Skip to main content
kx — kubectl, indexed.

kubectl, indexed

PyPI version License CI

kx is a kubectl wrapper that adds index-based resource selection. Run kx get <resource> once, then reference any result by number instead of typing full resource names.

kx demo

Install

Requires kubectl on your PATH. Every install path below delivers the same prebuilt binary — no Python runtime, no dependencies.

With uv (recommended):

uv tool install kx-cli

With pipx:

pipx install kx-cli

With pip:

pip install kx-cli

As a kubectl plugin via krew, where kx is published as idx:

kubectl krew install idx
alias kx="kubectl idx"

Standalone binaries for linux, macOS and Windows (amd64/arm64) are attached to each GitHub Release, with checksums in SHA256SUMS.

On macOS, the first run of a freshly installed krew plugin or standalone binary takes a few seconds while Gatekeeper scans the binary; later runs are unaffected until the next install. Get it over with up front:

kx --version >/dev/null

Or try it without installing (the package is kx-cli, the command is kx):

uvx --from kx-cli kx get pods
pipx run --spec kx-cli kx get pods

Usage

kx get <resource> fetches resources and assigns each row an index; every other command takes those indexes. Extra flags pass through to kubectl (-n <namespace>, selectors, ...), and --match/-m filters rows by name substring. All-namespace listings (-A) are display-only — names aren't unique across namespaces.

Known kinds can drop the get: kx pods, kx deploy -n kube-system, kx svc --match api — kubectl shorthands (po, deploy, svc, sts, ...) included. An integer after a kind relists just that index: kx po 3. CRDs and other resource types still use kx get <resource>.

Global flags: --no-color disables styled output, -v/--version prints the installed version, and -h/--help on any command shows usage, examples, and aliases.

Commands

Command Description
kx get <resource> [--decode] [--key/-k str] [--match/-m str] [--yes/-y] [kubectl flags...] List resources and assign index numbers for use with other commands; shorthand: kx (e.g. kx pods, kx po 3).
kx secret [<index>...] [--decode] [--key/-k str] [--match/-m str] [--yes/-y] [kubectl flags...] List Secrets like kx get, or show an indexed Secret's data with --decode; alias: kx secrets.
kx top [--match/-m str] [--no-limits] [kubectl flags...] List CPU/memory usage for pods in the current namespace and assign index numbers, like kx get; shows usage as a percent of each pod's resource limits unless --no-limits.
kx describe <index>... [kubectl flags...] Show full kubectl describe output for one or more indexed resources.
kx events <index>... Show Kubernetes events for one or more indexed resources.
kx logs <index>... [kubectl flags...] Stream logs for an indexed resource; aggregates across pods for Deployments, StatefulSets, DaemonSets, and Services.
kx labels <index>... [--selector/-s] Show labels for one or more indexed resources; --selector formats output as a label selector.
kx annotations <index>... Show annotations for one or more indexed resources.
kx label <index> [<key=value>...] [--overwrite] [--remove str] Set or remove labels on an indexed resource.
kx annotate <index> [<key=value>...] [--overwrite] [--remove str] Set or remove annotations on an indexed resource.
kx yaml <index>... [--show str] Print the raw YAML manifest for one or more indexed resources; --show filters to specific top-level fields.
kx delete <index>... [--yes/-y] Delete one or more indexed resources (prompts for confirmation unless --yes).
kx edit <index> [kubectl flags...] Open an indexed resource in your editor via kubectl edit.
kx exec <index> [<command>...] [kubectl flags...] Open an interactive shell in an indexed pod (bash, falling back to sh).
kx tree [<index>] [--index/-i] Show the ownership graph for an indexed resource, or the whole current namespace when no index is given; --index assigns indexes to tree nodes. A Namespace index graphs that namespace.
kx rollout <action> <index> Run a rollout action (status, restart, pause, resume, history, undo) on a Deployment, StatefulSet, or DaemonSet.
kx scale <index> <replicas> Scale an indexed Deployment, StatefulSet, or ReplicaSet to a given replica count.
kx scan [<index>] [--engine str] [--full] [scanner flags...] Scan the unique container images of an indexed workload for vulnerabilities, or the whole namespace when no index is given; prints a severity summary table by default, or the raw scanner output with --full. Requires the Docker Scout CLI plugin (https://docs.docker.com/scout/).
kx port-forward <index> <port> [kubectl flags...] Forward a local port to an indexed resource (Pod, Deployment, ReplicaSet, StatefulSet, DaemonSet, Service).
kx diagnostic [<index>] Diagnose an indexed Deployment, StatefulSet, DaemonSet, Job, CronJob, Service, PersistentVolumeClaim, or Pod, or triage the whole namespace when no index is given; alias: kx diag.
kx namespace [<index>] List namespaces, or switch to an indexed one; alias: kx ns.
kx context [<index>] List kubeconfig contexts, or switch to an indexed one; alias: kx contexts.
kx state [<position>] [--all/-a] Show current state, jump to a history position, or list all entries with --all.
kx drop <position> Remove a history entry by position (shown in kx state --all).
kx back Navigate to the previous kx get result.
kx forward Navigate to the next kx get result.
kx theme [<name>] List available color themes or persist a choice by name or index.

