Identity
Human sessions, machine API keys, agent identity, and operation-scoped target credentials are separate contracts.
Security & customer control
ClusterPilot is self-hosted by design and treats identity, release integrity, credentials, authorization, execution, audit, and destructive operations as first-class system boundaries.
Clear claim boundary. ClusterPilot provides technical controls and evidence. It does not claim that deployment alone creates regulatory compliance, complete sovereignty, or production approval.
The customer operates the control plane, persistence, agents, registry connection, credentials, and target environments.
Control families
Security is not a single “secure” toggle. Each transition has a distinct control and evidence owner.
Human sessions, machine API keys, agent identity, and operation-scoped target credentials are separate contracts.
RBAC, tenant/workspace scope, feature gates, admission, destructive confirmation, and environment approval remain independent.
Customer-managed protection key and typed SecretRefs keep credential values outside plans, logs, URLs, audit, and support bundles.
Checksums, signatures, immutable digests, compatibility metadata, SBOM, vulnerability evidence, and provenance identify the release.
Compatible agents receive bounded typed work; contract versions, leases, ordering, timeouts, redaction, and cleanup constrain execution.
Actors, decisions, plans, events, command results, artifacts, checksums, correlation, and retention form the review trail.
Software supply chain
The self-hosted release contract binds runtime subjects, exact digests, signed compatibility and release metadata, SBOM, provenance, and verification evidence.
Registry and air-gap operations →Checksums, signatures, build identity
Preserve subject, digest, metadata, evidence
Apply customer policy and record approval
Confirm runtime digest and retained proof
Fail-closed defaults
Talk to ClusterPilot
Bring your identity, network, registry, evidence, and operational-approval requirements to a focused technical conversation.
hello@clusterpilot.de