kubefwd
Infrastructure · tested 2026-08-15 · re-test due 2026-11-15 · by the Hlido desk, not the vendor
In short: A mature CNCF bulk Kubernetes port-forwarder that now speaks MCP — the AI angle is a thin but well-executed graft onto a tool that already earned its trust.
7 PASS · 0 FAIL of 7 public-surface claims
Quick answer
kubefwd scores 80/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-15). STEADY (80) for a mature, honestly-marketed CNCF project (Landscape since 2018, Apache 2.0) with a clean public surface, multiple documented interfaces (TUI, 40+ endpoint REST API, drop-in MCP server), and clear multi-pl Pricing: Open source (free entry point documented).
kubefwd has been on the CNCF Landscape since 2018 and does one unglamorous thing extremely well: it bulk-forwards Kubernetes services to local loopback addresses, giving each service its own 127.x.x.x IP and writing the cluster hostname into /etc/hosts, so in-cluster connection strings (http://api:8080, redis-cli -h cache, mysql -h db) resolve locally without modification. Many databases on port 3306, many gateways on 443, no remapping, no environment-specific config. It watches Kubernetes events and reconnects on pod churn with exponential backoff. Apache 2.0, installable via brew, winget, apt or a release binary. The surface is clean and honest — nothing here overshoots. For the agentic-tooling question Hlido cares about, the relevant hook is the drop-in MCP server: Claude, Cursor and any MCP-capable assistant can connect, browse cluster services and forward what a task needs in plain language ('connect me to staging redis'), alongside a 40+ endpoint REST API and an interactive Bubble Tea TUI with live traffic sparklines and pod-log streaming. Crucially, the MCP server is presented as one interface among several rather than a bolted-on gimmick, and it sits on top of a tool whose core value is deterministic devops plumbing that predates the AI framing by years. The honest limits: it requires sudo (it writes /etc/hosts and binds low ports), so it runs with real local privilege; the AI-assistant surface is a small slice of what is fundamentally a platform-engineering utility; and Hlido assessed the marketing site only, not the running binary. Nothing on the captured surface makes a claim it cannot obviously back.
Why STEADY
STEADY (80) for a mature, honestly-marketed CNCF project (Landscape since 2018, Apache 2.0) with a clean public surface, multiple documented interfaces (TUI, 40+ endpoint REST API, drop-in MCP server), and clear multi-platform install paths, marked as low-medium confidence because the review is surface-only (the marketing site, not the running binary), the AI/MCP surface is a thin slice of a core devops utility, and the tool requires sudo to operate. Not VITAL because the agent-facing surface is one feature among many and nothing was hands-on tested.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — 'kubefwd port-forwards Kubernetes services in bulk ... each service gets its own 127.x.x.x loopback address'
- PASS Cta present (required) — 'brew install kubefwd' plus install/run and user-guide links
- PASS Docs present (required) — Getting-started, user guide, configuration, advanced usage, troubleshooting, REST API and MCP integration all linked without login
- PASS Integrations documented (required) — TUI, 40+ endpoint REST API and MCP server (Claude/Cursor) each documented as a distinct interface
- PASS Pricing or access — Open source under Apache 2.0; no pricing surface (N/A)
- PASS Auth data handling — Runs locally with sudo; writes /etc/hosts (backup kept at ~/hosts.original); binds low ports — stated plainly on the surface
What we saw
1 screenshot captured by the Hlido engine during the reviewed run (run-3fa184f616ea72b2-kubefwd-com). Our own captures — not vendor marketing material.
What it does well
- Mature, trusted project — on the CNCF Landscape since 2018, Apache 2.0, sponsored and maintained
- Solves a real, specific problem: bulk local access to cluster services with per-service loopback IPs and /etc/hosts integration, so in-cluster connection strings work unchanged
- Three documented interfaces — interactive TUI, a 40+ endpoint REST API, and a drop-in MCP server for AI assistants
- Auto-reconnect with exponential backoff on pod churn; handles headless services, port mapping, label selectors, multi-namespace and multi-cluster
- Clean, honest marketing surface with clear multi-platform install paths (brew, winget, apt, binaries)
What it fails at
- Requires sudo to run — it writes /etc/hosts and binds low ports, so it operates with real local privilege
- The MCP/AI-assistant surface is a thin slice of what is fundamentally a platform-engineering utility
- Surface-only review — Hlido assessed the marketing site, not the running binary; no hands-on verification of the forwarding, TUI or MCP behaviour
- No hosted or managed option and no enterprise/support story on the captured surface — it is a self-run CLI
Best for
- Platform and devops engineers who need many cluster services accessible locally exactly as they resolve in-cluster
- Developers who want an MCP-drivable path for an AI assistant to reach staging/dev cluster services
- Teams already in the Kubernetes/CNCF ecosystem wanting a well-established, Apache-2.0 local tool
Not recommended for
- Non-technical users — this is a sudo-level command-line utility
- Environments where root-level local tooling that edits /etc/hosts is disallowed by policy
- Anyone wanting a managed or hosted service rather than a self-run binary
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
- Pricing findable on the public surfacePASS Open source under Apache 2.0; no pricing surface (N/A) (tested 2026-08-15)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-15.
Related agents
Agent relevance
API CLI MCP Behavioral-testable
Agentic-Commerce Readiness 79/100 · COMMERCE-READY
Independent readiness for agent delegation & transaction. How it’s scored · check live
A drop-in MCP server (`kubefwd mcp`, added via `claude mcp add kubefwd`) lets Claude, Cursor and any MCP-capable assistant browse cluster services and establish forwards in natural language. A 40+ endpoint REST API also drives forwards programmatically from CI or editor tooling. The tool itself is a Go CLI run with sudo.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Bulk-forwards Kubernetes services, one 127.x.x.x loopback IP per service, with cluster hostnames written to /etc/hosts — source (2026-08-15) verified
- Three interfaces documented — interactive TUI, 40+ endpoint REST API, and an MCP server for AI assistants — source (2026-08-15) verified
- Apache 2.0, on the CNCF Landscape since 2018; install via brew, winget, apt or release binary — source (2026-08-15) verified
- Auto-reconnect with exponential backoff on pod churn; requires sudo to write /etc/hosts and bind low ports — source (2026-08-15) verified
- Hands-on behaviour of forwarding, TUI and MCP server (verified by running the tool) — source (2026-08-15)
