Architecture

Standard interfaces, scoped credentials, nothing installed

DevOpsArk reads your estate the way your own scripts would, through the Kubernetes API, cloud provider APIs and OpenTelemetry. That is what makes a security review short and a cluster onboarding a five-minute job.

Short answer

How does DevOpsArk connect to my infrastructure?

DevOpsArk connects to your estate over standard interfaces (the Kubernetes API, cloud provider APIs, Git provider APIs and OpenTelemetry) using scoped, revocable credentials, and installs nothing inside your clusters by default.

Connection model

What connects to what

Your Kubernetes
EKSAKSGKEOpenShiftSelf-managedEdge clusters
Your cloud and hosts
AWS accountsAzure subscriptionsGCP projectsVirtual machinesBare metal
Connection
Kubernetes APICloud provider APIsGit provider APIsOTLPOutbound relay
DevOpsArk control plane
Shared inventoryTelemetry storePolicy engineDelivery engineArk agents
Every connection is a credential you create and can delete. There is no in-cluster component by default.
Access

What DevOpsArk reads, and what it can write

SourceRead (default)Write (only if granted)
KubernetesNodes, namespaces, workloads, services, ingresses, events, resource metrics, RBAC, CRDsWorkload manifests via ArkCD, scaling and rollout operations, approved remediation
Cloud accountsInstances, networks, storage, load balancers, IAM, DNS zones, billing exportsCluster provisioning via DMK8S, DNS record changes, approved remediation of tagged resources
Git providersRepository contents, manifests, commits, pull requests, pipeline runs, team membershipGenerated container definitions, pull request checks, deployment statuses, release notes
RegistriesRepositories, images, tags, digests, existing scan resultsImages pushed by ArkBuilder
TelemetryMetrics, logs and traces you route to the platform, plus existing Prometheus and LokiNothing, telemetry sources are read-only
Write access is never implied. Read and write are separate grants. Adding delivery or remediation for one namespace does not extend access anywhere else, and revoking it is deleting a role binding.
Connectivity

Clusters that cannot accept inbound connections

Edge sites behind carrier NAT, regulated environments with no public endpoint, and air-gapped clusters all share the same constraint: nothing outside may initiate a connection inward.

For these, the cluster initiates an outbound connection to a relay and management traffic flows over the connection it established. No ingress rule, no public API endpoint and no inbound firewall change is required.

Because the connection is initiated by the cluster, it is also revoked by the cluster: removing the relay component ends the connection regardless of anything at the other end.

Restricted cluster
No inbound pathNo public endpointRelay initiates outbound
Transport
Outbound TLSCluster-initiatedRevocable at the cluster
Control plane
InventoryTelemetryDelivery
Outbound-only connectivity for clusters that accept nothing inbound.
Onboarding

Connecting a cluster, step by step

  1. 1
    Create a ServiceAccount

    Apply the supplied read-only ClusterRole and binding in the cluster, or supply a cloud provider identity instead.

  2. 2
    Register the endpoint

    Provide the API endpoint and credential in DevOpsArk, or deploy the relay for a restricted cluster.

  3. 3
    Verify

    The connection is checked immediately and the inventory begins building.

  4. 4
    Review what is visible

    Inventory, health, security posture and cost attribution appear without any further configuration.

  5. 5
    Grant write scope selectively

    Add namespace-scoped write permissions only for the operations you want DevOpsArk to perform.

Data

What leaves your environment, and what does not

Read by DevOpsArk
  • Resource inventory and configuration
  • Metrics and resource usage
  • Kubernetes and cloud events
  • Logs you explicitly route to the platform
  • Deployment and pipeline history
  • Access bindings and policy configuration
  • Billing and usage exports
Not read
  • Application data in your databases
  • Contents of persistent volumes
  • Object storage contents
  • Secret values held in external stores
  • Customer or end-user records
FAQ

Architecture questions

Connect a cluster during the call

Onboarding is a ServiceAccount and a role binding. Most demos start with your own inventory rather than ours.