Triage a namespace

Bare kx diag sweeps the current namespace — Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, Services, and PersistentVolumeClaims, plus pods nothing owns — and prints a ranked table of what's unhealthy. Findings also draw on live resource usage (kx top): a pod running hot against its memory limit is flagged as an OOMKill risk before it dies. The rows are indexed, so kx diag 1 or kx logs 2 drill straight in.

kx diag demo

kx diag <index> diagnoses a single resource: a verdict banner, a SUMMARY of findings (CrashLoopBackOff, image pull failures, OOMKills, unschedulable pods, stalled rollouts, missing Service endpoints, Pending PVCs, failed CronJob runs, usage near limits), a per-pod status table, recent log tails from broken containers, and warning events — one screen instead of four kubectl commands.

Read a Secret in plaintext

kx secret <index> --decode prints an indexed Secret's keys and values decoded, instead of the base64 kubectl returns. Values that aren't text show a <binary, N bytes> placeholder rather than garbling the table. --key/-k prints a single value raw — no banner, no wrapping — so it drops straight into a shell: export PGPASSWORD=$(kx secret 1 --decode -k password), or redirect a binary value to a file. Bare kx secret --decode decodes every Secret in the namespace in one call, -n included — it confirms first unless you pass --yes/-y, since that prints every credential in the namespace.

kx secret --decode demo

Scan images for vulnerabilities

kx scan <index> scans the unique container images of an indexed workload (init containers and CronJob job templates included); bare kx scan sweeps every workload in the namespace. Results come back as a severity summary, or the full per-image CVE report with --full. Requires Docker Scout.

kx scan demo

State

kx maintains a history of up to 10 kx get results in ~/.kx/state.json. A cursor tracks your current position; index-based commands always resolve against the entry at the cursor. kx state --all lists the history, kx state <position> jumps to an entry, kx back/kx forward step through it, and kx drop <position> removes one.

Configuration

kx reads ~/.kx/config.toml; environment variables override file settings.

Key Env var Default Description
max_history KX_MAX_HISTORY 10 Number of kx get results kept in history.
shells KX_SHELLS (comma-separated) ["bash", "sh"] Shell candidates for kx exec.
no_color KX_NO_COLOR false Disable styled output (same as --no-color).
theme KX_THEME "github-dark" Color theme for all output.

Styled output is emitted only when stdout is a terminal — piped or redirected output is plain text, so kx get pods | grep worker stays clean. The NO_COLOR convention is honored as well.

Themes

kx theme lists the available themes with a preview of each; kx theme <name|index> persists a choice to ~/.kx/config.toml.

kx theme demo

Prefab themes: github-dark (default), dracula, nord, gruvbox, solarized-dark, catppuccin-mocha, tokyo-night, rose-pine, mono, light (for light terminal backgrounds), and plain (no styling at all).

