Skip to content
NewKubeOn AI: a managed LLM gateway with cost per 1M tokens for every model

Kubernetes cost management

Every Kubernetes dollar, traced to an owner.

KubeOn splits each node's cost across the pods that ran on it, using your real cloud bill or your data center rates. Each team sees what it spends, and each saving arrives as a change you can review.

One Helm chart per cluster on EKS, AKS, GKE, OpenShift or bare metal. Read-only RBAC, no inbound port, no changes to your workloads.

Agent access
Read-only
Billing source
Your invoice
First costs
Within 1 h

September invoices

USD
  • AWSCUR 2.0, 12 accounts$412,318.40
  • Microsoft AzureCost exports, 4 subscriptions$168,904.15
  • Google CloudBigQuery export, 3 projects$97,440.80
  • dc1 data centerRate card, 2 clusters$61,256.65
Total$739,920.00
PaymentsCC-1042$028.2%
MLCC-3301$021.8%
SearchCC-2245$020.7%
DataCC-2210$017.1%
Platform, shared and idlepolicy: proportional$011.1%
Unallocated3 namespaces unlabeled$01.2%
Reconciled to invoice: 100.00%max(request, usage) · net amortized · 4 sources

Runs wherever your clusters do

Amazon EKSAzure Kubernetes ServiceGoogle Kubernetes EngineRed Hat OpenShiftRancherVMware TanzuOracle OKEk3skubeadm on bare metalKarpenterPrometheusFluxArgo CDTerraform

The problem

Your cloud bill stops at the node.

Kubernetes packs many teams onto shared machines. Without allocation, the cost of a cluster belongs to everyone, so nobody acts on it.

One invoice line, forty teams

The bill lists EC2 instances, AKS node pools and GKE nodes. It does not say which namespaces ran on them.

Requests set once, never revisited

CPU and memory requests are copied from the last service and left alone. The difference is paid for every hour.

Savings with no owner

A dashboard says a node group is oversized. Nobody knows who should change it, or whether the change is safe.

Data centers have no bill at all

On-prem clusters run on hardware bought years ago, so their cost never reaches the teams that use them.

Product tour

From allocation to an approved change

Six screens from the product, shown with sample data.

Each node's cost split across the pods that ran on it, grouped by cluster, namespace, team or any label. Idle and shared cost keep their own columns.

Explore cost allocation

Cost allocation screen with sample data

How it works

Installed in an afternoon.

  1. 01

    Install the agent

    One Helm release per cluster. An hourly CronJob with read-only RBAC writes a snapshot of nodes, pods and volumes.

  2. 02

    Connect billing

    Point KubeOn at your CUR 2.0 export, Azure cost export, BigQuery billing export, a FOCUS file or a data center rate card.

  3. 03

    Assign and act

    Owners come from your labels. Budgets, alerts and change proposals go to the team that owns the spend.

Install the agent
helm repo add kubeon https://charts.kubeon.iohelm repo updatehelm upgrade --install kubeon-agent kubeon/kubeon-agent \  --namespace kubeon --create-namespace \  -f kubeon-agent.yaml

Reconciliation

Starts from the invoice, not a price list

KubeOn reads the billed, net amortized cost of every node, so Savings Plans, reservations, credits and negotiated discounts are already in the numbers. Each cluster reconciles to its bill, and what cannot be attributed is listed with resource IDs.

  • CUR 2.0, Azure cost exports, BigQuery billing export or FOCUS
  • Direct, shared and idle cost in separate columns
  • A reconciliation report for every cluster, every day
How allocation works

Change proposals

KubeOn proposes. You approve.

Each saving worth $25 a month or more becomes a proposal with the current and proposed state, the evidence behind it, a risk level and a patch. Approve it, merge it through your repo, and mark it applied.

  • YAML requests, Karpenter NodePool snippets and snapshot-then-delete scripts
  • Approve, reject or reopen, with every decision in the audit log
  • Nothing is applied by KubeOn, ever
See the review workflow

KubeOn AI

The same ledger for every model call

KubeOn AI measures what each model call costs across Azure OpenAI, Amazon Bedrock, Google Vertex AI, OpenAI and Anthropic, and runs a managed LLM gateway that routes every request, keeps each team within budget and uses your reserved capacity first.

  • Effective cost per 1M tokens, including PTU and reservations
  • One OpenAI-compatible endpoint with fallback and team keys
  • Provisioned throughput sized from per-minute use
Explore KubeOn AI

Deployment

Run the hub in our cloud or yours.

The agent is the same everywhere. Choose where the hub runs and where your data is stored.

KubeOn Cloud

We run the hub. You install the agent.

  • Agents send snapshots outbound over HTTPS
  • Billing read through a read-only role
  • Upgrades and backups handled by us
  • Regional hosting in the US or EU
How it deploys

Self-hosted in your cloud

The hub runs in your account, next to your billing data.

  • Terraform module for AWS: ECS on Fargate, RDS, ElastiCache, KMS
  • Helm chart in hub mode for AKS, GKE or any Kubernetes
  • Snapshots in a bucket you own
  • Your keys, your network, your audit trail
How it deploys

On-premises and air-gapped

For data centers and regulated networks.

  • Helm chart in hub mode on OpenShift, Rancher or kubeadm
  • Images from your private registry
  • Rate cards or amortized hardware for pricing
  • No internet egress required
How it deploys

By design

The numbers behind the product

3 verbs

get, list, watch: all the agent can do

Hourly

cluster snapshots, ingested at :20

180 days

of billing history on first connect

10

health checks on every cluster

Security

Built to pass your security review.

We publish the agent's ClusterRole and every IAM policy, so your team can check each permission before install.

Trust center

Read-only agent

get, list and watch only. It never reads Secrets or ConfigMaps.

Outbound only

No inbound port, no Service, no Ingress. Snapshots leave over HTTPS.

Your keys

Self-hosted hubs keep data in your account, encrypted with your KMS key.

SSO and team scope

SAML or OIDC sign-in. Team leads see their own teams.

FAQ

Questions platform and finance teams ask first

The agent's ClusterRole grants get, list and watch on nodes, pods, namespaces, workloads, volumes, services, quotas and storage classes, plus read access to metrics.k8s.io. It never reads Secrets or ConfigMaps and has no write verbs. It runs as an hourly CronJob with no Service, no Ingress and no inbound port.

See your own clusters in KubeOn.

A 30-minute walkthrough on your billing data, with an engineer who has run Kubernetes cost programs.