Open source
Kubernetes API for Laravel
composer require roundly-consulting/kubernetes-api-for-laravelOverview
A fluent, Eloquent-style client for the Kubernetes API in Laravel. Talk to one or many clusters through Laravel’s own HTTP client — list, create, patch, scale and restart workloads, stream pod logs, exec into containers and watch resources change — with 33 built-in resource types, the Traefik CRDs and your own custom resources. Everything starts at the Kubernetes facade — or an injected KubernetesManager — every request is paced per cluster, and Kubernetes::fake() swaps in an in-memory apiserver for tests. MIT-licensed and dependency-light: beyond Laravel it needs only symfony/yaml and three small Roundly packages.
What you get
Eloquent-style resources
Fluent get, find, create, update, updateOrCreate, patch and delete on 33 typed resources, with selectors and continue-token pagination.
One facade, many clusters
Kubernetes::cluster('production') or an injected KubernetesManager. Clusters come from config, code, a kubeconfig or the pod — and are immutable.
Operational verbs
Scale, rollout restart, four patch strategies and server-validated dry runs — each a single call.
Logs, exec and watch
Fetch or stream pod logs, run commands inside a container over WebSocket, and watch resources change in real time.
An in-memory apiserver for tests
Kubernetes::fake() answers and records every request — seed objects, then assert what was created, scaled, restarted or deleted.
Per-cluster rate limiting
400 requests a minute per cluster by default — paced, not failed — honouring the apiserver’s 429 Retry-After.
Traefik and your own CRDs
IngressRoute, Middleware, TLSStore, ServersTransport and TLSOption built in; register custom resources in one line.
Documentation
Installation
Install via Composer, optionally publish config/kubernetes.php, and let auto-discovery register the provider and the Kubernetes facade.
Configuration
Every config/kubernetes.php key with its env var and default — clusters, HTTP client options, rate limits, the Traefik group and the resource map.
The Kubernetes facade
The Kubernetes facade in full: default-cluster shortcuts, named and ad-hoc clusters, the Cluster handle, raw requests and the 33 resource accessors.
DI and actions
Inject KubernetesManager for the facade’s exact API without static calls, or bind resource objects to a managed cluster — the package has no actions.
Connecting to a cluster
Build an immutable client by hand with a URL, token and certificates, from a kubeconfig context, from the pod’s service account or from a KubeConfig.
Named clusters
Configure clusters in config/kubernetes.php or register them in code, then resolve them anywhere by name — through the facade or dependency injection.
Resource accessors
The 33 typed accessors — pods, deployments, services, RBAC, storage, Traefik and more — their kind, API version and scope, plus namespace scoping.
CRUD operations
List, find, check existence, create, update, updateOrCreate and delete any resource — with optimistic concurrency and delete options.
Listing, pagination & watch
Label and field selectors, all-namespace listing, continue-token pagination, lazy iteration and real-time watch streams.
Patch, scale, rollout & dry-run
Four patch strategies, scaling through the /scale subresource, kubectl-style rollout restarts and server-validated dry runs.
Pod logs, exec & status
Fetch or stream pod logs with PodLogOptions, run commands in a container over WebSocket, and read pod and container health.
Attributes, labels & annotations
Dot-path attribute access, spec and status helpers, labels, annotations, magic accessors, dirty tracking and serialisation on every resource.
Building resources with value objects
Compose pods and services from typed Container, Port, Probe, Volume, VolumeMount and claim-template objects instead of raw arrays.
Workloads
Deployments, stateful sets, daemon sets, replica sets, jobs, cron jobs and autoscalers — typed setters and readable status helpers.
ConfigMaps, secrets & networking
ConfigMap and Secret data helpers, TLS secrets in one call, services, ingresses and network policies with correct select-all selectors.
Storage, RBAC & cluster objects
Namespaces, nodes, events, endpoints, volumes and claims, storage classes, roles and bindings, service accounts, quotas and limit ranges.
Traefik CRDs
IngressRoute, Middleware, TLSStore, ServersTransport and TLSOption resources with pinned REST plurals and a configurable API group.
Custom resources & macros
Register your own CRDs, swap a built-in resource for your subclass, and extend the client and resources with macros and conditionals.
Client-side rate limiting
Every apiserver request is paced per cluster — 400 a minute by default, honouring 429 Retry-After, with an optional fail-fast ceiling.
Error handling
Typed exceptions for apiserver errors, unknown or misconfigured clusters, namespace-scope escapes, rate-limit ceilings, kubeconfig loading and exec.
Artisan & diagnostics
Check connectivity with kubernetes:ping and inspect the default cluster, rate limits, resources and Traefik group in php artisan about.
Testing
Kubernetes::fake() swaps in an in-memory apiserver — seed objects, stub logs and exec, then assert creates, updates, scales, restarts and deletes.
Requirements
PHP 8.4+, Laravel 12 or 13 and symfony/yaml — plus three small Roundly packages that install automatically.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.