Skip to main content
kx — kubectl, indexed.

kubectl, indexed

PyPI version License CI

kx is a kubectl wrapper that adds index-based resource selection. Run kx get <resource> once, then reference any result by number instead of typing full resource names.

kx demo

Install

Requires kubectl on your PATH. Every install path below delivers the same prebuilt binary — no Python runtime, no dependencies.

With uv (recommended):

uv tool install kx-cli

With pipx:

pipx install kx-cli

With pip:

pip install kx-cli

As a kubectl plugin via krew, where kx is published as idx:

kubectl krew install idx
alias kx="kubectl idx"

Standalone binaries for linux, macOS and Windows (amd64/arm64) are attached to each GitHub Release, with checksums in SHA256SUMS.

On macOS, the first run of a freshly installed krew plugin or standalone binary takes a few seconds while Gatekeeper scans the binary; later runs are unaffected until the next install. Get it over with up front:

kx --version >/dev/null

Or try it without installing (the package is kx-cli, the command is kx):

uvx --from kx-cli kx get pods
pipx run --spec kx-cli kx get pods

Usage

kx get <resource> fetches resources and assigns each row an index; every other command takes those indexes. Extra flags pass through to kubectl (-n <namespace>, selectors, ...), and --match/-m filters rows by name substring. All-namespace listings (-A) are display-only — names aren't unique across namespaces.

Known kinds can drop the get: kx pods, kx deploy -n kube-system, kx svc --match api — kubectl shorthands (po, deploy, svc, sts, ...) included. An integer after a kind relists just that index: kx po 3. CRDs and other resource types still use kx get <resource>.

Global flags: --no-color disables styled output, -v/--version prints the installed version, and -h/--help on any command shows usage, examples, and aliases.

Commands

Command Description
kx get <resource> [--decode] [--key/-k str] [--match/-m str] [--yes/-y] [kubectl flags...] List resources and assign index numbers for use with other commands; shorthand: kx (e.g. kx pods, kx po 3).
kx secret [<index>...] [--decode] [--key/-k str] [--match/-m str] [--yes/-y] [kubectl flags...] List Secrets like kx get, or show an indexed Secret's data with --decode; alias: kx secrets.
kx top [--match/-m str] [--no-limits] [kubectl flags...] List CPU/memory usage for pods in the current namespace and assign index numbers, like kx get; shows usage as a percent of each pod's resource limits unless --no-limits.
kx describe <index>... [kubectl flags...] Show full kubectl describe output for one or more indexed resources.
kx events <index>... Show Kubernetes events for one or more indexed resources.
kx logs <index>... [kubectl flags...] Stream logs for an indexed resource; aggregates across pods for Deployments, StatefulSets, DaemonSets, and Services.
kx labels <index>... [--selector/-s] Show labels for one or more indexed resources; --selector formats output as a label selector.
kx annotations <index>... Show annotations for one or more indexed resources.
kx label <index> [<key=value>...] [--overwrite] [--remove str] Set or remove labels on an indexed resource.
kx annotate <index> [<key=value>...] [--overwrite] [--remove str] Set or remove annotations on an indexed resource.
kx yaml <index>... [--show str] Print the raw YAML manifest for one or more indexed resources; --show filters to specific top-level fields.
kx delete <index>... [--yes/-y] Delete one or more indexed resources (prompts for confirmation unless --yes).
kx edit <index> [kubectl flags...] Open an indexed resource in your editor via kubectl edit.
kx exec <index> [<command>...] [kubectl flags...] Open an interactive shell in an indexed pod (bash, falling back to sh).
kx tree [<index>] [--index/-i] Show the ownership graph for an indexed resource, or the whole current namespace when no index is given; --index assigns indexes to tree nodes. A Namespace index graphs that namespace.
kx rollout <action> <index> Run a rollout action (status, restart, pause, resume, history, undo) on a Deployment, StatefulSet, or DaemonSet.
kx scale <index> <replicas> Scale an indexed Deployment, StatefulSet, or ReplicaSet to a given replica count.
kx scan [<index>] [--engine str] [--full] [scanner flags...] Scan the unique container images of an indexed workload for vulnerabilities, or the whole namespace when no index is given; prints a severity summary table by default, or the raw scanner output with --full. Requires the Docker Scout CLI plugin (https://docs.docker.com/scout/).
kx port-forward <index> <port> [kubectl flags...] Forward a local port to an indexed resource (Pod, Deployment, ReplicaSet, StatefulSet, DaemonSet, Service).
kx diagnostic [<index>] Diagnose an indexed Deployment, StatefulSet, DaemonSet, Job, CronJob, Service, PersistentVolumeClaim, or Pod, or triage the whole namespace when no index is given; alias: kx diag.
kx namespace [<index>] List namespaces, or switch to an indexed one; alias: kx ns.
kx context [<index>] List kubeconfig contexts, or switch to an indexed one; alias: kx contexts.
kx state [<position>] [--all/-a] Show current state, jump to a history position, or list all entries with --all.
kx drop <position> Remove a history entry by position (shown in kx state --all).
kx back Navigate to the previous kx get result.
kx forward Navigate to the next kx get result.
kx theme [<name>] List available color themes or persist a choice by name or index.

