Everything Roam does
Roam is a Kubernetes client for your phone and your desktop. It talks straight to your clusters' API servers — there is no Roam server — so you can see what's wrong and fix it from wherever you are.
Connect any cluster
- Sign in to a managed cluster: Amazon EKS (IAM keys, MFA, assumed roles or IAM Identity Center), Google GKE and Azure AKS. Roam looks up the endpoint and certificate for you.
- Kubeconfig or token for everything else: k3s, kind, minikube, self-managed and on-premises clusters. Pick a context from a kubeconfig with several.
- SSH bastion: reach a cluster whose API server isn't public by routing through an SSH host, with password or key and host-key pinning.
- Your CA, or none: give the cluster's CA certificate, or skip verification for a self-signed lab cluster.
On your phone — iOS and Android
See what needs you
- An overview with CPU, memory and disk use, node health, workload counts and the issues to look at first.
- Cluster events sorted into Critical, Warning and Info — OOMKilled, CrashLoopBackOff, failed scheduling — each one a tap away from the Pod or node it's about.
- Optional AI incident analysis that explains a failure and suggests fix commands. It runs on the device or on an AI engine you host, redacts secrets from logs, and flags destructive commands.
Act on it
- Scale and restart Deployments, StatefulSets and DaemonSets; view and edit any resource's YAML.
- Cordon, uncordon and drain nodes (drain respects PodDisruptionBudgets).
- Live logs with search, regex filtering and severity highlighting.
- Shells into Pods and nodes with command suggestions and an extra key row; node shells come with crictl, ctr, journalctl, systemctl, tcpdump and more.
- Swipe to restart or delete, pull to refresh, long-press for a quick-jump menu.
Every resource
More than 36 resource types: Pods, Deployments, StatefulSets, DaemonSets, Jobs and CronJobs, Services, Ingresses, Endpoints, ConfigMaps, Secrets, PersistentVolumes and claims, HPAs, NetworkPolicies, RBAC roles and bindings, namespaces and nodes — plus cert-manager (Certificates, Issuers, Orders, Challenges) and the Prometheus Operator.
On your desktop — macOS, Windows and Linux
The same client, rebuilt for a big screen and a keyboard: apps instead of resource lists, answers instead of dashboards.
- Home starts with what needs you: crash loops, unschedulable Pods, nodes under pressure, failing jobs and expiring certificates, each with a next step.
- Diagnosis in plain words: why a workload is failing — from its events, container state and last log lines — and what to check next.
- Changes: every change to the cluster while Roam runs, who made it (kubectl, Helm, Argo CD), the exact diff, and one-click revert.
- Health checks: reliability, security and efficiency scores, and what blocks your next Kubernetes upgrade.
- Apps and an app map: Deployments, StatefulSets, Services and Ingresses grouped into apps, with how traffic flows between them.
- Logs, shells and files: live logs, container and node shells, Pod files, port forwards, and a kubectl/helm terminal — kubectl and helm are built into Roam.
- Helm and metrics: release history, values diff, upgrade and rollback; metrics with rollouts drawn on the charts.
- TLS certificates: Secrets holding certificates show expiry, whether the private key matches and whether the chain verifies.
- Team access with Roam Gate: let your team sign in with GitHub, GitLab, Google, OIDC or LDAP and get only the access you grant, with an audit log.
- Bring your own AI, if you want it: explain an incident with an OpenAI-compatible API or a local Ollama model. Off until you set it up.
Private by design
- No Roam server and no proxy: the app connects directly to your API servers.
- Credentials are encrypted with the platform's secure storage — Keychain on iOS and macOS, Keystore on Android, Credential Manager on Windows, Secret Service on Linux.
- No analytics and no telemetry.
Get Roam
Free on every platform. Your clusters and credentials stay on your device.
Connection guides
- Amazon EKS — Sign in with IAM access keys, MFA, an assumed role or AWS IAM Identity Center, then pick a cluster.
- Google GKE — Connect with a service account key: the IAM roles it needs, how to create the key, and what to enter.
- Azure AKS — Sign in with device login or a service principal; what the cluster needs and which roles to grant.
- Kubeconfig or token — k3s, kind, minikube, on-premises and any other cluster: import a kubeconfig or use a bearer token, with SSH bastion and CA options.