Plan before change
Expose intended resources, steps, locks, compatibility, and risk before assigning work.
Product
ClusterPilot standardizes provider infrastructure, cluster changes, add-ons, validation and evidence in a customer-hosted execution model.
Expose intended resources, steps, locks, compatibility, and risk before assigning work.
Keep authorization, capability maturity, provider readiness, agent compatibility, and approval separate.
Project immutable history, stable errors, artifacts, checksums, audit, and explicit cleanup state.
Real product workflow
ClusterPilot keeps provider readiness, infrastructure state and Kubernetes operations connected across every handoff.
Register write-only credentials, validate the provider boundary, and continue only when the account is ready for infrastructure.
Review provider-safe defaults, node roles and the deterministic plan before infrastructure provisioning starts.
Track ordered lifecycle and add-on work with status, actor, duration, stable failure context and an explicit recovery path.
Every capability follows explicit admission, immutable inputs, a compatible execution boundary, and evidence contracts.
Critical actions become durable runs with explicit plans, ordered steps, assignments, events, bounded logs, artifacts, cancellation, retry, and recovery context.
Open documentation →Model accounts, validation, discovery, networks, machines, volumes, firewalls, quotas, and provider failures without mixing cloud calls into Kubernetes semantics.
Open documentation →Apply the selected OS hardening profile, prepare supported Linux nodes, bootstrap kubeadm, install Calico, scale, upgrade one minor, replace, inspect, and delete under explicit gates.
Open documentation →Resolve immutable artifact locks, validate dependencies, install curated or custom add-ons, and require semantic health evidence—not merely running pods.
Open documentation →Orchestrate pinned Sonobuoy quick, non-disruptive, or certified workflows with admission, privilege, artifacts, immutable results, and cleanup.
Open documentation →Fail closed on unsafe production configuration, require immutable images and signed metadata, redact sensitive values, and preserve authorization and audit.
Open documentation →Built for the day after provisioning
A platform earns trust when operators can understand why work stopped, what is safe next and who controls the boundary.
How ClusterPilot fits
ClusterPilot is a workflow and evidence layer, not a claim to replace every infrastructure or delivery system.
ClusterPilot adds lifecycle admission, agent execution state, recovery and evidence across infrastructure and Kubernetes.
ClusterPilot governs cluster platform operations and can install approved delivery add-ons without becoming the application pipeline.
ClusterPilot is customer-hosted and targets repeatable operations across customer-controlled provider and host boundaries.
ClusterPilot turns approved procedures into planned, stateful, observable and auditable OperationRuns.
Four-layer operating model
The control plane decides and records. The agent executes bounded compatible work. External systems remain explicit dependencies rather than hidden platform internals.
Intent, approval, visibility
Policy and orchestration
Bounded provider and host work
Durable state and proof
Designed to fail closed
Stable ProblemDetails codes, explicit next actions, operation state, dependency posture, and integrity-checked evidence replace vague “something failed” outcomes.
Talk to ClusterPilot
Bring us one high-friction lifecycle workflow. We will map it to the current product boundary and a useful technical evaluation.
hello@clusterpilot.de