Read-only · Connect in one Helm command

Know what breaks before
it breaks production.

Runtimez helps platform and SRE teams answer the questions that matter before every Kubernetes change:

Can we deploy this? · What changed? · What is the risk? · What will it cost? · Is it secure? · Who owns it? · Can we roll back?

A read-only Kubernetes deployment intelligence platform that finds upgrade blockers, CVEs, readiness gaps, cost waste, and risky workload changes before they turn into incidents. First production-risk report in under an hour.

See how it works
✓ Read-only by default ✓ Nothing leaves your cluster ✓ Upgrade breakage radar ✓ Image CVE + misconfig scan ✓ CIS · NSA compliance
Fleet risk · prod-us-east-1
304 objects15 namespaceslive
Critical risks
7
Upgrade blockers
3
Monthly waste
$2.4k
CIS score
82%
Fix first — ranked by blast radius
!
checkout-api
Critical CVE + removed API — one fix clears both
2 risks
ingress-nginx
Deprecated API blocks upgrade to 1.31
blocker
batch-worker
Over-provisioned — 4× memory vs p95 usage
$640/mo
Upgrade readiness · 1.31
75%ready
Clear workloads41
Need attention9
Hard blockers3
Runs on any conformant cluster Amazon EKS· Google GKE· Azure AKS· Rancher· k3s
The Platform

One read-only agent. Every answer you need before and after deploy.

Upgrade Breakage Radar

Pick a target version and see exactly what breaks — before you touch the cluster. Plus a countdown to your forced-upgrade deadline and the real cost of putting it off.

Upgrade risk

Cost Intelligence

Spend mapped to the teams responsible — by namespace, workload, environment, and cluster. Surface unowned cost, over-provisioned requests, and idle workloads before the bill arrives.

payments ns$310/mo
over-provisioned−$120/mo
unowned$48/mo
Attributed94%
By team & namespace

Cross-Axis Correlation

The differentiator. Security findings and upgrade blockers aren't siloed — they're joined by workload. "This critical CVE is on the same deployment blocking your 1.31 upgrade." Fix it first, retire two risks with one change.

Security ∩ Upgrade

PR-Time Analysis

Catch risk in review, not at 2am. On every pull request, Runtimez diffs the proposed workload against live state and posts a verdict — risk score, cost delta, readiness, and the cross-axis "fix first" list — straight onto the PR.

GitHub · Slack

Production Readiness

Every workload scored on the things that bite in prod — probes, limits, replicas, rollback. And its requests sized against real usage, flagged good, low, or high, so nothing ships starved or bloated.

Right-sized & ready

Security & Vulnerability

Image CVE scanning and misconfig posture, in-cluster — images and pull secrets never leave. Per-cluster compliance scorecards against CIS and NSA benchmarks, scored and rolled up across your whole fleet.

CVE · Misconfig · CIS · NSA

Ownership Mapping

Read owner, team, and service labels to build a map of who runs what — and surface the workloads nobody owns. Recommend the missing labels so accountability gaps and unowned cost get closed.

Owner · Team · Service

Day-One Observability

Workload health, restart counts, rollout status, and CPU/memory from your existing telemetry — no new collector to babysit. Slack alerts when a workload degrades, so you catch the crash loop at 2pm, not 2am.

Prometheus · OpenTelemetry · Slack

Two risk axes,
one prioritized view.

Everything above rolls into a single fix-first list, ranked by overlapping risk — so one change retires the most exposure.

See how it works →
The Process

From one Helm command
to a prioritized risk view.

1

Connect Your Cluster

One read-only Helm install. Least-privilege access, no kubeconfig to hand over, nothing exposed. It connects and starts reporting on its own.

helm repo add runtimez \
  https://charts.runtimez.io
helm install runtimez-agent \
  runtimez/runtimez-agent \
  --set token=rkc_••••
 agent registered
2

Discover & Inventory

The agent sweeps the cluster read-only — workloads, services, ingress, nodes, CRDs, and secret names (never values) — and builds a live inventory. Spins up ephemeral Trivy jobs in-cluster to scan images and config.

 304 objects · 15 ns
 images scanned in-cluster
 75 CRIT · 863 HIGH CVEs
3

Score & Correlate

Findings normalize into two risk axes — upgrade and security — scored per workload and rolled up per cluster and fleet. Then Runtimez joins them by workload to surface what carries both risks.

upgrade → 1.31 HIGH
security CRITICAL
 3 workloads block both
4

Act on What Matters

Work the fix-first list, gate risky changes on the PR, and get a Slack ping the moment a workload degrades. Prioritize by overlapping risk so one change retires the most exposure.

PR check ✓ posted
slack alert crash-loop
fix-first 3 → 0
Pricing

Start free. Scale as you connect more.

Free
$0
For a single cluster
✓ 1 connected cluster✓ 5 services✓ 100 deployment checks / mo✓ Basic readiness + ownership✓ Cluster dashboard
Starter
3 clusters
For a growing team
✓ 25 services✓ 1,000 deployment checks / mo✓ Production readiness checks✓ Ownership mapping + basic cost✓ Slack & GitHub integration
MOST POPULAR
Growth
10 clusters
For multiple teams & fleets
✓ 100 services✓ 5,000 deployment checks / mo✓ Advanced risk + cost intelligence✓ Policy, security & compliance checks✓ Day-one observability bootstrap

Paid tiers are usage-based and in early access — pricing finalizes at launch. Pay-as-you-go meters: extra deployment checks · active services · connected clusters · observability ingestion · advanced AI analysis.

⚠ Beat the deadline

Facing a forced Kubernetes upgrade?

EKS, GKE, and AKS retire old versions on a clock — and bill you extended-support fees for staying. Runtimez tells you exactly what breaks on the next version, ranks your whole fleet by nearest deadline, and shows the dollar cost of waiting.

✓ Deprecated & removed API detection ✓ CRD & runtime usage coverage ✓ Forced-upgrade countdown ✓ Extended-support $ exposure ✓ Fleet breakage ranking ✓ EKS · GKE · AKS · self-managed
Free for your first cluster

Get a deployment risk report in an afternoon.

Connect one cluster and we'll walk you through your first upgrade-readiness and security posture report — what's deprecated, what's vulnerable, and the workloads that carry both. Read-only, nothing leaves your cluster.

Prefer done-with-you? See the $2,500 Upgrade Readiness Audit →
See pricing →

See your first risk report
in under an hour.

Read-only. One Helm command. Nothing leaves your cluster.