indexed resources (prompts for confirmation unless --yes).
kx edit <index> [kubectl flags...] Open an indexed resource in your editor via kubectl edit.
kx exec <index> [<cmd>...] [kubectl flags...] Open an interactive shell in an indexed pod (bash, falling back to sh).
kx tree [<index>] [--index/-i] Show the ownership graph for an indexed resource, or the whole current namespace when no index is given; --index assigns indexes to tree nodes. A Namespace index graphs that namespace.
kx rollout <action> <index> Run a rollout action (status, restart, pause, resume, history, undo) on a Deployment, StatefulSet, or DaemonSet.
kx scale <index> <replicas> Scale an indexed Deployment, StatefulSet, or ReplicaSet to a given replica count.
kx port-forward <index> <port> [kubectl flags...] Forward a local port to an indexed resource (Pod, Deployment, ReplicaSet, StatefulSet, DaemonSet, Service).
kx diagnostic [<index>] Diagnose an indexed Deployment, StatefulSet, DaemonSet, Job, CronJob, Service, PersistentVolumeClaim, or Pod, or triage the whole namespace when no index is given; alias: kx diag.
kx namespace [<index>] List namespaces, or switch to an indexed one; alias: kx ns.
kx context [<index>] List kubeconfig contexts, or switch to an indexed one; alias: kx contexts.
kx theme [<name>] List available color themes or persist a choice by name or index.
kx state [<position>] [--all/-a] Show current state, jump to a history position, or list all entries with --all.
kx drop <position> Remove a history entry by position (shown in kx state --all).
kx back Navigate to the previous kx get result.
kx forward Navigate to the next kx get result.

Triage a namespace

Bare kx diag sweeps the current namespace — Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, Services, and PersistentVolumeClaims, plus pods nothing owns — and prints a ranked table of what's unhealthy. Findings also draw on live resource usage (kx top): a pod running hot against its memory limit is flagged as an OOMKill risk before it dies. The rows are indexed, so kx diag 1 or kx logs 2 drill straight in.

kx diag demo

kx diag <index> diagnoses a single resource: a verdict banner, a SUMMARY of findings (CrashLoopBackOff, image pull failures, OOMKills, unschedulable pods, stalled rollouts, missing Service endpoints, Pending PVCs, failed CronJob runs, usage near limits), a per-pod status table, recent log tails from broken containers, and warning events — one screen instead of four kubectl commands.

Read a Secret in plaintext

kx secret <index> --decode prints an indexed Secret's keys and values decoded, instead of the base64 kubectl returns. Values that aren't text show a <binary, N bytes> placeholder rather than garbling the table. --key/-k prints a single value raw — no banner, no wrapping — so it drops straight into a shell: export PGPASSWORD=$(kx secret 1 --decode -k password), or redirect a binary value to a file. Bare kx secret --decode decodes every Secret in the namespace in one call, -n included — it confirms first unless you pass --yes/-y, since that prints every credential in the namespace.

kx secret --decode demo

Scan images for vulnerabilities

kx scan <index> scans the unique container images of an indexed workload (init containers and CronJob job templates included); bare kx scan sweeps every workload in the namespace. Results come back as a severity summary, or the full per-image CVE report with --full. Requires Docker Scout.

kx scan demo

State

kx maintains a history of up to 10 kx get results in ~/.kx/state.json. A cursor tracks your current position; index-based commands always resolve against the entry at the cursor. kx state --all lists the history, kx state <position> jumps to an entry, kx back/kx forward step through it, and kx drop <position> removes one.

Configuration

kx reads ~/.kx/config.toml; environment variables override file settings.

Key Env var Default Description
max_history KX_MAX_HISTORY 10 Number of kx get results kept in history.
shells KX_SHELLS (comma-separated) ["bash", "sh"] Shell candidates for kx exec.
no_color KX_NO_COLOR false Disable styled output (same as --no-color).
theme KX_THEME "github-dark" Color theme for all output.

Styled output is emitted only when stdout is a terminal — piped or redirected output is plain text, so kx get pods | grep worker stays clean. The NO_COLOR convention is honored as well.

Themes

kx theme lists the available themes with a preview of each; kx theme <name|index> persists a choice to ~/.kx/config.toml.

kx theme demo

Prefab themes: github-dark (default), dracula, nord, gruvbox, solarized-dark, catppuccin-mocha, tokyo-night, rose-pine, mono, light (for light terminal backgrounds), and plain (no styling at all).

Development

python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

Run the CLI directly:

python -m kx.main --help

The demo GIFs are rendered from VHS tapes — see demo/README.md for seeding the demo namespace and re-recording.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

kx_cli-0.0.11.tar.gz (108.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

kx_cli-0.0.11-py3-none-any.whl (69.8 kB view details)

Uploaded Python 3

File details

Details for the file kx_cli-0.0.11.tar.gz.

File metadata

  • Download URL: kx_cli-0.0.11.tar.gz
  • Upload date:
  • Size: 108.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for kx_cli-0.0.11.tar.gz
Algorithm Hash digest
SHA256 daa48abcfb29bd4a7aac0aab2625a8879b28e34c44b2242a7e7c849fde14a9db
MD5 935b1777eb99cfa8c96b655286e0dbb3
BLAKE2b-256 127a7bcee3db7bd07fe69835531c07e19dfa140aa534f334a4cdaf1f67ebc7f9

See more details on using hashes here.

File details

Details for the file kx_cli-0.0.11-py3-none-any.whl.

File metadata

  • Download URL: kx_cli-0.0.11-py3-none-any.whl
  • Upload date:
  • Size: 69.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for kx_cli-0.0.11-py3-none-any.whl
Algorithm Hash digest
SHA256 3663bd743fe0faa6d623f409e6403c1f6bb6fa2c3549227bd3030513d729ef32
MD5 ab718d38e8c742e8abdb9b673d82075e
BLAKE2b-256 30bc50d8df87231eeb2dc0197ea93c2557344a0ac704c41acaec972a3a1389f2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page