Development

python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

Run the CLI directly:

python -m kx.main --help

The demo GIFs are rendered from VHS tapes — see demo/README.md for seeding the demo namespace and re-recording.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

kx_cli-0.1.0-py3-none-win_arm64.whl (42.8 MB view details)

Uploaded Python 3Windows ARM64

kx_cli-0.1.0-py3-none-win_amd64.whl (46.1 MB view details)

Uploaded Python 3Windows x86-64

kx_cli-0.1.0-py3-none-musllinux_1_2_x86_64.whl (45.0 MB view details)

Uploaded Python 3musllinux: musl 1.2+ x86-64

kx_cli-0.1.0-py3-none-musllinux_1_2_aarch64.whl (42.4 MB view details)

Uploaded Python 3musllinux: musl 1.2+ ARM64

kx_cli-0.1.0-py3-none-manylinux_2_17_x86_64.whl (45.0 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

kx_cli-0.1.0-py3-none-manylinux_2_17_aarch64.whl (42.4 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

kx_cli-0.1.0-py3-none-macosx_11_0_arm64.whl (43.6 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

kx_cli-0.1.0-py3-none-macosx_10_9_x86_64.whl (45.9 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file kx_cli-0.1.0-py3-none-win_arm64.whl.

File metadata

  • Download URL: kx_cli-0.1.0-py3-none-win_arm64.whl
  • Upload date:
  • Size: 42.8 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for kx_cli-0.1.0-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 3e4f4c9891b81c950e6563b7270e5ebc893ffc189abc8b3ef23098f9a4fa6be6
MD5 188a6e05e581ea42f5a2ce6eb81b29f6
BLAKE2b-256 5a746a2a10f221f91f106e0d733fc75439627231b29b986937cc97d3b4879fe4

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-win_amd64.whl.

File metadata

  • Download URL: kx_cli-0.1.0-py3-none-win_amd64.whl
  • Upload date:
  • Size: 46.1 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for kx_cli-0.1.0-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 c4c998186eee944cca34ef6d056599cb168f82b9b53ecc3f79d0e58769564790
MD5 36037d1f84326713370699427ce08acb
BLAKE2b-256 63c2d39365d8de90681b51e07d75031d6831c9f4f0bf3a101dae8967c2f091e3

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.0-py3-none-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 c27213c92d16dc4ad4fc8438aa1de5de68163b73cb59b4343cfb586ce42d6966
MD5 5de3019d595e3d10d321967728421569
BLAKE2b-256 c1ee7956cdd842b8eebecd95fe7c5245c773b154724126f99ddba722b247c44e

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.0-py3-none-musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 311129ac8aae1ae9d820fbf9965926c07bca64f8411ed767529fc6b48ca8a894
MD5 118824deb9e64f04a5578f51dde932d3
BLAKE2b-256 74ad0952844fb65a60f55f81c594e453c3d8bce1b72efda838725472ecf8e6c0

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-manylinux_2_17_x86_64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.0-py3-none-manylinux_2_17_x86_64.whl
Algorithm Hash digest
SHA256 1c52f96d817b3e9ea9226d5b647089c5df5f1de2469b9d54c84b6b1cadc7d3e0
MD5 91cc023f7ae77c760b78688ffb293111
BLAKE2b-256 d68f45a22e11224d108e2a2c1dfce09d5ec70c59eccc09519082fdccaabdd129

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-manylinux_2_17_aarch64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.0-py3-none-manylinux_2_17_aarch64.whl
Algorithm Hash digest
SHA256 b4c5a1e2d82a8d0573b009b9b801aa20344e411eb46af04a2004be7c27fc6eeb
MD5 63899b7d9db0d4fee82dc6181084d2ce
BLAKE2b-256 be3e933b5e8397dd66870abbc8a7bd1af1c6df83615226567fc701c9d13e2382

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.0-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 a50d2bd6afc030c287841a6da987c3f185871c62c6b59ca401fa5712b9504d07
MD5 9466d6b09171128b0bb8557518345a07
BLAKE2b-256 086be2bc219ad99f3ae4cb367f721c0cfa8c22195c31eeb3b71786ec55358e77

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.0-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.0-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 fa31fb67936f33778fbfd562fcae344097e1e386de1e120ce951ba3db5efbba9
MD5 a3da2153c3c4d23950e34c752f64a19e
BLAKE2b-256 c296be77fc906668dbec1bb791b41b83abf9978bc4def7597f917d949c943d67

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page