Omahub
← All plugins
N

KubeContext

by Nepomuk Software

Shows the active Kubernetes context in the bar, switches between contexts and namespaces across every kubeconfig in ~/.kube, and gives a short overview of the selected cluster.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
e29c456
Scanned
4 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e29c456
Reviewed
4 weeks ago

The deterministic scan found no issues, and the sampled code is a transparent, carefully written Kubernetes widget: it parses kubeconfigs locally, quotes shell arguments, caps output and timeouts, and probes only the bound context while the panel is open. I found no obfuscation, persistence, credential theft, or install-time destructive behavior. The main risk is inherent to the plugin's purpose: it runs kubectl, can rewrite kubeconfig context/namespace entries, and can start/stop Kind Docker containers, all documented and user-triggered.

  • Opening the panel runs kubectl against the active kubeconfig, so any exec-based credential plugin in the default kubeconfig will be executed while the panel is open; this is standard Kubernetes tool behavior and is disclosed in the README.
  • Explicit user actions can change the global current-context and namespace in ~/.kube/config and can start or stop Docker containers for kind-* clusters, which is a powerful capability even though it requires user consent.
  • The full repository was only sampled rather than exhaustively reviewed; the provided files show no hidden install steps, persistence, or malicious behavior.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Nepomuk-Software/KubeWidget --enable
Developer Tools #bar #quickshell

KubeContext for Omarchy

Shows the active kubectl context in the bar, switches between contexts with a click (or a right-click picker that never talks to a cluster), sets the current namespace, and gives a short overview of the selected cluster.

(Deutsche Fassung: README.de.md.)

Preview

  • Bar — the current context name next to a Kubernetes icon, so the context you are about to run a command against is never a guess. Optionally the namespace too. Tints if the last probe found the cluster unreachable or pods not running — without starting a new probe while the panel is closed.
  • Picker — right-click the icon to switch context. That write is local; no API server is contacted.
  • Contexts — every kubeconfig file sitting directly in ~/.kube (not cache/), grouped by file. Two files that both have a context named default are two rows. Listing is a local YAML/JSON parse — kubectl is not run against extra files, so a credential exec plugin in a file you did not pick cannot start when the panel opens. Switching a context in ~/.kube/config is what new shells inherit. Switching in another file binds this widget to that file (--kubeconfig); new terminals still use the default.
  • Cluster — nodes ready, roles, pods running, namespaces, server and kubelet versions, and average CPU and memory when a metrics server answers. Click the namespace to pick another; that is kubectl config set-context --current --namespace=, same file as a context switch.

Why it stays out of the way

Reading a kubeconfig is a local file operation and costs nothing, so the bar label follows a context you changed in a terminal within seconds.

Talking to a cluster is the opposite. Clusters fail in more ways than they succeed — a credential plugin that errors, a private endpoint whose DNS does not resolve, an API server that simply never answers — and this widget lives inside the process that draws your desktop. So:

  • Nothing leaves the machine while the panel is closed.
  • Extra kubeconfigs are listed without kubectl. Only the bound context is probed (kubectl get --raw /version), and only while the panel is open.
  • Every call is bounded twice, by kubectl --request-timeout and by an outer timeout, so a dead cluster costs seconds rather than forever.
  • A cluster that does not answer is reported as unreachable, never as an empty cluster with zero nodes and zero pods.
  • A kind-* context whose node container is not running is reported as Kind cluster is not running, not as a generic API timeout. That check is local (docker inspect / kind get nodes) and only runs while the panel is open.

Requirements

kubectl on PATH and a readable kubeconfig. Nothing else. If kubectl is missing the panel says so instead of showing an empty list.

Install

omarchy plugin add https://github.com/Nepomuk-Software/KubeWidget.git --enable

Uninstall

omarchy plugin remove io.github.nepomuk-software.kubecontext

That takes the widget out of the bar and deletes the plugin directory. There is nothing else to undo: it installs no files outside that directory, no services and no privileged helper. Kind node containers it started or stopped stay in whatever state you left them. Kubeconfig writes (current-context and the current namespace) stay as you left them too.

What it writes

Three things, all on an explicit click, always against the file of the row:

  • kubectl --kubeconfig=<file> config use-context <name> — sets current-context in that file
  • kubectl --kubeconfig=<file> config set-context --current --namespace=<name> — sets the namespace of the current context in that file
  • docker start / docker stop of the Kind node containers labeled io.x-k8s.kind.cluster=<name> (and cloud-provider-kind-<name> if that sidecar exists). Kind has no start/stop CLI; this is the local equivalent. Only offered for kind-* contexts whose containers were actually found.

Writes against the default kubeconfig (~/.kube/config, or the first KUBECONFIG entry) are what new shells inherit. Writes against another file stay in that file; the widget keeps --kubeconfig pointed there until you pick a context in a different file. New terminals still use kubectl's default. The widget never copies clusters into ~/.kube/config, never exports KUBECONFIG, and never replaces ~/.kube/config with a symlink.

Docker start/stop never happens on its own. Everything else the widget does is read-only. The right-click picker only switches context, and never contacts a cluster or Docker.

Usage

Where Action
Bar, left open/close the panel
Bar, right pick a context (no network)
Bar, middle re-read the kubeconfig; full refresh if the panel is open
Panel, click a context switch to it
Panel, Start / Stop Kind cluster docker start / docker stop the local Kind nodes
Panel, click Namespace list namespaces of the current cluster, click to set
Panel, n open/close the namespace list
Panel, ↑ ↓ / Enter pick a context or namespace
Panel, r refresh
Panel, Esc close

Settings

omarchy bar set io.github.nepomuk-software.kubecontext <key> <value>

Key Default Effect
showContext true context name next to the icon; ignored on vertical bars
showNamespace false append /namespace to the bar label
maxLabel 18 longer names are elided in the bar
contextIntervalSec 5 how often the kubeconfig is re-read (local, no network)
probeIntervalSec 30 how often the bound cluster is contacted while the panel is open

IPC

omarchy-shell io.github.nepomuk-software.kubecontext <method> [context]
Method Does
open close toggle the popup
current the active context name
kubeconfig the kubeconfig file this widget is bound to
rows every row as name<TAB>file, * on the bound one
namespace the current context's namespace
use <context> switch to a context in the bound file, or the unique name; name@file when two files share a name
useIn <file> <context> same, with the file as its own argument
useNamespace <name> set the current context's namespace
kindStart kindStop start or stop the Kind node containers for the current kind-* context
refresh re-read kubeconfig; probe the bound context and overview only while the panel is open
status <context> reachable <version> nodes=r/t pods=r/t ns=n, or unreachable, unprobed, no kubectl

License

MIT — see LICENSE. Plugins run unsandboxed inside the Omarchy shell; read the code before you install it.