惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
GRAHAM CLULEY
Security Latest
Security Latest
C
Cybersecurity and Infrastructure Security Agency CISA
C
Cyber Attacks, Cyber Crime and Cyber Security
K
Kaspersky official blog
P
Privacy & Cybersecurity Law Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
V
Vulnerabilities – Threatpost
S
Security @ Cisco Blogs
S
Schneier on Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Scott Helme
Scott Helme
TaoSecurity Blog
TaoSecurity Blog
Hacker News: Ask HN
Hacker News: Ask HN
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
CERT Recently Published Vulnerability Notes
The Last Watchdog
The Last Watchdog
T
Threat Research - Cisco Blogs
W
WeLiveSecurity
P
Privacy International News Feed
T
Threatpost
I
Intezer
Cisco Talos Blog
Cisco Talos Blog
Google Online Security Blog
Google Online Security Blog
Webroot Blog
Webroot Blog
Forbes - Security
Forbes - Security
N
News and Events Feed by Topic
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Simon Willison's Weblog
Simon Willison's Weblog
T
Tor Project blog
C
Cisco Blogs
P
Palo Alto Networks Blog
V2EX - 技术
V2EX - 技术
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
A
Arctic Wolf
Schneier on Security
Schneier on Security
H
Hacker News: Front Page
O
OpenAI News
Latest news
Latest news
T
Tenable Blog
Cloudbric
Cloudbric
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
S
Securelist
AWS News Blog
AWS News Blog
S
Secure Thoughts
Spread Privacy
Spread Privacy
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
H
Help Net Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Apptio

