Open source

The honest comparison: local, in-cluster, or Cloud.

Three ways to run Radar. No marketing gymnastics - here's exactly what you get with each path so you can make the right call for your team.

Local binary
Apache 2.0 · 2.8k

Single binary. Your laptop. Done.

kubectl radar opens your browser in 30 seconds. No cluster install, no in-cluster footprint, no account. Best for individual engineers and on-call work.

Single native binary, every engine feature
Airgap-ready - one anonymous version check; block releases.skyhook.io and api.github.com for zero outbound calls
Auto-discovers any CRD in your cluster
kubectl plugin / brew / krew / curl
Install locally
$brew install skyhook-io/tap/radar
Full install guide in the docs →
In-cluster (Helm)
Apache 2.0 · in-cluster

Run Radar in your cluster. Your team logs in.

Deploy Radar to your cluster with Helm. OIDC or proxy auth lets your whole team in. Per-user K8s RBAC via impersonation. Same engine, no Cloud account. Best for one-cluster teams.

OIDC: Google, Okta, Dex, Keycloak
Proxy: oauth2-proxy, Pomerium, Cloudflare Access
Per-user K8s RBAC via impersonation
Airgap-ready - cluster data stays local; block the version-check endpoints for zero outbound calls
Install in-cluster
$helm repo add skyhook https://skyhook-io.github.io/helm-charts helm install radar skyhook/radar -n radar --create-namespace
In-cluster deployment docs →
Cloud
Hosted SaaS

Multi-cluster fleet. We host it.

Radar Cloud is the hosted control plane on top of the same engine. It adds the things only useful at fleet scale: cross-cluster views, long-term retention, SSO, and routed alerts.

Unified view across every cluster
Per-cluster event timeline retained in Cloud for up to 1 year
SAML/OIDC SSO + SCIM on Enterprise, scoped RBAC
Slack, PagerDuty, MS Teams, webhooks
Connect to Cloud
$helm repo add skyhook https://skyhook-io.github.io/helm-charts helm install radar skyhook/radar -n radar --create-namespace \\ --set cloud.token=$TOKEN
Feature by feature

The full comparison matrix.

Three deployments, same engine. Where OSS is enough, it says so. Where Cloud adds value, we explain why.

Core engine

Topology graph

Live service + workload topology with real-time connections

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Enhanced (multi-cluster)

Resource explorer

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Helm release manager

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Image filesystem viewer

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

TLS certificate tracker

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Traffic visualization

Auto-detects Hubble, Caretta, or Istio

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Cluster audit (36 checks)

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Cost insights (OpenCost)

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

MCP / AI integration

Built-in MCP server, enabled by default

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

GitOps (FluxCD + ArgoCD)

Sync state, app-of-apps, reconciliation triggers

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Scope

Clusters

Local binary connects via your kubeconfig, one active context at a time. In-cluster Helm sees the cluster it runs in. Cloud connects multiple clusters via in-cluster Radar instances and shows them all in one fleet view.

Local binary
Any cluster via kubeconfig
In-cluster (Helm)
Cluster where deployed
Cloud
Unlimited, all in one fleet view

Users

Local binary is single-user (your laptop). In-cluster Helm authenticates via OIDC or proxy and impersonates each user against the K8s API. Cloud users sign in to your workspace.

Local binary
1 (local)
In-cluster (Helm)
Unlimited (OIDC + RBAC)
Cloud
Unlimited

Multi-cluster dashboards

Local binary
No
In-cluster (Helm)
No
Cloud
Yes

Cross-cluster search

Local binary
No
In-cluster (Helm)
No
Cloud
Yes

Data retention

Event timeline

Radar stores timeline evidence in memory by default or local SQLite when persistence is configured. Radar Cloud adds cloud-backed event retention up to one year.

Local binary
In-memory or local SQLite
In-cluster (Helm)
Local SQLite, configurable
Cloud
24 hours / 30 days / 1 year

Audit log of UI actions

Cloud retention is 7 days on Free, 30 days on Team, and 365 days on Enterprise.

Local binary
No
In-cluster (Helm)
No
Cloud
7 / 30 / 365 days

Resource-change diffs while retained

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Yes

Authentication & access

Auth modes

Local binary uses your kubeconfig directly. In-cluster Helm supports proxy auth (oauth2-proxy, Pomerium, Cloudflare Access) and OIDC (Google, Okta, Dex, Keycloak). Cloud adds Google/GitHub sign-in on every plan, with SAML/OIDC SSO and SCIM on Enterprise.

Local binary
kubeconfig
In-cluster (Helm)
Proxy, OIDC
Cloud
Google & GitHub on every plan; SAML/OIDC + SCIM on Enterprise

Team workspaces

Local binary
No
In-cluster (Helm)
No
Cloud
Yes

Role-based access control

In-cluster uses K8s RBAC via impersonation. Cloud adds workspace-level scoped roles.

