DevOpsArk + Kubernetes
Agentless connection through the cluster API
Vendor: CNCF
What does the DevOpsArk Kubernetes integration do?
The DevOpsArk Kubernetes integration connects any cluster through its API server using scoped credentials, providing inventory, monitoring, cost attribution, security posture and delivery without installing an in-cluster agent.
What the Kubernetes integration provides
- Connect EKS, AKS, GKE, OpenShift, Rancher-managed and self-managed clusters through one path.
- Build a continuous inventory of nodes, namespaces, workloads, services and their relationships.
- Collect pod metrics from the metrics API and events from the cluster event stream.
- Evaluate pod security standards, network policy coverage and RBAC breadth.
- Deploy and reconcile workloads through ArkCD where write scope is granted.
- Detect workloads using APIs removed in the next Kubernetes version.
- Connect clusters with no inbound connectivity through an outbound-only relay.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- Nodes, namespaces, workloads, services, ingresses and config
- Pod events and container logs
- Resource metrics via the Kubernetes metrics API
- Roles, ClusterRoles and their bindings
- CustomResourceDefinitions and custom resources
- Persistent volumes and storage classes
- Workload manifests applied through ArkCD reconciliation
- Scaling and rollout operations within granted scope
- Approved remediation such as resource limit changes
Connecting Kubernetes
- 1Create a ServiceAccount
Apply the supplied read-only ClusterRole and binding in the cluster.
- 2Register the cluster
Provide the API endpoint and credential, or use a cloud provider identity.
- 3Verify
DevOpsArk confirms connectivity and begins building the inventory immediately.
- 4Add write scope selectively
Grant namespace-scoped write permissions only where you want DevOpsArk to act.
Which modules use Kubernetes
Kubernetes
Multi-cluster Kubernetes management
Agentless Kubernetes
Manage clusters without installing anything
ArkCD
Continuous delivery and progressive rollout
Monitoring
Infrastructure and application monitoring
Security
Posture, policy and continuous verification
Cost Management
Cloud and Kubernetes cost attribution
Kubernetes integration: frequently asked questions
No. DevOpsArk connects through the Kubernetes API with scoped credentials. Everything needed for inventory, monitoring, cost and security posture is available through that API. An optional in-cluster component exists only for higher-frequency metric sampling.
Amazon EKS, Azure AKS, Google GKE, Red Hat OpenShift, Rancher-managed clusters and self-managed upstream Kubernetes, on cloud or on-premises.
A read-only ClusterRole covering the resource types you want visible. Write access is granted separately and can be scoped per namespace.
Through an outbound-only relay: the cluster initiates the connection, so no ingress rule or public endpoint is required.
A few minutes, the time to create a ServiceAccount, apply a binding and register the endpoint. Inventory appears straight away.
Integrations that commonly go with this one
AWS
EKS, EC2, ECR, IAM and billing in one plane
Azure
AKS, virtual machines, ACR and cost
Google Cloud
GKE, Compute Engine, Artifact Registry and billing
Argo CD
Read existing Argo applications, or take over reconciliation
Prometheus
Read existing metrics, or replace the collector
Docker
Image build, scan and registry publishing
Connect Kubernetes and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.