How IBM Apptio Delivers Data Center Value in the Age of AI - Apptio Managing K8s Agent Updates at Scale with Helm and Terraform - Apptio GitOps with IBM Kubecost: Preventing Argo CD Rollbacks - Apptio GitOps with IBM Kubecost: API-Driven Rightsizing - Apptio It’s Here: Meet the New IBM Apptio Report Studio – A Faster, More Intuitive Approach to Reporting - Apptio New Tech, Same Rules: Cloud Lessons for an AI Advantage - Apptio IBM Cloudability Advanced Containers for Kubernetes FinOps - Apptio The Next Era of IT Financial Management Reporting with the New IBM Apptio Report Studio - Apptio From Guesswork to Confidence: Introducing Intelligent Forecasting for Tech Spend Planning - Apptio Smarter Technology Spend with AI-Driven Financial Intelligence - Apptio Budgets Are Up, Confidence Isn't: 2026 Global Tech Investment Insights - Apptio IBM Kubecost 3.1: Kubernetes Resource Quota Rightsizing - Apptio Driving FinOps Forward in 2025 and Beyond - Apptio ITFM Maturity: The Next CIO Imperative in the Age of Innovation - Apptio How Banks Can Optimize IT Spend Without Sacrificing Impact - Apptio Introducing IBM Apptio Product TCO: Turn Product Spend into Strategic Investments with Clear, End-to-End Total Cost of Ownership and Unit Costs: Creating a Strategic Lens for IT Investment Decisions - Apptio Workforce Management: The Engine of Strategic Portfolio Management - Apptio FinOps for AI: Enabling the Next Wave of Cloud Innovation - Apptio IBM Kubecost 3.0: Faster, Smarter, and Built for Scale - Apptio Introducing IBM Apptio Mainframe TCO: Complete Visibility into Mainframe Costs and Usage - Apptio Essential K8s Cost Metrics for Reducing Spend - Apptio The New Standard for Strategic Portfolio Management: Financial Visibility at Every Level - Apptio K8s Cost Ownership: Who’s Responsible and How to Make It Work - Apptio Kubecost 2.8: Centralized Custom Pricing and a Big Performance Leap with ClickHouse - Apptio Unlock the Power of IT Financial Management with IBM Apptio Essentials - Apptio Full Transparency for Smart AI Investments with IBM Apptio’s AI Total Cost of Ownership & Usage - Apptio What’s New in IBM Apptio Planning - Apptio Labeling in Kubernetes: From Metadata to Money-Saving Insights - Apptio Innovative Approaches to Drive Tech Spend Management with AI, Analytics, and Automation - Apptio Discover Kubecost on Apptio’s Website: Enhancing FinOps with Kubernetes Insights - Apptio How Kubecost Collections Works: From the Engineers Who Built It - Apptio Kubecost 2.7 Release Highlights - Apptio Introducing Hybrid IT TCO Impact: IBM Apptio’s Newest Solution to Manage Your Evolving Hybrid Environment - Apptio FinOps Essentials: Best Practices for Finance Teams - Apptio Upgrading Your Kubecost Experience - Apptio Kubecost 2.6 Release Highlights - Apptio Kubernetes Efficiency: Cut Waste, Not Performance - Apptio FinOps Essentials: Best Practices for Product Teams - Apptio Optimizing GPU Monitoring for AI Efficiency - Apptio Kubecost 2.5 Release Highlights - Apptio FinOps Essentials: Strategies for Smarter Cloud Spending - Apptio Achieving Cost-Effective Scaling in Kubernetes - Apptio Celebrating OpenCost’s Journey to CNCF Incubation - Apptio Unlocking Technology Value: The Essential Role of TBM in Modern IT Management - Apptio The Complex Costs of AI: Investments, Funding, and ROI Tracking - Apptio Addressing Carbon Emissions in IT: The New Business Imperative - Apptio Kubecost Brings NVIDIA GPU cost monitoring for AI workloads in 2.4 - Apptio Kubecost Launches Support for Oracle Cloud - Apptio Kubecost 2.4 Release Highlights - Apptio Evolving Container Cost Visibility with IBM Cloudability - Apptio Transforming the Way You Manage Your Digital Portfolios: IBM Apptio and ServiceNow - Apptio Maximizing Kubernetes Cost Efficiency with Kubecost and Amazon EKS - Apptio FinOps Foundations: Strategies for Cross-Team Alignment - Apptio Managing Kubernetes Costs in a Multi-Cloud Environment - Apptio Unlock Kubernetes Savings with Kubecost’s Automated Actions - Apptio Celebrating a Milestone: Kubecost Surpasses 10 Million Installs - Apptio Kubernetes Pricing: On-Premises Versus Cloud Environments - Apptio Maximizing Multi-Cloud Efficiency with Kubecost APIs - Apptio Aligning Tech Financials and Labor Resources - Apptio Kubecost 2.3 Release Highlights - Apptio IBM Cloudability Introduces New Innovations for FinOps Practitioners - Apptio Kubecost Launches the First Kubecost Certification - Apptio Enhancing Cloud Reporting: Attributing Costs to Kubernetes Applications - Apptio Building a FinOps Solution for All - Apptio Navigating the Growing Complexities of Technology Spend Management - Apptio Apptio Introduces New Products to Elevate Technology Value - Apptio Developing a Strategy for Kubernetes Cost Monitoring - Apptio Visualize your Kubernetes Network Costs - Apptio Getting Highly Accurate and Granular Cost Metrics with Kubecost - Apptio 8 Steps to Achieve Enterprise Agile Planning Success - Apptio FinOps and TBM at Public Sector Summit - Apptio Introducing Kubecost Collections - Apptio Apptio & ServiceNow launch new Application Portfolio Management capabilities - Apptio Beyond the Hype: A Balanced View of AI Adoption - Apptio 2.1 Release Highlights - Apptio Starting your Technology Business Management Journey: A Guide for Smart Technology Investments with Apptio Cost Management - Apptio IBM Cloudability: 2023 Innovation in Review - Apptio Kubecost 2.0 Packaging - Apptio Kubernetes Readiness Probe: Tutorial & Examples - Apptio Kubernetes Health Check - How-To and Best Practices - Apptio Introducing Kubecost 2.0 - Apptio Kubernetes Liveness Probe: Tutorial & Examples - Apptio Kubernetes Cluster Size: Your Guide to Optimization - Apptio EKS Cost Monitoring: The Kubecost and AWS Solution - Apptio Kubernetes Deployment Strategies: Tutorial & Examples - Apptio Automate Your Rightsizing Workflows with IBM Cloudability and ServiceNow - Apptio Kyverno and Kubecost: Real-time Kubernetes Cost Management - Apptio Making Smarter IT Decisions With Apptio Plus ServiceNow Breaking Down Silos Between Finance and Agile Teams With Lean Budgeting - Apptio Maximize Cloud Savings Without Running Afoul of AWS RI Marketplace Enforcements - Apptio Cost-Effective Deployment Policies With Kyverno - Apptio Tracking Waste on Kubernetes Clusters - Apptio Blending FinOps With Observability - Apptio 3 Key Opportunities for Finance Teams in SAFe 6.0 - Apptio Kubecost Predict Part 2: Introducing the Admission Controller - Apptio The CEO as the Chief Transformation Officer - Apptio Client Challenge Client Challenge Client Challenge
Guide to Kubernetes Management Tools - Apptio
Mike Miller · 2024-01-17 · via Apptio