Triage a namespace

Bare kx diag sweeps the current namespace — Deployments, StatefulSets, DaemonSets, Jobs, CronJobs, Services, and PersistentVolumeClaims, plus pods nothing owns — and prints a ranked table of what's unhealthy. Findings also draw on live resource usage (kx top): a pod running hot against its memory limit is flagged as an OOMKill risk before it dies. The rows are indexed, so kx diag 1 or kx logs 2 drill straight in.

kx diag demo

kx diag <index> diagnoses a single resource: a verdict banner, a SUMMARY of findings (CrashLoopBackOff, image pull failures, OOMKills, unschedulable pods, stalled rollouts, missing Service endpoints, Pending PVCs, failed CronJob runs, usage near limits), a per-pod status table, recent log tails from broken containers, and warning events — one screen instead of four kubectl commands.

Read a Secret in plaintext

kx secret <index> --decode prints an indexed Secret's keys and values decoded, instead of the base64 kubectl returns. Values that aren't text show a <binary, N bytes> placeholder rather than garbling the table. --key/-k prints a single value raw — no banner, no wrapping — so it drops straight into a shell: export PGPASSWORD=$(kx secret 1 --decode -k password), or redirect a binary value to a file. Bare kx secret --decode decodes every Secret in the namespace in one call, -n included — it confirms first unless you pass --yes/-y, since that prints every credential in the namespace.

kx secret --decode demo

Scan images for vulnerabilities

kx scan <index> scans the unique container images of an indexed workload (init containers and CronJob job templates included); bare kx scan sweeps every workload in the namespace. Results come back as a severity summary, or the full per-image CVE report with --full. Requires Docker Scout.

kx scan demo

State

kx maintains a history of up to 10 kx get results in ~/.kx/state.json. A cursor tracks your current position; index-based commands always resolve against the entry at the cursor. kx state --all lists the history, kx state <position> jumps to an entry, kx back/kx forward step through it, and kx drop <position> removes one.

Configuration

kx reads ~/.kx/config.toml; environment variables override file settings.

Key Env var Default Description
max_history KX_MAX_HISTORY 10 Number of kx get results kept in history.
shells KX_SHELLS (comma-separated) ["bash", "sh"] Shell candidates for kx exec.
no_color KX_NO_COLOR false Disable styled output (same as --no-color).
theme KX_THEME "github-dark" Color theme for all output.

Styled output is emitted only when stdout is a terminal — piped or redirected output is plain text, so kx get pods | grep worker stays clean. The NO_COLOR convention is honored as well.

Themes

kx theme lists the available themes with a preview of each; kx theme <name|index> persists a choice to ~/.kx/config.toml.

kx theme demo

Prefab themes: github-dark (default), dracula, nord, gruvbox, solarized-dark, catppuccin-mocha, tokyo-night, rose-pine, mono, light (for light terminal backgrounds), and plain (no styling at all).

Development

python -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

Run the CLI directly:

python -m kx.main --help

The demo GIFs are rendered from VHS tapes — see demo/README.md for seeding the demo namespace and re-recording.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

kx_cli-0.1.1-py3-none-win_arm64.whl (42.9 MB view details)

Uploaded Python 3Windows ARM64

kx_cli-0.1.1-py3-none-win_amd64.whl (46.2 MB view details)

Uploaded Python 3Windows x86-64

kx_cli-0.1.1-py3-none-musllinux_1_2_x86_64.whl (45.1 MB view details)

Uploaded Python 3musllinux: musl 1.2+ x86-64

kx_cli-0.1.1-py3-none-musllinux_1_2_aarch64.whl (42.5 MB view details)

Uploaded Python 3musllinux: musl 1.2+ ARM64

kx_cli-0.1.1-py3-none-manylinux_2_17_x86_64.whl (45.1 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64

kx_cli-0.1.1-py3-none-manylinux_2_17_aarch64.whl (42.5 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64

kx_cli-0.1.1-py3-none-macosx_11_0_arm64.whl (43.6 MB view details)

Uploaded Python 3macOS 11.0+ ARM64

kx_cli-0.1.1-py3-none-macosx_10_9_x86_64.whl (45.9 MB view details)

Uploaded Python 3macOS 10.9+ x86-64

File details

Details for the file kx_cli-0.1.1-py3-none-win_arm64.whl.

