KubeHerodocs · v0.3.0

Compatibility

Point Grafana, Promtail, Grafana Alloy, Fluent Bit, the OpenTelemetry Collector, Pyroscope SDKs, OpenCost clients, FinOps tools, Alertmanager and MCP clients at KubeHero — with config snippets.

KubeHero speaks the wire formats your tools already use. Adopting it is a configuration change: keep your dashboards, shippers and pipelines, and point them here.

All HTTP APIs below are served by the control plane on its service port — in-cluster, http://kubehero-control-plane.kubehero-system.svc:8080 — and authenticate with the same bearer tokens as the rest of the API. Pushes need a token with at least the member role; queries need viewer. See Identity for tokens and roles.

You runTalks to KubeHero viaSection
GrafanaLoki datasource, PrometheusGrafana
Promtail, Grafana Alloy, Fluent BitLoki push APILog shippers
OpenTelemetry CollectorOTLP/HTTP logsOpenTelemetry
Pyroscope SDKsPyroscope /ingestProfiles
OpenCost / Kubecost API clients/allocation/computeOpenCost
FinOps toolsFOCUS 1.2 CSVFOCUS
Slack, PagerDuty, Opsgenie, Teams, Discord, webhooks, Alertmanageralert channelsAlerting
Claude and MCP clientskubehero mcpMCP
Karpenter, Cluster Autoscaler, HPA, KEDA, VPA, Trivyruns beside themAutoscalers

Grafana

Logs — the Loki datasource

KubeHero implements Loki's query API (query_range, query, labels, label/{name}/values, series, index/volume, index/stats, status/buildinfo), so Grafana's built-in Loki data source works for Explore, dashboards and Grafana-managed alerts.

# provisioning/datasources/kubehero.yaml
apiVersion: 1
datasources:
  - name: KubeHero logs
    type: loki
    access: proxy
    url: http://kubehero-control-plane.kubehero-system.svc:8080
    jsonData:
      httpHeaderName1: Authorization
      httpHeaderName2: X-Scope-OrgID       # optional: pin one cluster
    secureJsonData:
      httpHeaderValue1: "Bearer <a viewer token>"
      httpHeaderValue2: eks-use1-prod

Loki's tenant header, X-Scope-OrgID, maps to a cluster. Multi-tenant queries (a|b) are not supported — add one data source per cluster, or leave the header off and filter with {cluster="…"}.

Metrics — Prometheus

KubeHero doesn't replace your metrics TSDB. The chart ships ServiceMonitors, recording rules and Grafana dashboards for kube-prometheus-stack — see Prometheus + Grafana and the metrics reference.

Log shippers

The collector already tails every container's logs, so you don't need a shipper for Kubernetes pods. Use these to bring in logs from elsewhere — VMs, other clusters, an existing pipeline — through the Loki push API (POST /loki/api/v1/push, JSON or protobuf + snappy).

loki.write "kubehero" {
  endpoint {
    url          = "http://kubehero-control-plane.kubehero-system.svc:8080/loki/api/v1/push"
    bearer_token = sys.env("KUBEHERO_TOKEN")
    tenant_id    = "eks-use1-prod"   // becomes the cluster
  }
}

Stream labels namespace, pod, container, app, job and level / detected_level map onto KubeHero's columns; other labels are kept as extra labels. A cluster stream label, or X-Scope-OrgID, sets the cluster.

OpenTelemetry Collector

POST /v1/logs accepts OTLP/HTTP logs, protobuf or JSON.

exporters:
  otlphttp/kubehero:
    logs_endpoint: http://kubehero-control-plane.kubehero-system.svc:8080/v1/logs
    headers:
      Authorization: "Bearer ${env:KUBEHERO_TOKEN}"

service:
  pipelines:
    logs:
      receivers: [otlp]
      processors: [k8sattributes, batch]
      exporters: [otlphttp/kubehero]

Resource attributes k8s.namespace.name, k8s.pod.name, k8s.container.name, k8s.deployment.name and service.name map onto the columns; severity_text / severity_number become the level; trace IDs are kept. OTLP traces are not ingested in v0.3.

Pyroscope SDKs

POST /ingest implements the Pyroscope HTTP ingest API (pprof and folded formats, including the SDKs' multipart uploads). Point an SDK's server address at the control plane:

# Python
import pyroscope
pyroscope.configure(
    application_name="payments-worker",
    server_address="http://kubehero-control-plane.kubehero-system.svc:8080",
    auth_token=os.environ["KUBEHERO_TOKEN"],
    tags={"namespace": "payments"},
)

For Kubernetes pods you usually don't need an SDK at all: KubeHero's eBPF profiler covers every container, and the collector scrapes pprof endpoints annotated the Pyroscope/Alloy way (profiles.grafana.com/cpu.scrape: "true"). See Profiling. Alloy's pyroscope.write uses Pyroscope's push API, which KubeHero does not implement — scrape with KubeHero's collector instead.

OpenCost API consumers

GET /allocation/compute (and /allocation) answer in OpenCost's JSON shape with OpenCost's parameters — window, aggregate, accumulate, idle, includeIdle, shareIdle, shareNamespaces:

curl -s -H "Authorization: Bearer $KUBEHERO_TOKEN" \
  "http://kubehero-control-plane.kubehero-system.svc:8080/allocation/compute?window=7d&aggregate=namespace&accumulate=true"

Scripts, reports and dashboards built on OpenCost's allocation API can switch by changing the base URL. See Cost allocation.

FinOps FOCUS

GET /api/v1/export/focus?window=30d&aggregate=workload streams a FinOps FOCUS 1.2 CSV (or kubehero cost export --format focus). Feed it to your FinOps platform next to provider billing data; KubeHero's rows are marked as allocated estimates (InvoiceIssuerName: KubeHero (allocated)).

Alerting

Alert rules route to slack://, pagerduty://, opsgenie://, teams:// (or teams+https://), discord+https://, webhook+https:// and alertmanager+https:// channels. With Alertmanager, KubeHero posts to /api/v2/alerts with labels, annotations, startsAt / endsAt and a generator URL, and your existing routing, grouping and inhibition apply. See Alerting.

MCP clients

kubehero mcp serves KubeHero's read-only tools to Claude Code, Claude Desktop and any MCP client over stdio or streamable HTTP. See Agents & MCP.

Autoscalers and scanners

ToolHow KubeHero coexists
Karpenter, Cluster AutoscalerNodes they create are priced like any other; KubeHero never provisions or removes nodes (a CeilingPolicy's nodepool.cordon step only cordons, and only when armed).
HPA, KEDARightsizing changes requests, never replica counts; recommendations are priced with the average replica count.
VPAContainers targeted by a VerticalPodAutoscaler are skipped by RightsizingPolicy apply mode.
TrivyVulnerability reports from the Trivy operator appear in the posture view, ranked by workload cost.

On this page