Skip to main content

The Hubble UI

Inspect 1.36

The Hubble UI draws the live service map: which workloads talk to which, and where traffic is dropped, updating as connections happen. It is the quickest way to see a namespace's real dependencies. It also has no login, so how you reach it matters more than usual.

Warning

The Hubble UI shows the full cluster flow data to anyone who can reach it, with no login screen. Never expose it on a type: LoadBalancer Service on a cluster shared by more than one team or reachable from the internet. That publishes your entire service map, unauthenticated, to anyone who reaches the IP.

How to reach it

Port-forward, so nothing is exposed to the network:

		$ kubectl port-forward -n kube-system svc/hubble-ui 12000:80
	

Then open http://localhost:12000. This is the right choice for a quick investigation by one person.

Combine it with the other signals

Hubble shows network activity only. When you are investigating an incident, read it next to , which show who changed the policy, and , which shows whether a file changed on a node.