Moving or incomplete artifacts
Tag-only mirroring can change identity or omit charts, tools, metadata and transitive dependencies.
Restricted and disconnected environments
ClusterPilot’s release and registry contracts are designed to preserve exact subjects, digests, metadata and evidence while artifacts move through a customer-controlled promotion path.
Operational challenge
A mirrored container image alone is not enough. Operators need compatible tools, Kubernetes and add-on artifacts, trust material, signed metadata and a repeatable way to prove the promoted set.
Tag-only mirroring can change identity or omit charts, tools, metadata and transitive dependencies.
Private CAs, registry endpoints and host trust stores can diverge between control plane, agents and targets.
Teams may know that files were copied without retaining a digest- and approval-bound release record.
Enterprise value
The value comes from shared state, explicit ownership and reviewable execution.
API, agent, tool, Kubernetes and add-on subjects are selected by exact digest and compatibility metadata.
Harbor or another approved registry becomes the customer policy and promotion boundary.
Checksums, signatures, SBOM, vulnerability evidence and provenance remain associated with the promoted release.
Controlled workflow
The same artifact identity is preserved from connected staging through the restricted runtime.
Select the exact release, compatibility line, provider tools, Kubernetes artifacts and approved add-ons.
Validate checksums, signatures, digests, SBOM and provenance in the connected zone.
Transfer the complete inventory, preserve digests, apply customer policy and record promotion approval.
Confirm registry trust, agent compatibility, runtime digests and retained evidence before lifecycle work.
Evidence
Operators can connect the approved inventory to the runtime subjects and the operation that consumed them.
Version, commit, immutable subjects, exact digests and signed compatibility metadata.
Source and destination registry, policy result, actor, timestamp, checksums and approval.
Agent/tool identity, pulled digest, trust posture, operation result and retained artifact evidence.
Honest product boundary
Frequently asked questions
Clear answers about fit, boundaries and the evaluation path.
The documented registry and air-gap model supports customer-controlled distribution. The exact dependency inventory and network design must be validated for the selected capabilities.
The supported release posture is digest-pinned. A moving tag alone does not preserve artifact identity or provide sufficient verification evidence.
Private trust is part of the documented deployment boundary. The CA must be installed and validated consistently across the control plane, agents, registries and target hosts.
Capability scope: v0.0.1 release candidate. Review the current release boundary →
Start with a measurable workflow
We will review the environment, operational bottleneck, control boundaries and evidence needed for a decision.
hello@clusterpilot.de