There are many Kubernetes management tools available today. These tools can vary in complexity, functionality, and price.

Finding the right solution for a specific use case can be challenging with so many options. These tools cover Kubernetes cluster management categories, including cluster provisioning and application Installation to monitoring and cost management.

This article will explore the different free and open-source Kubernetes management tools available for common use cases and help you make an informed decision by detailing the strengths and drawbacks of each tool in our list.

Kubernetes management tools summary

The table below categorizes and summarizes the Kubernetes management tools we will review in this article.

Category Tool name Description
Cluster Provisioning Terraform Written in Go by Hashicorp, Terraform is a declarative, Industry standard tool for creating and managing Infrastructure as Code (IaC).
Crossplane A declarative API-driven control plane for Kubernetes that allows you to provision and manage your infrastructure in a modern, Kubernetes-based fashion.
Application installation Helm A developer-friendly, versioned package manager for deploying Kubernetes applications.
CI/CD ArgoCD A declarative GitOps Kubernetes controller that continuously deploys your applications and Kubernetes resources.
Secret Management Vault A self-managed Hashicorp tool that allows identity-based secret and encryption management.
Policy Management OPA Gatekeeper A mechanism for defining Custom Resource Definition (CRD) based rules enforced by a general-purpose policy engine.
Service Mesh Istio A flexible tool for Kubernetes networking that manages communication between applications.
Autoscaling KEDA A Kubernetes-based Event Driven Autoscaler (KEDA) that enables Kubernetes autoscaling opportunities.
Monitoring Kube-Prometheus-Stack A convenient collection of tools and manifests for monitoring, dashboarding, and alerting on Kubernetes.
Loki Created by Grafana, Loki is a scalable Kubernetes log aggregation tool.
Cost monitoring and allocation Kubecost A tool for Kubernetes cost-visibility and management.

Kubernetes management tools by category

In the sections below, we’ll explore each Kubernetes management tool in our list in more detail.

Cluster provisioning

Kubernetes cluster provisioning tools enable infrastructure as code (IaC) and streamline the process of setting up clusters.

Terraform

Written in Go by Hashicorp, Terraform is a declarative, Industry standard tool for creating and managing Infrastructure as Code (IaC).

image 11 - Guide to Kubernetes Management Tools - Apptio

Terraform is probably the most widely used tool for managing Infrastructure as Code. As well as provisioning Cloud infrastructure, you can also use Terraform to create managed Kubernetes clusters with ease on AWS, Azure or GCP. If you would like to install Kubernetes yourself on-premises or on bare-metal virtual machines (VMs) in the Cloud, you will need another tool to provision your Kubernetes clusters, such as Kubeadm or KOPS.

