Skip to content

probably the best developer platform*

Drop a lightweight agent into your clusters and see every workload across all of them: owners, exposed services, RBAC risk, Helm and GitOps status. The catalog, search and docs come built in.

*probably. Self-hosted, Kubernetes-native and Backstage-compatible: your catalog-info.yaml files just work.

The Shoehorn dashboard: security, pipelines, workloads, scorecards and team resources at a glance

fig.1 — your whole platform at a glance, discovered automatically

Connect. Map. Ask.

Three moves. Shoehorn does the wiring in between.

01Connect

GitHub org & repos
Kubernetes clusters
Cloud (UpCloud)

About 15 minutes of setup, once.

02Map

checkout-webnotificationspayments-apipostgres

Shoehorn crawls your repos and clusters, then builds the ownership and dependency graph.

137 dependencies across 42 services, none hand-written.

03Ask

who owns payments?
payments-api ● healthy

owned by Team Orion · 3 services depend on it

Found in 184 ms across 42 services.

Your cluster talks out.
Nothing reaches in.

Drop a lightweight agent into your cluster. It watches your workloads and pushes what's running up to Shoehorn over a single outbound connection.

  • No inbound access. No open ports, no firewall holes, no VPN into your cluster.
  • Real-time. Deploy something and it shows up in the catalog within seconds.
  • GitOps-aware. Understands ArgoCD and FluxCD sync status out of the box.
$ helm install shoehorn-agent shoehorn/agent
your kubernetes clusterapi-gatewaypaymentsworkersredisshoehorn-agentwatches & pushesoutbound · tlsShoehorncatalog · graphno inbound

fig.2 — one outbound tls connection carrying workloads, gitops and helm state; inbound is structurally impossible

Everything ships together

Catalog, search, docs, governance and operations: one service in your stack. No plugins to maintain.

A catalog that builds itself

Every service, who owns it, what it depends on, where the docs live, all discovered from your repos and clusters. Nobody has to hand-write a single YAML file.

catalog / services42 services

payments-api

Team Orion · Go

● healthy

checkout-web

Team Vega · Svelte

● healthy

notifications

Team Lyra · Python

● degraded

"what breaks if i change payments-api?"

payments-apicheckoutledgerbillingrefundstransitive

fig.3 — three direct dependents, plus refunds through billing

See the blast radius before you ship

Trace dependencies one to five levels deep. Know exactly what calls the endpoint you're about to deprecate, before the incident instead of during it.

Search that actually finds it

Hybrid keyword and vector search across services, docs and APIs. Stop asking in Slack who owns the thing that's on fire.

search⌘K
who owns auth

auth-service

Team Phoenix · 99.98% uptime

service

Authentication guide

docs · updated 3d ago

doc

12 results · 184ms

Plug your AI assistant
into your platform

Shoehorn ships an MCP server that sits in front of every cluster you've connected. Point Claude, Cursor or Copilot at it and they answer from your real catalog: what's degraded in production, who owns it, what depends on it, where the runbook is.

  • One server, every cluster. Nothing to wire up per cluster. The catalog already merged them.
  • Your permissions carry over. The same Cerbos policies as the web UI. What you can't see, your assistant can't either.
  • Sign in with your company login. Your IDE authenticates through the identity provider you already run. No token pasted into a config file.
  • Read-only. Assistants read. Writes go through the CLI, Terraform or the REST API.
assistant · connected to shoehorn mcp
What's degraded in production right now, and is any of it missing a network policy?
3 degraded workloads across prod-eu-1 and prod-us-2.
payments-api: 12 restarts, liveness probe timing out.
2 of the 3 have no network policy.
via shoehorn mcp · one call

Why Shoehorn?

It runs as part of your stack. No portal team needed just to keep it alive.

Other portalsShoehorn
Days of setup before anything's usefulConnect your GitHub org. Drop an agent into your cluster. 15 minutes.
Maintenance becomes an ongoing side jobJust another service in your stack
Common needs still require extra assemblyCatalog, search, docs, security and Kubernetes operations ship together
Adoption depends on how much rework's requiredBackstage-compatible. Your YAML just works.

Build with Shoehorn

Terraform, CLI, REST or MCP. Every action is an API. Same data underneath.

Free while we're in beta

Self-hosted, per cluster, never per seat. Unlimited entities, users and sources.

Free

[beta]

Self-host on your own infrastructure. Pay nothing while we're in beta.

€0during beta

During beta, Free unlocks everything

Up to 3 Kubernetes clusters and every feature. Your feedback shapes 1.0.


  • Unlimited nodes, entities and users
  • Every feature included
  • Backstage-compatible: your YAML just works
  • A direct line to the team
Get started free