Security & customer control

Keep control and data inside your environment.

ClusterPilot is built for customer-hosted operation. Identity, software, credentials, permissions, execution and critical changes are checked separately.

Secure agent connection

Every lifecycle agent receives a clear identity and short-lived access.

ClusterPilot checks the endpoint, enrolls the agent and limits every token to the right operation.

01

TLS trust

The agent checks that it is connected to the correct ClusterPilot endpoint.

02

Secure enrollment

A dedicated bootstrap token connects a new agent to the control plane.

03

Short-lived access

Signed tokens link access to the right operation, agent and time window.

Read the lifecycle-agent documentation →

Built to run in your environment.

You operate the control plane, database, agents, registry, credentials and target environments.

Approved operator networkUsers · API clients · IdP boundary
Customer control planeAPI · Workers · PostgreSQL · ArtifactsAuthentication · Plans · Policy · Evidence
Execution boundaryLifecycle agents · Secret materializationVersioned work · Isolated commands · Cleanup
Customer target estateProviders · Hosts · Registries · Kubernetes clusters

Control families

Several layers protect every critical operation.

Security is not one switch. Every handoff has its own checks and clear ownership.

01

Identity

Separate access for people, API clients and lifecycle agents.

02

Permissions

Roles define who can view, start and approve an operation.

03

Secrets

Credentials stay out of plans, logs, URLs and support files.

04

Software

Checksums, signatures and fixed image digests identify every release.

05

Execution

Short-lived tokens and clear scopes protect each operation.

06

History

Actors, steps, results and important events remain easy to review.

Software supply chain

Deploy a release you can verify, not a moving tag.

Checksums, fixed digests, signed metadata, the SBOM and provenance show exactly which software is running.

Registry and air-gap operations →
01Verify

Checksums, signatures, build identity

02Mirror

Preserve subject, digest, metadata, evidence

03Promote

Apply customer policy and record approval

04Attest

Confirm runtime digest and retained proof

Safe defaults

Unsafe shortcuts are rejected clearly.

  • Production startup rejects missing durable database, artifact, or key settings
  • Multi-replica operation requires leader election and shared artifacts
  • Runtime software uses verified, fixed image digests
  • Roles and approvals protect sensitive actions
  • Agent placement, trust, clock, runtime, and version are negotiated before work
  • Secrets are excluded from ProblemDetails and evidence contracts
Mandatory SaaSNoneCustomer hosts the control plane
AccessRole-basedPeople see and start only the right workflows
Software identityVerifiableChecksums, signatures and fixed digests
Operation historyTraceableSteps, actors and results stay together

Talk to ClusterPilot

Review your security boundaries with us.

We will discuss your identity, network, registry, result and approval requirements in a focused technical call.

hello@clusterpilot.de