中文 日本語
home / by integration / Kubernetes

AI Agents That Work With Kubernetes (2026)

As of Sep 9, 2026, 10 AI agents in the KanonAgent index are judged to connect to Kubernetes; this page covers the top 8 by real traction (8 with the source line quoted). Judgements come from quoted evidence, not vendor claims — where we cannot read it, we leave it blank.
Connecting an agent to Kubernetes lets it provision infrastructure, watch live deployments, or run sandboxes directly on the cluster instead of simulating them. This matters now because more agents are moving from local containers to production-grade orchestration with real metrics and events. The agents below were selected only where evidence shows explicit Kubernetes usage.
Updated 2026-09-09 · 8 products · live data from KanonAgent
1. substrate672 upvotes
Substrate builds and runs autonomous agents; the Kubernetes integration provisions the actual runtime infrastructure for them.
source: “leverages Kubernetes for the infrastructure provisioning”
AgentNest provides self-hosted sandboxes; it deploys those sandboxes on your Kubernetes cluster for isolated agent testing.
source: “your Docker or Kubernetes; third-party backends via entry points”
3. Archwise2 upvotes
Archwise turns product ideas into multi-cloud architectures; it includes Kubernetes as a target environment with cost and security checks.
source: “AWS, Azure, GCP, and Kubernetes”
TellIaC generates infrastructure from plain English; it provisions the resulting setup directly onto Kubernetes clusters.
source: “provisions it across AWS, Azure, GCP, and Kubernetes”
Cynative builds custom security agents; the Kubernetes integration lets them reason over cluster events and resources.
source: “reasoning through GitHub, GitLab, AWS, GCP, Azure and Kubernetes”
Arness automates the full path from idea to deployed app; it handles Kubernetes infrastructure as part of the one-click workflow.
source: “ai-workflows,claude-code,claude-code-plugin,cli-tool,developer-tools,infrastructure-as-code,kubernetes,mcp,mit-license,open-source,plugin-marketplace,”
7. Skyportal1 upvotes
Skyportal acts as an AI infra engineer; it watches Kubernetes events, deployments, GPU metrics, and logs to diagnose issues.
source: “watches your deployments, Kubernetes events, GPU metrics and logs”
MaskShift is a coding agent that writes and debugs code; it uses Kubernetes (alongside containers) for execution and checkpoints.
source: “Git worktrees and checkpoints, LSP, browsers over CDP, containers and Kubernetes, SSH and rsync”

What the data says

Computed from our index over the 8 products on this page; judgement fields are left blank where we cannot read them (methodology).
AutonomyL3 × 2 · L2 × 2 (4/8 judged)
Prerequisitesopen source × 5 · self-hostable × 3
Common integrationsKubernetes × 8 · AWS × 3 · Azure × 3 · Google Cloud × 3 · MCP (Model Context Protocol) × 2
In the index since2026-07-17 — 2026-09-09
Ranked by real traction from our index — not editorial picks, and no paid placement. Every judgement field requires a source quote; where we cannot read it, we leave it blank. Full criteria, thresholds and known limits: methodology.

Before you wire it up

Choose by how deeply the agent touches the cluster: Skyportal and substrate read live events and metrics, while TellIaC and Archwise only generate manifests. Check the permission scope required—agents that watch events need broader RBAC than those that just export YAML. Rate limits and breakage usually appear when the agent tries to apply changes without approval gates or when it lacks access to the Kubernetes API server from its own runtime.

FAQ

Which agents can actually apply changes to a live cluster?
Skyportal and substrate have evidence of watching and acting on real Kubernetes resources; most others only generate or export manifests.
Do any require cluster-admin rights?
The quoted evidence does not specify exact RBAC scopes, so you must review each agent's documented permissions before granting access.
What breaks most often with these integrations?
Missing service accounts, network policies that block the agent's pod from the API server, and lack of approval gates before applying generated manifests.

Explore more