Strengths Considerations
✅ Cloud agnostic: you can use terraform with any Cloud provider. 📖 Applying Terraform changes locally can be error-prone. It’s best to use an automated pipeline to Plan and Apply your Terraform, such as Atlantis.
✅ Reliably and quickly deploy Infrastructure. 📖 No API, Terraform is a Command Line Interface (CLI)
✅ Terraform’s modularisation can abstract away environment-specific variables and be re-used multiple times. 📖 Any manual changes to Cloud Infrastructure via console or API will need to be replicated in Terraform code or face Infrastructure drift repercussions.
✅ Pre-built, publicly available modules.

Crossplane

A declarative API-driven control plane for Kubernetes allowing you to provision and manage your infrastructure in a modern, Kubernetes-based fashion.

image 21 - Guide to Kubernetes Management Tools - Apptio

Crossplane, a Cloud Native Computing Foundation (CNCF) project, is frequently compared to Terraform. However, while Terraform is a declarative command-line tool, Crossplane is an extension of the Kubernetes API. It extends a cluster’s capabilities to provision, manage, and orchestrate cloud infrastructure, services, and applications.

The ability to deploy infrastructure alongside your Kubernetes YAML is remarkable. However, unless you’re using Kubernetes at scale, Crossplane may not be the tool for you yet.

Strengths Considerations
✅ Always-on control loops (think Kubernetes operators) that watch and correct infrastructure configuration, which, unlike Terraform, can’t be circumvented by making changes manually. 📖 It doesn’t make sense to use if you are not using Kubernetes or want to deploy other infrastructure unrelated to Kubernetes.
✅ Easily enables self-service infrastructure. 📖 Steeper learning curve if Developers aren’t hands-on with Kubernetes.
✅ Easy installation with Helm. 📖 More complexity and abstraction, especially during debugging and troubleshooting.
✅ Cross-Cloud.

Apptio IBMKubecost ProductLogotype WithIcon Pos - Guide to Kubernetes Management Tools - Apptio

Comprehensive Kubernetes cost monitoring & optimization

Install in 5 mins or less.

Application installation

Kubernetes management tools in this category act as Kubernetes package managers.

Helm

A developer-friendly, versioned package manager for deploying Kubernetes applications.

image 31 - Guide to Kubernetes Management Tools - Apptio

Helm is a CNCF graduated project written in Go. Helm allows you to define and deploy Kubernetes applications in versioned, source-controllable packages called ‘Charts’. Charts contain Templates for Kubernetes resources. You need a Helm Chart and a YAML configuration file to make an application release.

Strengths Considerations
✅ Versioned, self-contained application packages. Helm charts use semantic versioning. 📖 Error prone when applying configuration files containing variables to templates. Alleviated by running ‘helm validate’ and ‘helm template’ locally or as part of a deployment pipeline.
✅ Easy application rollbacks 📖 Slight learning curve and another layer of abstraction.
✅ Public Charts available for many applications

CI/CD

This category of Kubernetes tools deals with CI/CD pipelines and GitOps.

ArgoCD

A declarative GitOps Kubernetes controller that will Continuously Deploy your applications.

image 41 - Guide to Kubernetes Management Tools - Apptio

ArgoCD is another CNCF graduated project. ArgoCD uses a declarative, GitOps approach that makes application deployment and lifecycle management easy and automated.

GitOps is a set of DevOps practices that uses Git repositories as a single source of truth for declarative infrastructure and application deployment.

image 51 - Guide to Kubernetes Management Tools - Apptio

ArgoCD UI demonstrating Continuous Delivery source

Strengths Considerations
✅ Immutable deployments. ArgoCD keeps your application deployments synchronized with your Git repository. 📖 Easy to cause havoc through the UI without further RBAC configuration. By default, the basic users are read-only or Admin.
✅ Allows developers to manage applications without interacting with Kubernetes

Secret management

Tools in this category are designed to keep sensitive data like API keys safe.

