Sazabi
Sandbox CLIs

Kubernetes

Give the Sazabi agent the Kubernetes CLI (kubectl) in its sandbox to inspect and manage your cluster.

About

This CLI connection makes the Kubernetes CLI (kubectl) available in the Sazabi agent's sandbox. The agent can use it to inspect and manage resources in your cluster. The tool is baked into the sandbox image; connecting it configures the connection for the already-installed CLI.

Prerequisites

  • A Sazabi project.
  • The contents of a kubeconfig file (KUBECONFIG_CONTENTS) granting access to your cluster. This is the raw YAML content of a kubeconfig, typically found at ~/.kube/config or generated by your cloud provider's CLI (e.g., aws eks update-kubeconfig, gcloud container clusters get-credentials).

Set up in the dashboard

Configure the sandbox in the dashboard under Settings > Sandbox CLIs.

Find Kubernetes in the catalog

In Settings > Sandbox CLIs, find Kubernetes under Browse sandbox CLIs and choose to connect it.

Provide credentials

Enter the required value: KUBECONFIG_CONTENTS — the full YAML contents of your kubeconfig file. Save to store it securely; Sazabi injects it into the sandbox when the agent runs.

Set up with the CLI

You can also configure the Kubernetes CLI connection with the Sazabi CLI (installed and authenticated — see CLI reference).

sazabi sandbox-clis set --type kubectl --env KUBECONFIG_CONTENTS="$(cat ~/.kube/config)"

To validate the credentials without saving, run the same command with test in place of set (the test command also requires the --env flags).

Verify

Ask the agent, in a thread, to run the kubectl CLI (a read-only or status command) and confirm it returns real output. If the command is not found, the CLI connection may not be enabled; if it runs unauthenticated or cannot connect, recheck the credentials.

Troubleshooting

Command not found — Confirm the Kubernetes CLI connection is enabled for the project under Settings > Sandbox CLIs.

Authentication or connection fails — Recheck the credential/connection values under Settings > Sandbox CLIs.

Further reading