TLS trust
The agent checks that it is connected to the correct ClusterPilot endpoint.
Security & customer control
ClusterPilot is built for customer-hosted operation. Identity, software, credentials, permissions, execution and critical changes are checked separately.
Secure agent connection
ClusterPilot checks the endpoint, enrolls the agent and limits every token to the right operation.
The agent checks that it is connected to the correct ClusterPilot endpoint.
A dedicated bootstrap token connects a new agent to the control plane.
Signed tokens link access to the right operation, agent and time window.
You operate the control plane, database, agents, registry, credentials and target environments.
Control families
Security is not one switch. Every handoff has its own checks and clear ownership.
Separate access for people, API clients and lifecycle agents.
Roles define who can view, start and approve an operation.
Credentials stay out of plans, logs, URLs and support files.
Checksums, signatures and fixed image digests identify every release.
Short-lived tokens and clear scopes protect each operation.
Actors, steps, results and important events remain easy to review.
Software supply chain
Checksums, fixed digests, signed metadata, the SBOM and provenance show exactly which software is running.
Registry and air-gap operations →Checksums, signatures, build identity
Preserve subject, digest, metadata, evidence
Apply customer policy and record approval
Confirm runtime digest and retained proof
Safe defaults
Talk to ClusterPilot
We will discuss your identity, network, registry, result and approval requirements in a focused technical call.
hello@clusterpilot.de