Runtimez runtimez
Connect a cluster
live · read-only agent v1.4

Ship the upgrade without a war room.

Runtimez reads every connected cluster read-only and tells you exactly what the next Kubernetes version breaks — which workloads, which owners, and how long until the upgrade is forced on you.

Connect a cluster — free Book a risk teardown

one helm install · get, list, watch only · first score in under an hour

fleet risk MEDIUM
62 of 100
upgrade HIGH
security 12 crit
releases 86%
cost $2.4k
4 clusters assessedwindow 7d
open findings +4 · 24h
38
7 crit · 19 high
releases 7d pass rate
86%
18 healthy · 2 degraded
monthly waste identified
$2.4k
9 workloads over-provisioned
attention queue · streaming 4 of 4 · ranked by score impact
APPROVAL1.31 removes an API still in useprod-eu-west-1+7 risk
APPROVALcert-manager CRD on a removed versionprod-us-east-1blocker
CRITICALcheckout-api: CVE on the blocking imageprod-us-east-12 risks
AUDITforced upgrade window opens in 64 days2 clustersclock
prod-eu-west-1 · risk 81 · degraded checkout-api · CVE-2024-21626 · critical cert-manager · CRD removed @ 1.31 forced upgrade in 64d · 2 clusters batch-worker · 4× over-provisioned · $640/mo CIS 82% · NSA 79% · prod-us-east-1
the platform

One agent. Six answers. No new collector.

Everything below runs off the same read-only sweep — correlated per workload, not stitched together by you.

◆ cross-axis

Security ∩ upgrade, joined by workload

The differentiator: findings are not two backlogs. A critical CVE sitting on the same deployment that blocks your 1.31 upgrade surfaces as one item, ranked first, because one change retires both risks.

one ranked queue scored per workload fleet rollups
↑ upgrade risk

What the next version breaks

Deprecated and removed APIs, CRD coverage and runtime usage per workload — with the forced-upgrade clock and extended-support exposure on every cluster.

1.30 → 1.37 CRD coverage
☣ security

CVEs scanned in place

Ephemeral in-cluster jobs read running images and config where they live. Images and pull secrets never leave. CIS and NSA scorecards per cluster.

in-cluster CIS · NSA
▲ releases

Every rollout verified

Healthy, degraded, awaiting verification or rolled back — with a pass rate computed over verified rollouts only, and an alert the moment one degrades.

verdict per release slack alerts
$ cost

Spend mapped to owners

Requests sized against real p95 usage per namespace, workload and cluster. Over-provisioned and idle workloads carry a monthly number; unowned spend gets named.

right-sizing ownership map
✦ agent

Ask runtimez

Questions answered from your own fleet — inventory, findings, posture — with a confidence score and a deep link into the cluster the answer came from. In Slack or in console.

slack · console grounded answers
release verdicts · 7d 86% pass

Every rollout is verified against live signals after it lands. A degraded release becomes the first row of the queue, not a Slack thread someone missed.

checkout-api v2.31.0 · prod-us-east-1 DEGRADED
payments-worker v1.8.4 · prod-eu-west-1 HEALTHY
search-indexer v0.44.2 · staging-eu AWAITING
web-frontend v5.12.1 · prod-us-east-1 HEALTHY
ask runtimez live · fleet signals

Ask in Slack or in the console. Answers come from your own inventory, findings and posture — with a confidence score and a link back to the cluster.

@sre-oncall in #platform
what blocks prod-us-east-1 from 1.31?
runtimez · conf. 92%
3 blockers. checkout-api carries a critical CVE on the same image as a removed API — bump it once and both clear.
open in runtimez →
install · 2 minutes
$ helm repo add runtimez https://charts.runtimez.io
$ helm install runtimez-agent runtimez/runtimez-agent \
    --set token=rkc_••••
 
✓ registered · rbac: get, list, watch
✓ 304 objects · 15 namespaces · nothing egressed
! 3 upgrade blockers · 7 critical findings
→ fleet risk 62/100 · queue ready
✓
Read-only RBAC
get, list, watch. No mutating verbs, no kubeconfig handover, no inbound access.
✓
Secret names only
Inventory records that a secret exists. Values are never read or transmitted.
✓
Scanning stays inside
Scan jobs run as ephemeral pods in your cluster. Images and pull secrets never egress.
✓
Multi-tenant by org
Every call is scoped to your org. Clusters, findings and tokens never cross tenants.
who it's for
platform engineering

Own the upgrade

Blockers, owners and order of work before you book the window — plus a countdown on every cluster approaching forced upgrade.

›deprecated & removed API detection
›fleet ranked by nearest deadline
›extended-support exposure in dollars
sre & on-call

Work the queue

Degraded rollouts first, then blocked gates, then the CVEs riding along with them. Ask runtimez from the channel you are already in.

›release verdicts with pass rate
›restart, rollout and probe health
›alerts before the incident
cto & infra leads

Report the number

One fleet score with a level, compliance posture per cluster, and cost attributed to teams — reported without a dashboard project.

›fleet risk score, rolled up
›CIS & NSA scorecards
›unowned spend named

See your fleet risk score in under an hour.

Free for your first cluster. Read-only by default. Uninstall is one helm command.

Connect a cluster Book a risk teardown