FinOps Strategies for Cost Analysis: Understanding and Reducing Your Cloud Bill

Vault

A self-managed Hashicorp tool that allows identity-based secret and encryption management.

image 61 - Guide to Kubernetes Management Tools - Apptio

Vault, like Terraform, is a Hashicorp product that you install and manage yourself, and can be used to manage Kubernetes secrets that can run within Kubernetes or as a standalone. Vault allows you to manage and create secrets and even manage certificates dynamically.

Strengths Considerations
✅ Secure secret management 📖 Self-hosted. Although this does have benefits, it also introduces plenty of complexity with backups, Disaster Recovery, and User management.
✅ Inject secrets directly into Kubernetes pods.

Policy Management

This category of Kubernetes management tools focuses on Kubernetes security policies.

OPA Gatekeeper

A tool for defining Custom Resource Definition (CRD) based rules enforced by a general-purpose policy engine.

image 71 - Guide to Kubernetes Management Tools - Apptio

Open Policy Agent (OPA) is an open-source, general-purpose policy engine, again part of the CNCF. OPA Gatekeeper is a Kubernetes-based validating admission webhook that enforces OPA policies on interactions with Kubernetes resources.

For instance, you could enforce that all container definitions require resource requests and limits. If a resource doesn’t meet this specification, OPA Gatekeeper rejects this resource. OPA Gatekeeper will also show any policy violations on existing resources. There is a baseline set of policies you can use as a starting point to build.

Strengths Considerations
✅ Greater support and adoption than alternatives 📖 OPA Gatekeeper uses Rego, a specialized programming language that one must learn.
✅ Policies can be extremely sophisticated 📖 Capability limited to Validation
✅ Highly available and scalable

Service mesh

Kubernetes tools in the service mesh category manage inter-app networking.

Istio

A flexible tool for Kubernetes networking that manages communication between applications.

image 81 - Guide to Kubernetes Management Tools - Apptio

A service mesh is a dedicated layer of abstraction that controls service-to-service communication over a network. Istio, another CNCF project on this list of tools, is a service mesh consisting of two parts:

  • A control plane, Istiod, manages service discovery, configurations, and certificate management.
  • A data plane consisting of an Envoy proxy.

Envoy is a proxy and communication bus for single services and applications and a data plane for large microservice “service mesh” architectures.

image 91 - Guide to Kubernetes Management Tools - Apptio

Application traffic now flows through Envoy proxies rather than directly source

Strengths Considerations
✅ You can extract telemetry data from proxy containers for observability dashboards. 📖 Added complexity due to an additional infrastructure layer.
✅ Seamless traffic management. 📖 Slightly slower application speeds due to using a proxy sidecar.
✅ Complements and enhances microservice architectures.
✅ Load balancing and Scaling.

Autoscaling

Kubernetes autoscaling tools help streamline how clusters scale up and down based on requirements.

Kubecost Installation 101: Best Practices for a Seamless Setup

KEDA

A Kubernetes-based Event Driven Autoscaler (KEDA) that enables Kubernetes autoscaling opportunities.

image 101 - Guide to Kubernetes Management Tools - Apptio

KEDA serves as a Kubernetes Metrics Server, enabling users to scale Kubernetes workloads based on specific events. KEDA complements and adds more functionality than the native Kubernetes Horizontal Pod Autoscaler (HPA), which only has a limited number of metrics that users can use to perform autoscaling. The HPA also cannot scale a deployment to 0 pods.

Some example use cases include:

  • Scaling up the number of Kafka consumers when the consumer group lag metric climbs above a certain threshold.
  • Scale pods up in response to RabittMQ queue length
  • Scale up in response to AWS Simple Queue Service (SQS) number of messages
Strengths Considerations
✅ Extended autoscaling functionality 📖 Slightly more complex to use than native autoscaling options
✅ Scale down to 0 replicas

Monitoring

Kubernetes management tools in this category enable visibility and observability to help improve cluster uptime and performance.

