Kubernetes cost management
Every Kubernetes dollar, traced to an owner.
KubeOn splits each node's cost across the pods that ran on it, using your real cloud bill or your data center rates. Each team sees what it spends, and each saving arrives as a change you can review.
One Helm chart per cluster on EKS, AKS, GKE, OpenShift or bare metal. Read-only RBAC, no inbound port, no changes to your workloads.
- Agent access
- Read-only
- Billing source
- Your invoice
- First costs
- Within 1 h
September invoices
USD- AWSCUR 2.0, 12 accounts$412,318.40
- Microsoft AzureCost exports, 4 subscriptions$168,904.15
- Google CloudBigQuery export, 3 projects$97,440.80
- dc1 data centerRate card, 2 clusters$61,256.65
Runs wherever your clusters do
The problem
Your cloud bill stops at the node.
Kubernetes packs many teams onto shared machines. Without allocation, the cost of a cluster belongs to everyone, so nobody acts on it.
One invoice line, forty teams
The bill lists EC2 instances, AKS node pools and GKE nodes. It does not say which namespaces ran on them.
Requests set once, never revisited
CPU and memory requests are copied from the last service and left alone. The difference is paid for every hour.
Savings with no owner
A dashboard says a node group is oversized. Nobody knows who should change it, or whether the change is safe.
Data centers have no bill at all
On-prem clusters run on hardware bought years ago, so their cost never reaches the teams that use them.
Product tour
From allocation to an approved change
Six screens from the product, shown with sample data.
Each node's cost split across the pods that ran on it, grouped by cluster, namespace, team or any label. Idle and shared cost keep their own columns.
Explore cost allocationCost allocation screen with sample data
How it works
Installed in an afternoon.
- 01
Install the agent
One Helm release per cluster. An hourly CronJob with read-only RBAC writes a snapshot of nodes, pods and volumes.
- 02
Connect billing
Point KubeOn at your CUR 2.0 export, Azure cost export, BigQuery billing export, a FOCUS file or a data center rate card.
- 03
Assign and act
Owners come from your labels. Budgets, alerts and change proposals go to the team that owns the spend.
helm repo add kubeon https://charts.kubeon.iohelm repo updatehelm upgrade --install kubeon-agent kubeon/kubeon-agent \ --namespace kubeon --create-namespace \ -f kubeon-agent.yamlReconciliation
Starts from the invoice, not a price list
KubeOn reads the billed, net amortized cost of every node, so Savings Plans, reservations, credits and negotiated discounts are already in the numbers. Each cluster reconciles to its bill, and what cannot be attributed is listed with resource IDs.
- CUR 2.0, Azure cost exports, BigQuery billing export or FOCUS
- Direct, shared and idle cost in separate columns
- A reconciliation report for every cluster, every day
Change proposals
KubeOn proposes. You approve.
Each saving worth $25 a month or more becomes a proposal with the current and proposed state, the evidence behind it, a risk level and a patch. Approve it, merge it through your repo, and mark it applied.
- YAML requests, Karpenter NodePool snippets and snapshot-then-delete scripts
- Approve, reject or reopen, with every decision in the audit log
- Nothing is applied by KubeOn, ever
KubeOn AI
The same ledger for every model call
KubeOn AI measures what each model call costs across Azure OpenAI, Amazon Bedrock, Google Vertex AI, OpenAI and Anthropic, and runs a managed LLM gateway that routes every request, keeps each team within budget and uses your reserved capacity first.
- Effective cost per 1M tokens, including PTU and reservations
- One OpenAI-compatible endpoint with fallback and team keys
- Provisioned throughput sized from per-minute use
Deployment
Run the hub in our cloud or yours.
The agent is the same everywhere. Choose where the hub runs and where your data is stored.
KubeOn Cloud
We run the hub. You install the agent.
- Agents send snapshots outbound over HTTPS
- Billing read through a read-only role
- Upgrades and backups handled by us
- Regional hosting in the US or EU
Self-hosted in your cloud
The hub runs in your account, next to your billing data.
- Terraform module for AWS: ECS on Fargate, RDS, ElastiCache, KMS
- Helm chart in hub mode for AKS, GKE or any Kubernetes
- Snapshots in a bucket you own
- Your keys, your network, your audit trail
On-premises and air-gapped
For data centers and regulated networks.
- Helm chart in hub mode on OpenShift, Rancher or kubeadm
- Images from your private registry
- Rate cards or amortized hardware for pricing
- No internet egress required
By design
The numbers behind the product
3 verbs
get, list, watch: all the agent can do
Hourly
cluster snapshots, ingested at :20
180 days
of billing history on first connect
10
health checks on every cluster
Security
Built to pass your security review.
We publish the agent's ClusterRole and every IAM policy, so your team can check each permission before install.
Trust centerRead-only agent
get, list and watch only. It never reads Secrets or ConfigMaps.
Outbound only
No inbound port, no Service, no Ingress. Snapshots leave over HTTPS.
Your keys
Self-hosted hubs keep data in your account, encrypted with your KMS key.
SSO and team scope
SAML or OIDC sign-in. Team leads see their own teams.
FAQ
Questions platform and finance teams ask first
The agent's ClusterRole grants get, list and watch on nodes, pods, namespaces, workloads, volumes, services, quotas and storage classes, plus read access to metrics.k8s.io. It never reads Secrets or ConfigMaps and has no write verbs. It runs as an hourly CronJob with no Service, no Ingress and no inbound port.
See your own clusters in KubeOn.
A 30-minute walkthrough on your billing data, with an engineer who has run Kubernetes cost programs.