Now in public preview — free

Your infrastructure,
under your control.

One native macOS workspace for Runbooks, SSH, RDP, and Kubernetes — with Vault-backed secrets and a Change Review gate before anything runs. Local-first, enterprise-ready, engineered for the way real teams operate.

macOS 13.0+ · Apple Silicon & Intel · Signed & notarized

The workspace

An IDE for the things you SSH into.

Pooled editor tabs, split-view terminals across every host you selected, Vault-backed secrets that resolve at connect time, and a Change Review gate that shows the blast radius before anything runs.

Capabilities

Every surface an on-call touches, in one workspace.

Runbooks, SSH, RDP, Kubernetes, tunnels, and Vault — with a coherent inventory and execution model, not six separate applications glued together.

Runbooks

A VS Code–shaped IDE for operational scripts. Pooled editor tabs, split-view terminals across every selected host, and a Change Review gate that shows the blast radius before anything runs.

SSH sessions

First-class SSH inventory with per-environment grouping. Runbook steps execute through the same visible PTY you are typing into — sudo prompts stay in one terminal.

Windows RDP

First-class RDP targets alongside SSH and Kubernetes. Same inventory, same sharing, same audit — driven by FreeRDP, rendered natively.

Kubernetes

kubectl-parity inspector for clusters, workloads, and events. Reads your existing kubeconfig — no cloud credentials leave the device.

Tunnels

Unified SSH port-forward and Kubernetes port-forward lifecycle. See what's running, why, and to which target — in one place.

Vault secrets

HashiCorp Vault (KV v2) resolves credentials at connect time for SSH, RDP, Kubernetes, and Runbook steps. Nothing sensitive on disk. Every fetch audited.

Local-first

Your credentials never leave your machine.

Ark8 is a native macOS application first. SSH keys stay in ~/.ssh, kubeconfigs stay in ~/.kube, sudo passwords stay in the macOS Keychain. Nothing sensitive is ever uploaded — not to Ark8, not to anywhere.

  • SSH passwords are never persisted anywhere.
  • Private keys and kubeconfigs stay on the device.
  • Sharing across a team publishes descriptors only — never secrets.
your Mac
~/.ssh/id_ed25519~/.kube/configKeychainssh-agent
descriptors only
your organization
prod-01 · staging-arista · dev-cluster

Team sharing

Publish infrastructure descriptors to your organization — explicitly.

Right-click a host, click Share with Organization, and teammates see the descriptor. They connect using their own local credentials. Sharing is per-item, reversible, and enforced by Postgres RLS — not client filtering.

What gets shared
  • Name, hostname, port, username
  • Tags and free-form notes
  • Kubernetes context name and cluster URL
  • Tunnel labels and port bindings
What never gets shared
  • Passwords
  • SSH private keys and passphrases
  • kubeconfig contents and client certificates
  • Tokens, Keychain items, or credentials of any kind

Enterprise identity

SSO, RBAC, and audit — designed in from day one.

Ark8's enterprise layer is built on Supabase Auth, PostgreSQL Row-Level Security, and a scoped RBAC model. No parallel auth system, no bolt-on permissions, no security theater.

Google Workspace

Sign in with Google — corporate or personal accounts.

Microsoft Entra ID

Azure AD SSO with PKCE, no client secrets in the app.

Owner / Admin / Member / Viewer

A scoped RBAC hierarchy enforced by Postgres RLS.

Append-only audit

Auth events, membership changes, and shares — with secret redaction.

Positioning

Ark8 is a workspace, not a hosted infrastructure service.

We don't run your clusters or store your keys. Ark8 sits between you and the infrastructure you already own — organized, auditable, and shareable with your team. The macOS application performs the actual work; the web platform manages identity, organizations, and descriptors.

Get started

Download Ark8 for macOS.

Free during public preview. No account required to try — sign in only when you're ready to share with your team.