Kube-Prometheus-Stack

A convenient collection of tools and manifests for monitoring, dashboarding, and alerting on Kubernetes.

image 111 - Guide to Kubernetes Management Tools - Apptio

Prometheus is an open-source system monitoring and alerting toolkit, built initially by SoundCloud, now part of the CNCF. If you want metrics and cluster monitoring on Kubernetes, Prometheus is an excellent place to start. Alertmanager integrates with your notification service integration for on-call, such as email, PagerDuty, or OpsGenie. Grafana is a flexible dashboard service that plugs neatly into Prometheus.

image 121 - Guide to Kubernetes Management Tools - Apptio
An example Grafana dashboard. (Source)

Kube-Prometheus-Stack is a handy Helm installation of the Kube-Prometheus library, which includes:

  • The Prometheus Operator
  • Highly available Prometheus
  • Highly available Alertmanager
  • Prometheus node-exporter
  • Prometheus Adapter for Kubernetes Metrics APIs
  • Kube-state-metrics
  • Grafana

In other words, almost everything you need for Kubernetes cluster monitoring in a single Helm chart.

Strengths Considerations
✅ Convenient, no-hassle installation. 📖 No integrated solution for Log collection.
✅ Scrape metrics for any application using Prometheus. 📖 Needs an extra component for long-term retention.

Loki

Created by Grafana, Loki is a scalable Kubernetes log aggregation tool.

image 131 - Guide to Kubernetes Management Tools - Apptio

Loki is a scalable, highly available, multi-tenant log aggregation solution inspired by Prometheus. Loki doesn’t index the full content of the logs but just a set of labels for each log stream.

Loki has three components:

  • The agent, Promtail, sends logs to Loki.
  • The server, Loki, stores logs and processes queries.
  • Dashboards, Grafana, for visualization.

Hence, the informal name PLG stack, for Promtail, Loki, and Grafana.

Strengths Considerations
✅ Switch between Metrics and Logs using the same Prometheus labels 📖 No rich text search capabilities due to lack of full indexing
✅ Doesn’t fully index log text. Only indexing metadata is cheaper to run. 📖 Uses its own language for querying logs, called LogQL
✅ Far simpler and less resource intensive than an alternative deployment of the Elasticsearch/Logstash/Kibana (ELK) stack

Cost monitoring and allocation

Kubernetes cost management tools enable cost visibility and optimization to help you spend more efficiently.

Kubecost

A tool for Kubernetes cost-visibility and management.

kubecost - Guide to Kubernetes Management Tools - Apptio

Kubecost is a cost-monitoring and optimisation solution for Kubernetes. Its use cases include:

  • Cost allocation
  • Unified cost monitoring
  • Optimization insights
  • Cost alerts and governance.

You can install the community edition with a Helm chart and use the free tier for unlimited individual clusters.

Strengths Considerations
✅ Real-time cost allocation. 📖 Technical support is only available in Pro and Enterprise tiers.
✅ 15-day metric retention with free version. 📖 Free tier has limited data retention, which means that users can only access cost data from the past 15 days.
✅ Breakdown of monthly cluster cost, deployment resource costs, and cost efficiency. 📖 Advanced features such as granular cost allocation, detailed reports, and integration with third-party tools are not available in the free tier.
✅ Generate reports and set alerts when thresholds are crossed.

Summary

In order to strike a balance between management complexity and feature richness, we have compiled this list of some of the best Kubernetes management tools. Depending on your specific requirements, you can select any or all of these tools to help you create a feature-rich and resilient production-grade Kubernetes environment. By now, you should at least have some ideas of your preferred Kubernetes management tooling options. While using such tools is not mandatory, doing so can simplify your management tasks, save time, and reduce stress.