Orchestration

DevOpsArk + Kubernetes

Agentless connection through the cluster API

Vendor: CNCF

Short answer

What does the DevOpsArk Kubernetes integration do?

The DevOpsArk Kubernetes integration connects any cluster through its API server using scoped credentials, providing inventory, monitoring, cost attribution, security posture and delivery without installing an in-cluster agent.

Capabilities

What the Kubernetes integration provides

  • Connect EKS, AKS, GKE, OpenShift, Rancher-managed and self-managed clusters through one path.
  • Build a continuous inventory of nodes, namespaces, workloads, services and their relationships.
  • Collect pod metrics from the metrics API and events from the cluster event stream.
  • Evaluate pod security standards, network policy coverage and RBAC breadth.
  • Deploy and reconcile workloads through ArkCD where write scope is granted.
  • Detect workloads using APIs removed in the next Kubernetes version.
  • Connect clusters with no inbound connectivity through an outbound-only relay.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • Nodes, namespaces, workloads, services, ingresses and config
  • Pod events and container logs
  • Resource metrics via the Kubernetes metrics API
  • Roles, ClusterRoles and their bindings
  • CustomResourceDefinitions and custom resources
  • Persistent volumes and storage classes
Write, only if granted
  • Workload manifests applied through ArkCD reconciliation
  • Scaling and rollout operations within granted scope
  • Approved remediation such as resource limit changes
Setup

Connecting Kubernetes

  1. 1
    Create a ServiceAccount

    Apply the supplied read-only ClusterRole and binding in the cluster.

  2. 2
    Register the cluster

    Provide the API endpoint and credential, or use a cloud provider identity.

  3. 3
    Verify

    DevOpsArk confirms connectivity and begins building the inventory immediately.

  4. 4
    Add write scope selectively

    Grant namespace-scoped write permissions only where you want DevOpsArk to act.

FAQ

Kubernetes integration: frequently asked questions

Connect Kubernetes and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.