Product

One controlled operating path for the Kubernetes lifecycle.

ClusterPilot standardizes provider infrastructure, cluster changes, add-ons, validation and evidence in a customer-hosted execution model.

01

Plan before change

Expose intended resources, steps, locks, compatibility, and risk before assigning work.

02

Gate every boundary

Keep authorization, capability maturity, provider readiness, agent compatibility, and approval separate.

03

Preserve the truth

Project immutable history, stable errors, artifacts, checksums, audit, and explicit cleanup state.

Real product workflow

Connect the provider. Build the cluster. Keep the proof.

ClusterPilot keeps provider readiness, infrastructure state and Kubernetes operations connected across every handoff.

Operational depth without hidden execution.

Every capability follows explicit admission, immutable inputs, a compatible execution boundary, and evidence contracts.

01
Core contract

Deterministic OperationRuns

Critical actions become durable runs with explicit plans, ordered steps, assignments, events, bounded logs, artifacts, cancellation, retry, and recovery context.

Open documentation →
02
Stable providers / gated

Provider infrastructure

Model accounts, validation, discovery, networks, machines, volumes, firewalls, quotas, and provider failures without mixing cloud calls into Kubernetes semantics.

Open documentation →
03
Production-gated

Cluster lifecycle

Apply the selected OS hardening profile, prepare supported Linux nodes, bootstrap kubeadm, install Calico, scale, upgrade one minor, replace, inspect, and delete under explicit gates.

Open documentation →
04
Production-gated

Add-ons and health

Resolve immutable artifact locks, validate dependencies, install curated or custom add-ons, and require semantic health evidence—not merely running pods.

Open documentation →
05
Candidate / gated

Conformance evidence

Orchestrate pinned Sonobuoy quick, non-disruptive, or certified workflows with admission, privilege, artifacts, immutable results, and cleanup.

Open documentation →
06
Production-gated

Release and security controls

Fail closed on unsafe production configuration, require immutable images and signed metadata, redact sensitive values, and preserve authorization and audit.

Open documentation →

Built for the day after provisioning

See success, failure and governance in the same operating model.

A platform earns trust when operators can understand why work stopped, what is safe next and who controls the boundary.

How ClusterPilot fits

Use your tools. Standardize the operation between them.

ClusterPilot is a workflow and evidence layer, not a claim to replace every infrastructure or delivery system.

Terraform / IaCDeclares and provisions infrastructure

ClusterPilot adds lifecycle admission, agent execution state, recovery and evidence across infrastructure and Kubernetes.

CI/CD & GitOpsBuilds and delivers applications

ClusterPilot governs cluster platform operations and can install approved delivery add-ons without becoming the application pipeline.

Managed KubernetesProvides a provider-operated cluster service

ClusterPilot is customer-hosted and targets repeatable operations across customer-controlled provider and host boundaries.

Scripts & runbooksCapture expert procedures

ClusterPilot turns approved procedures into planned, stateful, observable and auditable OperationRuns.

Four-layer operating model

Clear ownership at every boundary.

The control plane decides and records. The agent executes bounded compatible work. External systems remain explicit dependencies rather than hidden platform internals.

1ExperienceWeb UI · API · automation

Intent, approval, visibility

2ControlAuth · plans · gates · workers

Policy and orchestration

3ExecutionCompatible lifecycle agents

Bounded provider and host work

4EvidencePostgreSQL · artifacts · audit

Durable state and proof

Designed to fail closed

Know why work stopped—and what is safe next.

Stable ProblemDetails codes, explicit next actions, operation state, dependency posture, and integrity-checked evidence replace vague “something failed” outcomes.

  • No hidden mutation on read paths
  • No tag-only release fallback
  • No credential material in operation options
  • No retry without replay and conflict controls
See operator troubleshooting →

Talk to ClusterPilot

See whether ClusterPilot’s operating model fits your environment.

Bring us one high-friction lifecycle workflow. We will map it to the current product boundary and a useful technical evaluation.

hello@clusterpilot.de