kubriX 8.0.0 - More Self-Service, Less Platform Toil
A developer platform creates value when teams can get things done without waiting for someone else.
kubriX 8.0.0 takes another step in that direction: pull request preview environments, Kubernetes access through Backstage, automated catalog discovery, and more self-service team onboarding.
Alongside these kubriX Prime capabilities, the release updates core platform components and improves the automation we use to validate and maintain kubriX.
🔀 Preview Environments for Pull Requests
kubriX Prime now supports preview environments driven by application pull requests, using Argo CD ApplicationSets.
Platform teams define the defaults during team onboarding. Application teams can adapt them through their application configuration:
- Select which pull request labels trigger preview environments
- Configure reconciliation intervals
- Choose the Helm values files used for preview deployments
- Override team defaults for individual applications
This gives teams a dedicated environment to review and test changes before merging them.
🔑 Kubernetes Access Through Backstage
A new kubriX Prime self-service template provides kubectl access through Keycloak OIDC authentication, scoped by Kubernetes RBAC.
Developers can use the portal to obtain access to the clusters and namespaces their role permits. Platform teams retain control through the existing identity and authorization model.
A common developer request becomes a repeatable self-service workflow.
🗂️ A Catalog That Follows Your Deployments
Keeping a developer catalog up to date should not require maintaining the same application information in several places.
kubriX Prime now automatically discovers team applications and hub-and-spoke platform applications and brings them into the Backstage catalog.
This reduces manual registration and keeps the portal closer to what is actually deployed through Argo CD.
For developers, that means easier discovery. For platform teams, it means less catalog maintenance.
👥 Team Onboarding Through GitOps
The new Prime team-onboarding scaffolder brings configuration and delivery credential provisioning into a single workflow.
- Team configuration is stored in individual team files
- Onboarding creates a pull request for platform-team review
- Argo CD ApplicationSet and Kargo credentials are provisioned as part of the workflow
Teams get a clearer path onto the platform, while platform engineers keep changes reviewable through GitOps.
📊 Observability With Clearer Ownership
Centralized Grafana Folder Permissions
kubriX Prime now manages Grafana dashboard folder visibility and permissions centrally.
Platform teams can define which shared folders are available to which teams. Team memberships are synchronized, reducing separate access-management work in Grafana.
Shared dashboards become easier to govern as more teams join the platform.
Crossplane Monitoring
A new Crossplane metrics dashboard and PodMonitor provide visibility into controller metrics and reconciliation activity.
Grafana metrics collection is also enabled in the Prime configuration, extending monitoring of the platform itself.
Loki Multi-Tenancy
kubriX Prime enables Loki multi-tenancy, supporting separation of log data by tenant alongside the existing authentication integration.
☁️ Expanded Hub-and-Spoke Validation
kubriX 8.0.0 extends the Azure AKS and MetalStack hub-and-spoke demo and test workflows.
The automation covers provisioning, cluster registration, platform installation, and teardown. This helps us validate multi-cluster scenarios beyond the local Kubernetes environments used in our regular CI pipeline.
🔄 Updated Platform Foundations
The release updates components across delivery, identity, security, and observability:
- Argo CD 3.5
- Grafana 13
- Tempo 3
- Keycloak 26.7.4
- Crossplane provider-keycloak 3
- Crossplane provider-vault 4
Kargo, CloudNativePG, Kyverno, External Secrets, and other platform components also receive updates.
As with any major release, customers maintaining their own integrations or configuration overrides should review the relevant migration notes before upgrading.
🧪 Better Validation and Maintenance
The Prime end-to-end test suite now covers more platform features, role-based access, team onboarding, KubeVirt, and vCluster workflows.
We have also improved shared pipeline automation:
- Cached Backstage authentication is validated before reuse
- Parallel test jobs use isolated repository names
- Playwright test images stay aligned with the npm dependency
- Vulnerability checks detect newly introduced CVEs and GHSAs
Prime adds vulnerability assessment tooling, release vulnerability comparisons, and dependency preflight checks for backports.
These improvements strengthen the checks behind each release and support ongoing platform maintenance.
Why kubriX 8.0.0 Matters
This release makes everyday platform workflows easier to use and maintain:
- Faster feedback through pull request preview environments
- More developer autonomy through self-service Kubernetes access
- Less manual maintenance through automated catalog discovery
- Clearer ownership through GitOps team onboarding and Grafana permissions
- Broader validation through extended end-to-end and multi-cluster testing
The result is a platform that gives development teams more autonomy while keeping configuration and access under platform-team control.
Upgrade to kubriX 8.0.0
Already a kubriX Prime customer?
Please review the kubriX 8.0.0 changelog before upgrading, especially if you use custom Helm charts, Grafana plugins, Keycloak integrations, Tempo configuration, or Crossplane managed resources.
ExternalDNS annotations also need attention: the default prefix changes from external-dns.alpha.kubernetes.io/ to external-dns.kubernetes.io/. Temporary compatibility allows migration one ingress at a time; the changelog documents the migration deadline.
Reach out to kubriX support for assistance with planning and validating your upgrade.
New to kubriX?
Explore the release, or let's talk about how to give your teams an internal developer platform with practical self-service and clear operational ownership.
kubriX 8.0.0 - more self-service, less platform toil. 🚀