Agentless Kubernetes: nothing to install in the cluster
Connect through the Kubernetes API with scoped credentials. No DaemonSet consuming node memory, no sidecar to patch, no privileged component to justify to a security review.
What is Agentless Kubernetes?
Agentless Kubernetes management is an approach in which the management platform connects to a cluster through its Kubernetes API using scoped credentials, rather than installing an in-cluster agent, DaemonSet or sidecar.
What Agentless Kubernetes is for
The conditions this module removes. If none of these are familiar, you probably do not need it yet.
- Every management tool wants a DaemonSet, and each one takes memory on every node in the fleet.
- In-cluster agents need their own patching cycle, and an unpatched agent is an unpatched privileged workload.
- Security review of a new tool stalls for weeks because it requires cluster-admin and a privileged container.
- Regulated and air-gapped clusters cannot accept an agent that calls out to a vendor.
- Proving value takes a month because the pilot cannot start until the agent is approved.
DevOpsArk authenticates to the Kubernetes API using a ServiceAccount token, a cloud provider identity such as an IAM role, or a kubeconfig you supply. Everything the inventory, monitoring, cost and security-posture views need (resources, events, metrics from the metrics API, node conditions, RBAC bindings) is available through that API. Read-only access is enough for the entire observability and posture surface; write scope is granted separately, per cluster and per namespace, only for the operations you want DevOpsArk to perform. For clusters with no inbound connectivity, an outbound-only relay can be used so the cluster initiates the connection and no ingress rule is required.
What Agentless Kubernetes does
The 6 capabilities that make up Agentless Kubernetes.
API-only connection
Inventory, events, metrics, RBAC and node state are read through the Kubernetes API. Nothing is deployed into the cluster.
Scoped, revocable credentials
Start read-only. Grant write scope per cluster and per namespace when you want DevOpsArk to act, and revoke it in one place.
No node overhead
No DaemonSet means no per-node memory and CPU cost, which matters most on the large fleets where agents are most expensive.
Smaller security review
No privileged in-cluster workload to assess, no agent supply chain to vet, no additional patching obligation.
Outbound-only option
For clusters that accept no inbound connections, a relay lets the cluster initiate the connection instead.
Minutes to first value
A cluster is connected and inventoried in the time it takes to create a ServiceAccount.
How Agentless Kubernetes fits together
Outcomes
- A cluster can be onboarded during the security conversation rather than after it.
- Node resources go to workloads instead of to management agents.
- There is one fewer privileged component in the cluster to patch and defend.
- Regulated and air-gapped environments can be managed on the same terms as everything else.
- Access is revocable centrally, so offboarding is a single action.
Using Agentless Kubernetes, step by step
The path from connecting a source to getting value, in the order it happens.
- 1Create a ServiceAccount
Apply a read-only ClusterRole and binding, or supply a cloud IAM identity.
- 2Register the cluster
Provide the API endpoint and credential, or connect through the outbound relay.
- 3Inventory and observe
Resources, events, metrics and posture are read continuously through the API.
- 4Grant write scope if wanted
Add scoped permissions per namespace only for the actions you want DevOpsArk to perform.
Where teams apply Agentless Kubernetes
Approve a management platform quickly
Evaluate a tool that reads through the Kubernetes API rather than one that requires a privileged DaemonSet.
Onboard a large fleet
Connect dozens of clusters without a rollout project for the agent itself.
Reclaim node capacity
Remove per-node management overhead from a fleet where it adds up to real capacity.
Manage restricted clusters
Use outbound-only connectivity for clusters that cannot accept inbound traffic.
What Agentless Kubernetes works with
Named integrations link to their own page. The rest are supported runtimes and formats.
Agentless Kubernetes: frequently asked questions
The 8 questions teams ask most often before adopting Agentless Kubernetes.
Agentless Kubernetes management means the platform connects to a cluster through its Kubernetes API using scoped credentials, instead of installing an agent, DaemonSet or sidecar inside the cluster. The cluster runs no additional workload on the platform behalf.
Cluster and node state, namespaces, workloads and their configuration, pod events, container logs, RBAC bindings, and resource metrics from the Kubernetes metrics API. That covers inventory, monitoring, cost attribution and security posture.
Higher-frequency metric sampling and some deep process-level signals. An optional in-cluster component is available for teams that want those, but it is opt-in rather than a prerequisite.
It reduces the attack surface rather than increasing it: there is no privileged workload inside the cluster and no additional supply chain to vet. Access is a scoped, revocable Kubernetes credential.
A read-only ClusterRole covering the resource types you want visible. Write permissions are separate, granted per cluster and per namespace, and only needed for deployment or remediation.
Yes. Where the cluster accepts no inbound connections, an outbound-only relay lets the cluster initiate the connection, so no ingress rule or public API endpoint is required.
Typically a few minutes, the time to create a ServiceAccount, apply a role binding and register the endpoint. Inventory appears immediately after.
No. Actions are performed through the Kubernetes API using the write scope you grant. The difference is that the permission is explicit and revocable rather than embedded in a privileged in-cluster component.
See Agentless Kubernetes against your own environment
A 30-minute walkthrough with a platform engineer, not a sales deck. Bring a cluster and a problem.