Deploy

Agentless Kubernetes: nothing to install in the cluster

Connect through the Kubernetes API with scoped credentials. No DaemonSet consuming node memory, no sidecar to patch, no privileged component to justify to a security review.

Short answer

What is Agentless Kubernetes?

Agentless Kubernetes management is an approach in which the management platform connects to a cluster through its Kubernetes API using scoped credentials, rather than installing an in-cluster agent, DaemonSet or sidecar.

Why it matters

What Agentless Kubernetes is for

The conditions this module removes. If none of these are familiar, you probably do not need it yet.

  • Every management tool wants a DaemonSet, and each one takes memory on every node in the fleet.
  • In-cluster agents need their own patching cycle, and an unpatched agent is an unpatched privileged workload.
  • Security review of a new tool stalls for weeks because it requires cluster-admin and a privileged container.
  • Regulated and air-gapped clusters cannot accept an agent that calls out to a vendor.
  • Proving value takes a month because the pilot cannot start until the agent is approved.
How it works

DevOpsArk authenticates to the Kubernetes API using a ServiceAccount token, a cloud provider identity such as an IAM role, or a kubeconfig you supply. Everything the inventory, monitoring, cost and security-posture views need (resources, events, metrics from the metrics API, node conditions, RBAC bindings) is available through that API. Read-only access is enough for the entire observability and posture surface; write scope is granted separately, per cluster and per namespace, only for the operations you want DevOpsArk to perform. For clusters with no inbound connectivity, an outbound-only relay can be used so the cluster initiates the connection and no ingress rule is required.

Capabilities

What Agentless Kubernetes does

The 6 capabilities that make up Agentless Kubernetes.

API-only connection

Inventory, events, metrics, RBAC and node state are read through the Kubernetes API. Nothing is deployed into the cluster.

Scoped, revocable credentials

Start read-only. Grant write scope per cluster and per namespace when you want DevOpsArk to act, and revoke it in one place.

No node overhead

No DaemonSet means no per-node memory and CPU cost, which matters most on the large fleets where agents are most expensive.

Smaller security review

No privileged in-cluster workload to assess, no agent supply chain to vet, no additional patching obligation.

Outbound-only option

For clusters that accept no inbound connections, a relay lets the cluster initiate the connection instead.

Minutes to first value

A cluster is connected and inventoried in the time it takes to create a ServiceAccount.

Architecture

How Agentless Kubernetes fits together

Cluster
Kubernetes API serverServiceAccountmetrics API
Connection
Direct APICloud IAM identityOutbound relay
DevOpsArk
InventoryMonitoringSecurity postureCost attribution
Optional write scope
ArkCD deliveryApproved remediation
Agentless Kubernetes architecture within the DevOpsArk control plane.

Outcomes

  • A cluster can be onboarded during the security conversation rather than after it.
  • Node resources go to workloads instead of to management agents.
  • There is one fewer privileged component in the cluster to patch and defend.
  • Regulated and air-gapped environments can be managed on the same terms as everything else.
  • Access is revocable centrally, so offboarding is a single action.
How to use it

Using Agentless Kubernetes, step by step

The path from connecting a source to getting value, in the order it happens.

  1. 1
    Create a ServiceAccount

    Apply a read-only ClusterRole and binding, or supply a cloud IAM identity.

  2. 2
    Register the cluster

    Provide the API endpoint and credential, or connect through the outbound relay.

  3. 3
    Inventory and observe

    Resources, events, metrics and posture are read continuously through the API.

  4. 4
    Grant write scope if wanted

    Add scoped permissions per namespace only for the actions you want DevOpsArk to perform.

Use cases

Where teams apply Agentless Kubernetes

Security

Approve a management platform quickly

Evaluate a tool that reads through the Kubernetes API rather than one that requires a privileged DaemonSet.

Platform engineering

Onboard a large fleet

Connect dozens of clusters without a rollout project for the agent itself.

SRE

Reclaim node capacity

Remove per-node management overhead from a fleet where it adds up to real capacity.

Regulated industries

Manage restricted clusters

Use outbound-only connectivity for clusters that cannot accept inbound traffic.

Supported technologies

What Agentless Kubernetes works with

Named integrations link to their own page. The rest are supported runtimes and formats.

kubernetesawsazuregcpOpenShiftRanchermetrics-server
Do not see your stack? DevOpsArk works over standard interfaces: the Kubernetes API, OCI images, OpenTelemetry and cloud provider APIs, so most environments are supported without a bespoke connector. Ask us about yours.
FAQ

Agentless Kubernetes: frequently asked questions

The 8 questions teams ask most often before adopting Agentless Kubernetes.

See Agentless Kubernetes against your own environment

A 30-minute walkthrough with a platform engineer, not a sales deck. Bring a cluster and a problem.