File metadata

  • Download URL: kx_cli-0.1.1-py3-none-win_arm64.whl
  • Upload date:
  • Size: 42.9 MB
  • Tags: Python 3, Windows ARM64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for kx_cli-0.1.1-py3-none-win_arm64.whl
Algorithm Hash digest
SHA256 4e7b20532946310cacc3598d72df6b301b8f59864d9411edae913377e256fb96
MD5 0b6c610fd3182a849f06d8dd93d4270e
BLAKE2b-256 8eeef00ddcbe3597d5e26212dc8058319565a2fb8b8f6d48f4531e063e5fe147

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-win_amd64.whl.

File metadata

  • Download URL: kx_cli-0.1.1-py3-none-win_amd64.whl
  • Upload date:
  • Size: 46.2 MB
  • Tags: Python 3, Windows x86-64
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.12.3

File hashes

Hashes for kx_cli-0.1.1-py3-none-win_amd64.whl
Algorithm Hash digest
SHA256 b8da44389a13442ccb7062a56db1d9cc1a4a0ffe87d6c9f3d71de6144c921530
MD5 7588b3812d7018811a9be9bc6e978ed5
BLAKE2b-256 b91cfd8296ffe11cae06a2c41f13ac07c327f41aa2b7698bff38d5bf3d1594cc

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.1-py3-none-musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 9c9667d142e12911b91bfc8ae311f3aaf3f9f5825b6d9dd08ddbc21566818be2
MD5 c52186f3cbca6297248be9d979250fd7
BLAKE2b-256 e60f72a2d9e6e1eae3d74e35ff1a9f2f6d82f1c3688013324b861a41a30219f1

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.1-py3-none-musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 957f93dace87a330ef9cfb8e244d71999487eac41e8b6a5dc6719a223c638604
MD5 4f59cb0da9da6559e7728b9ef3e30e77
BLAKE2b-256 6babdd0f4595dd1d5b229a8c6ed7d1bbac19f49a8e20ced727e915bad2c42946

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-manylinux_2_17_x86_64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.1-py3-none-manylinux_2_17_x86_64.whl
Algorithm Hash digest
SHA256 918f1da5c680692c403ec05c08b27acab4d93bb2d46f75e8cad3c08a2f6e9c08
MD5 ad62f7e8f0263287aec38d87d2786532
BLAKE2b-256 fde18a8c5b617cce1baf151bd12759333c0a83e1d2fafd4fd746bb237138176e

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-manylinux_2_17_aarch64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.1-py3-none-manylinux_2_17_aarch64.whl
Algorithm Hash digest
SHA256 d0329446f2e1ffd535cfac02d969339f3f32865fed00874bff321c6ebfaa5bb5
MD5 445afcb459bbbdcc37a8294ea04abbc9
BLAKE2b-256 db18b06707d9066977c1b256faa9177013c14413a191f49ff08e277d01f598e4

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.1-py3-none-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 2fd43a70a3103f3c6b24a57d1ac86a5d97f944820ca8b4e1a6e386e8dcecfb4c
MD5 8d4d4f7c0bb7b0c8e33f5a623f980a8d
BLAKE2b-256 fff3c953f824ef436f69f21431515e540195369050c172c570448025c9491077

See more details on using hashes here.

File details

Details for the file kx_cli-0.1.1-py3-none-macosx_10_9_x86_64.whl.

File metadata

File hashes

Hashes for kx_cli-0.1.1-py3-none-macosx_10_9_x86_64.whl
Algorithm Hash digest
SHA256 317b1a1fdc50555222de49fe6983be91bb3938c4c23db8dadf6d42cf04266fca
MD5 8a372da401fa3ea7141057df395c040a
BLAKE2b-256 019bc2c487cd04deb5c6f6a88f8d3a558e9b4f96b67b2dcf68fa40082520e088

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page