KUBERNETES TROUBLESHOOTING · RUNS LOCALLY

Kubernetes workload failing?
Investigate it in one place.

When pods restart or readiness drops, Fortem shows the affected namespace and workload. Open pod status, events, logs, resource limits and routing from a local UI connected to your kubeconfig.

or install yourself

Local install · read-only first · no Helm chart

Want to look first? Open the interactive demo
Actual Fortem UI · synthetic Kubernetes dataOpen interactive demo

Pod restarted? Readiness dropped? Start with the affected workload.

pod status events & logs resources & routing next read-only check

FROM ALERT TO WORKLOAD

See what happened around the failing pod.

Start from a namespace overview, then open the affected workload. Check restarts and termination reasons beside events, logs, requests, limits and recent changes. Fortem labels possible explanations separately from observed facts and suggests a read-only next check.

Active incidentstaging / payments-api
Synthetic data · updated 14s ago
01 · Symptom2/3 ready

Requests are reaching the service, but server errors increased after a rollout.

5xx
3.6%
p95
940 ms
02 · Observed evidence
OOMKilledpod/payments-api-7bc4 · 7 restartspod status
1.0 GiB memory limitcurrent usage 918 MiBmetrics
Rollout 12 minutes agoimage changed to payments:v2.8.1workload
Database pool exhausted ×18reduced pattern · raw logs stay locallogs
03 · Bounded hypothesisMemory exhaustion

The termination reason and memory boundary support this explanation.

Strong signal. It explains termination, not why memory use increased.
04 · Next useful checkRead-onlyInspect the OOM pod and memory boundaryOpen workload evidence
Deterministic analysis runs locallyJev is not required
fortem doctorexample preflight
Selected context
platform-productionread-only
EKS · Kubernetes 1.31 · us-east-1
$ fortem --doctor --context platform-production

Cluster access

API server
connected 84 ms
Exec authentication
aws external
Required reads
10/10 allowed
Namespace scope
12 visible

Optional sources

metrics-server
available 28s fresh
Prometheus
not configured
Karpenter
3 NodePools
✓

Ready to open a read-only workspaceCredentials remain in the local Go process.

fortem --context platform-production

YOUR MACHINE · YOUR ACCESS

Point it at the kubeconfig you already use.

One Go binary, one local interface, and the Kubernetes access already on your machine. The same workflow supports EKS, GKE, AKS, kind and k3s.

Environment scanNamespace health, workloads, pods and readiness.
Workload evidenceReasons, events, images, rollouts and live logs.
Resource fitRequests, limits, usage, GPU allocation, nodes and NodePools.
Traffic pathIngress, Services, backends and optional request metrics.
Read-only first Credentials stay in the local Go process
Read the security model

WHAT FORTEM CAN READ

Start with Kubernetes data. Add metrics if you already have them.

built in

Local decision engine

Deterministic incident rules run on your machine and show their evidence, caveats and provenance.

BYOK preview · optional

Jev decision layer

An experimental typed ranking layer over Fortem's redacted evidence. It never replaces the local facts or authorizes a mutation.

built in

Kubernetes API

Namespaces, workloads, pods, images, events, Services, Ingress and EndpointSlices.

optional

metrics-server

Current CPU and memory usage. Core investigation remains available without it.

optional

Prometheus

Compatible ingress-nginx, Traefik or Istio request and error signals, with source and time window shown.

FORTEM FOR TEAMS

When individual cluster work becomes team work.

Free handles one selected cluster; Pro gives one engineer a local fleet view across up to 10 contexts. Fortem Teams is the paid path for shared access, larger fleets, integration work and support.

Book a Kubernetes engineer
01
Multi-cluster environment viewMove across contexts and clusters without flattening their identity or freshness.
02
Shared operational workspaceGive responders the same workload, event, log and routing context.
03
Team access and supportDiscuss deployment boundaries, access control and an update path with an engineer.

PRACTICAL QUESTIONS

Before you point it at a cluster.

Does Fortem install anything in my cluster?+

No. The local binary reads the Kubernetes API through the context you select from your existing kubeconfig.

Which Kubernetes distributions work?+

Fortem uses standard Kubernetes APIs and supports EKS, GKE, AKS, kind and k3s through an existing kubeconfig. Your cloud auth helper, VPN or private endpoint access, and Kubernetes RBAC still apply.

Does it show multiple clusters at once?+

Free investigates one selected kubeconfig context. A Pro license adds a read-only fleet summary for up to 10 contexts, with each cluster read independently; detailed investigation opens in one selected context at a time.

Do credentials reach the browser?+

No. kubeconfig and exec credentials stay in the local Go process. The browser talks only to Fortem on loopback by default.

Does it work without metrics-server?+

Yes. Workloads, readiness, pod states, images, events, routes and logs still work. Actual CPU and memory usage is marked unavailable instead of shown as zero.

Where do HTTP request and error metrics come from?+

From an optional Prometheus source with a compatible ingress-nginx, Traefik or Istio profile. Fortem labels the measurement window and source.

Can Fortem change workloads?+

The default is read-only. Supported mutations require an explicit --manage flag, exact-target confirmation and a Kubernetes RBAC check.

Does incident analysis send cluster data anywhere?+

No in the default local mode. Fortem's built-in deterministic engine runs on your machine. The current BYOK preview lets a user explicitly enable the experimental Jev decision layer; it receives only normalized facts and reduced log-pattern labels, never kubeconfig credentials, raw logs or local object names. Jev ranks bounded hypotheses while Fortem keeps the evidence, caveats, next check and local fallback. A future Pro/Teams gate depends on evaluation.

Install locally. Start in demo mode or use a context you control.

No account, Helm chart or in-cluster Fortem component. The default stays read-only.

or install yourself

Local install · read-only first · no Helm chart