kubefwd
A CLI for bulk port forwarding of Kubernetes services to your local machine, with an MCP integration for AI assistants
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Requires elevated rights and edits the hosts file
- Opens network access to cluster services from the local machine
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/kubefwdDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
brew install kubefwdCommands for macOS and Linux, on Windows run them in Git Bash.
Install kubefwd (brew install kubefwd or run the txn2/kubefwd container), then run sudo kubefwd svc -n <namespace> with a working kubeconfig. To drive it from an assistant, set up MCP per the guide on kubefwd.com.
Other ways from the author
brew install kubefwdInstalls the binary on macOS and Linux via Homebrew. Run: sudo kubefwd svc -n <namespace>.
This is third-party code. Review the repository files before installing.
What it does
kubefwd forwards many services from selected cluster namespaces at once and makes them reachable locally under their in-cluster names. An app on your laptop connects to db:5432 or api-gateway:8080 with no environment-specific config. It offers an interactive TUI, a unique IP per service and automatic reconnection. A separate MCP integration lets an AI assistant drive the forwarding.
Who it is for. For developers and devops engineers who develop locally against services running in a Kubernetes cluster.
Good fit when
- You need local access to cluster services by their names without editing connection strings
- You need to forward a whole namespace at once rather than a single port
- You want an AI assistant to start and check forwarding through MCP
Not a fit when
- You have no cluster access or a valid kubeconfig
- A one-off kubectl port-forward for a single service is enough
Example request
Forward the services from the staging namespace and show me their local addressesLimitations
It needs a working kubeconfig and forwarding permissions. kubefwd edits the hosts file and brings up local addresses, so it requires elevated rights (sudo or a privileged container). MCP setup is described on the docs site rather than as a ready snippet in the README.
How to disable. Stop the kubefwd process, remove the binary (for example brew uninstall kubefwd) and delete the server from your MCP client config if you added it.
Security check
- Requires elevated rights and edits the hosts file
- Opens network access to cluster services from the local machine
README in short
The README presents kubefwd as a tool for local development against a cluster: services become reachable by their names with no environment config. It covers Homebrew install and Docker usage, permission requirements, the interactive TUI and automatic reconnection. Separate sections point to getting-started, reference and MCP-integration docs. The project is part of the CNCF Landscape, Apache-2.0 licensed.
FAQ
Why does it need sudo?
kubefwd edits the hosts file and assigns local IPs to services, which requires elevated rights. Running it in a privileged container is an alternative.
Can it forward several namespaces?
Yes, the namespace flag can be repeated and kubefwd brings up ports for all selected namespaces at once.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring