Use case
Manage Kubernetes from your phone
Chat with a Claude Code session on a server you own, one that already has access to your cluster, and approve each command it wants to run from the Escanor app on Android or iPhone. Your kubeconfig stays on the server. The server does the work, and you decide on every write.
How it works
Step 1
Connect a server that can reach the cluster
Install the Escanor agent on a Linux server you own, with Node.js 20 or newer, git and systemd. The agent connects out to Escanor, so you open no inbound ports. Give the server only the cluster access you want a session to have.
Connect a VMStep 2
Install the phone app
On Android, install the APK from the Escanor home page. On iPhone, sideload the preview build with Sideloadly or AltStore.
Android appStep 3
Open a chat with the machine
Each chat with a machine is its own Claude Code session, with a working directory and history. Ask for a read first, such as the state of the pods in one namespace, and check the answer against the cluster.
MachinesStep 4
Approve each command
By default Claude Code asks before it runs a command or edits a file, and the app shows each request as an Allow or Deny card. Read-only operations go through without asking.
Machine session modes
Get the phone app
Both apps have the same screens: chat, voice, connections, computers, machines and approvals. Download them from the download section.
Android
- Download the APK from the home page. It needs Android 7 or newer.
- Approvals and alerts arrive as notifications.
- To update, install the newer APK over the old one.
iPhone
- Install the preview build with Sideloadly or AltStore and your own Apple ID. It needs iOS 15 or newer.
- Open the app to see pending approvals.
- When your signing profile expires, renew it through the sideloading tool.
Choose how much the session may do
Set the permission mode per chat: default, auto, accept edits, plan, don't ask or bypass. You can also pick the model and reasoning effort, and changes apply immediately, even mid-session. Start in plan or default mode, and keep bypass for an isolated environment.
Run the agent under an unprivileged account and give it cluster credentials scoped to what sessions should touch. See Permissions and approvals.
Any cluster your server can reach
The machine route works with any cluster the server's own credentials can reach, whether self-hosted or managed. Kubernetes, Amazon EKS, Azure AKS and Google GKE are also in the integrations catalog, next to AWS, Google Cloud, Azure and Docker. See the MCP provider list for how each one connects.
Before you approve a change from your phone
- Confirm the machine is online and the chat is in the project you meant.
- Run a read first and compare it with the cluster.
- Read the exact command on the Allow card, including the namespace and context.
- Allow one change, then ask the session to check the result.
- If a request is denied, narrow the scope rather than widening credentials.