External control-plane dependency
Critical lifecycle work can depend on a third-party service, egress path or identity boundary.
Sovereign operations
ClusterPilot gives platform and operations teams a self-hosted control plane for provider infrastructure, cluster lifecycle work, add-ons and validation. The customer controls where state, credentials, artifacts, agents and target clusters run.
Operational challenge
Moving a control plane into a customer network does not automatically create sovereignty. Teams still need explicit control over trust, identity, dependencies, software supply chain, execution and evidence.
Critical lifecycle work can depend on a third-party service, egress path or identity boundary.
Provider tokens, SSH access, kubeconfigs and registry credentials move through scripts and operator workstations.
Operational proof is split between vendor logs, local terminals, tickets and target systems.
Enterprise value
The value comes from shared state, explicit ownership and reviewable execution.
API, workers, PostgreSQL and artifact storage run under the customer’s deployment and recovery model.
Lifecycle Agents receive bounded, versioned work and materialize target credentials only inside the approved environment.
Immutable digests, signatures, SBOM, provenance and compatibility metadata identify what is deployed.
Controlled workflow
Each boundary is prepared and accepted independently before production-gated capabilities are enabled.
Place control plane, persistence, artifacts, registry and agents according to network, trust and availability requirements.
Mirror and verify exact image and bundle digests together with signed metadata, SBOM and provenance.
Reference provider, registry and cluster credentials without placing secret values in plans, logs or evidence.
Exercise backup, restore, failure, cleanup and one bounded lifecycle path before environment approval.
Evidence
The operation record connects intention, admission, execution and outcome without requiring a vendor-hosted audit trail.
Actor, scope, plan, resource impact, compatibility, capability gates and destructive confirmation.
Ordered steps, leases, status, events, timings, correlation, redacted logs and stable failure codes.
Results, artifacts, checksums, cleanup status, retry history, acceptance and retention context.
Honest product boundary
Frequently asked questions
Clear answers about fit, boundaries and the evaluation path.
No. The documented deployment model is self-hosted and places the application, state, artifacts and lifecycle execution in the customer environment.
No. ClusterPilot provides technical controls and evidence. Legal, organizational and environmental requirements still need a customer-specific assessment.
The release contract includes digest-pinned distribution, private registry and air-gap workflows. Exact network and trust prerequisites must be validated for the target environment.
Capability scope: v0.0.1 release candidate. Review the current release boundary →
Start with a measurable workflow
We will review the environment, operational bottleneck, control boundaries and evidence needed for a decision.
hello@clusterpilot.de