AI-powered Kubernetes cluster management for platform engineers. Ask questions about your EKS clusters in natural language — get health checks, troubleshooting, cost analysis, upgrade planning, and operational commands.
Built on Amazon Bedrock AgentCore with Strands Agents.
| Capability | Examples |
|---|---|
| Cluster Health | "Is my prod cluster healthy?" |
| Pod Troubleshooting | "Why is payment-processor crashing?" |
| Cost Analysis | "Where am I wasting money?" |
| Network Debugging | "Debug networking in prod-us-west-2" |
| Upgrade Planning | "Is prod-eu-west-1 ready for an upgrade?" |
| Workload Management | "Scale api-gateway to 5 replicas" |
| Cluster Comparison | "Compare my two production clusters" |
| Node Operations | "Is it safe to drain this node?" |
| PDB Checks | "Will any PDBs block my maintenance?" |
| CronJob Monitoring | "Are any cronjobs failing?" |
27 tools across 4 categories: Observe, Diagnose, Act, Plan.
- AWS CLI configured with credentials
- AgentCore CLI (
npm install -g @aws/agentcore) - Python 3.10+ and uv
cd EksPilot
agentcore devMock mode is on by default — 3 simulated clusters with realistic issues (CrashLoopBackOff, OOMKilled, NotReady nodes, expiring TLS certs, PDB blockers, failing cronjobs).
EKS_PILOT_MOCK=false agentcore devRequires IAM permissions (see IAM Permissions below). Auto-discovers all EKS clusters in your account/region. No kubeconfig, kubectl, or aws-iam-authenticator needed.
agentcore deploy -yFirst deploy takes 5-8 minutes (includes memory provisioning). After deploy:
agentcore invoke --stream "What's wrong with my clusters?"cd chat-ui
pip install streamlit requests
python -m streamlit run app.py --server.port 8502 --server.address 0.0.0.0 --server.headless trueEksPilot/
├── app/EksPilot/
│ ├── main.py # Agent entrypoint — system prompt, memory, tool wiring
│ ├── eks_tools.py # 17 core tools (health, pods, nodes, deployments, services, costs, upgrades)
│ ├── eks_tools_advanced.py # 10 advanced tools (PDBs, rollback, drain, quotas, ingress, cronjobs)
│ ├── k8s_client.py # EKS auth via STS presigned tokens, dynamic kubeconfig
│ ├── mock_data.py # Realistic simulated cluster data for demos
│ ├── model/ # Bedrock model configuration
│ └── pyproject.toml # Python dependencies
├── chat-ui/
│ ├── app.py # Streamlit chat interface
│ └── .streamlit/config.toml # K8s blue/white theme
└── agentcore/
├── agentcore.json # Project config (runtime + memory)
├── aws-targets.json # Deployment target
└── cdk/ # CDK infrastructure (auto-managed)
| Tool | Description |
|---|---|
list_clusters |
List all EKS clusters with version, status, region |
describe_cluster |
Detailed cluster info (networking, endpoint, tags) |
cluster_health |
Comprehensive health check — nodes, pods, deployments, resource usage, warnings |
list_nodes |
Node status, instance types, CPU/memory utilization |
list_pods |
Pods with status, restarts, readiness, node placement |
list_deployments |
Deployments with replica counts and images |
list_services |
Services with type, IPs, ports, selectors |
list_namespaces |
Namespaces with pod counts |
list_ingresses |
Ingress rules, TLS status, expiring certificates |
list_cronjobs |
CronJobs with schedule, status, failure reasons |
list_addons |
EKS managed addons (vpc-cni, coredns, kube-proxy) |
get_cluster_events |
Recent cluster events, filterable by type |
get_logs |
Pod logs for debugging application errors |
compare_clusters |
Side-by-side cluster comparison |
| Tool | Description |
|---|---|
troubleshoot_pod |
Deep pod diagnosis — status, events, logs, root cause, fix |
debug_networking |
DNS, service endpoints, VPC CNI, load balancer health |
check_pdbs |
PodDisruptionBudgets — find blockers before draining |
check_resource_quotas |
Namespace quota usage and exhaustion alerts |
top_pods |
Top pods by CPU or memory — find resource hogs |
| Tool | Description |
|---|---|
scale_deployment |
Scale deployment replicas |
restart_deployment |
Rolling restart (respects PDBs) |
rollback_deployment |
View revision history and rollback |
cordon_node |
Mark node unschedulable |
drain_node |
Evict pods with PDB safety checks |
| Tool | Description |
|---|---|
check_upgrade_readiness |
Version currency, deprecated APIs, addon compatibility |
get_autoscaler_status |
HPA metrics and nodegroup scaling headroom |
analyze_costs |
Compute costs by nodegroup, savings opportunities |
EKS Pilot uses AgentCore Memory (SEMANTIC + USER_PREFERENCE) to remember:
- Cluster facts and past incidents across sessions
- User preferences (response style, priority clusters, alert thresholds)
Memory is available after deploy. Not available during agentcore dev.
| Variable | Default | Description |
|---|---|---|
EKS_PILOT_MOCK |
true |
true for simulated data, false for real clusters |
AWS_REGION |
auto-detected | AWS region for EKS API and k8s auth |
MEMORY_EKSPILOTMEMORY_ID |
set by deploy | AgentCore Memory resource ID |
For live mode (EKS_PILOT_MOCK=false), the agent needs:
AWS IAM:
eks:ListClusterseks:DescribeClustereks:ListNodegroupseks:DescribeNodegroupeks:ListAddonseks:DescribeAddonsts:GetCallerIdentity
Kubernetes RBAC:
- Read access to pods, nodes, deployments, services, events, namespaces, ingresses, cronjobs, HPAs, PDBs, resource quotas
- Write access for scale, restart, rollback, cordon, drain operations (optional — read-only mode works without these)
# Install dependencies
cd app/EksPilot && uv venv && source .venv/bin/activate && uv pip install -r pyproject.toml
# Run locally
agentcore dev
# Run tests
EKS_PILOT_MOCK=true python -c "from eks_tools import ALL_TOOLS; from eks_tools_advanced import ADVANCED_TOOLS; print(f'{len(ALL_TOOLS) + len(ADVANCED_TOOLS)} tools loaded')"
# Deploy
agentcore deploy -y
# Check status
agentcore status
# Invoke deployed agent
agentcore invoke --stream "Your question here"
# View logs
agentcore logs --runtime EksPilot --since 1h
# View traces
agentcore traces --runtime EksPilot --since 1hUser → Chat UI (Streamlit) → Agent Server (Strands + Bedrock) → Tools
↓ ↓
AgentCore Memory boto3 / kubernetes
(SEMANTIC + USER_PREF) (EKS API + k8s API)
- Agent: Strands framework on Amazon Bedrock (Claude Sonnet)
- Auth: STS presigned tokens for EKS (no kubeconfig needed)
- Memory: AgentCore managed memory with semantic search
- Deploy: AgentCore Runtime (CodeZip) via CDK
- UI: Streamlit with Kubernetes-themed design