Local binary
K8s native
In-cluster (Helm)
K8s native (impersonation)
Cloud
K8s native + scoped roles

Collaboration

Shareable deep-links

Local binary
No
In-cluster (Helm)
Within your network
Cloud
Yes

Annotations on resources

Local binary
No
In-cluster (Helm)
No
Cloud
Yes

Slack / PagerDuty / MS Teams alerts

Local binary
No
In-cluster (Helm)
No
Cloud
Yes

Webhook integrations

Local binary
No
In-cluster (Helm)
No
Cloud
Yes

Operations

Hosting

Local binary
Your laptop
In-cluster (Helm)
Your cluster
Cloud
Fully managed SaaS

Updates

Local binary
Manual binary upgrade
In-cluster (Helm)
Manual `helm upgrade`
Cloud
Automatic, zero-downtime

Uptime SLA

Team targets 99.5% uptime without service credits. Enterprise provides a 99.9% SLA with service credits.

Local binary
No
In-cluster (Helm)
No
Cloud
Varies by Cloud tier

Professional support

Cloud Free uses community support. Team adds email, in-app chat, and a dedicated Slack channel. Enterprise adds a CSM and phone support.

Local binary
GitHub Discussions
In-cluster (Helm)
GitHub Discussions
Cloud
Varies by Cloud tier

Outbound network calls

Both OSS deployments run airgapped: block egress to releases.skyhook.io and api.github.com (its fallback) and there are zero outbound calls. Otherwise the one outbound call is an anonymous version check when the UI opens (version plus OS/arch). Cloud-connected Radar instances open an outbound tunnel to the Radar control plane.

Local binary
Anonymous version check only
In-cluster (Helm)
Anonymous version check only
Cloud
In-cluster → control plane

Data residency

Local binary
Your laptop
In-cluster (Helm)
Your cluster
Cloud
US hosted; EU region or BYOC on Enterprise

Compliance

SOC 2 Type 2

Local binary
N/A (you host)
In-cluster (Helm)
N/A (you host)
Cloud
Yes

BYOC / on-prem deployment

Local binary
Yes
In-cluster (Helm)
Yes
Cloud
Enterprise plan

Source code visibility

Local binary
Full (Apache 2.0)
In-cluster (Helm)
Full (Apache 2.0)
Cloud
In-cluster Radar only (Apache 2.0)
Our commitments

Four promises we make to the OSS community.

You're going to invest time learning Radar. Here's what we commit to in return.

The OSS stays OSS.

Radar is Apache 2.0. It will remain Apache 2.0. We will not relicense to BUSL, SSPL, Elastic License, or any other 'open-ish' license that reserves commercial rights for us.

No artificial crippling.

We won't remove features from the OSS to push you toward Radar. If a feature ships in OSS, it stays in OSS. Radar features exist because they can't work in a local binary - not because we gated them.

Community contributions welcome.

We review PRs from the community the same way we review internal PRs. Maintainers at Skyhook are paid to make the OSS better, not to keep it behind Radar Cloud.

What runs in your cluster is open-source too.

The in-cluster Radar install that connects to Radar Cloud is Apache 2.0 and auditable. You can read every line of code that runs in your cluster.

Live · Community signal·2.8k

Loved by Kubernetes operators.

Unfiltered signal from teams running Radar in their clusters. Click any card to see the original.

Redditr/devops

I got kicked out of Lens free dashboard and now I need to subscribe, after using it since like 2020. Saw this post, made the switch and holy I am in love … Lens should be free and this dashboard should be paid 😂

u/More-Lavishness-9969view →
Redditr/kubernetes

Looks very promising at first sight, especially the visualizations for topology, timeline and traffic.

u/zZzHerozZzview →
Redditr/kubernetes

loudly said oo0o0oo when I got it running.

u/sp_dev_guyview →
GitHubskyhook-io/radar #355

I am really liking Radar so far and I am finding it much more useful and streamlined than using Lens IDE.

@UntestedEngineerview →
Redditr/kubernetes

Love it. A fantastic bit of work here. Well done!

u/Double_Intention_641view →
GitHubskyhook-io/radar #54

The topology feature is great.

@vrabbiview →
Redditr/kubernetes

It looks gorgeous.

u/Double_Intention_641view →

More feedback every week on GitHub, Reddit, and the Kubernetes Slack.

When to upgrade

You probably want Radar Cloud when...

You run more than one cluster and jumping kubeconfigs is slowing down incidents.
Your on-call rotation is more than one person and you need a shared view of what's happening.
You need to prove to an auditor what happened 60 days ago.
Your security team needs SAML SSO and SCIM provisioning.
You want Slack or PagerDuty integrations without writing a custom controller.
You're spending engineering time maintaining your own Radar deployment instead of using it.

Try it. Both of them.

Install OSS Radar in 30 seconds. Connect it to Radar Cloud in 30 more. See the difference.

Apache 2.0 OSS · Unlimited clusters with Radar OSS · Hosted free tier for up to 3 clusters