Runtimez helps platform and SRE teams answer the questions that matter before every Kubernetes change:
Can we deploy this? · What changed? · What is the risk? · What will it cost? · Is it secure? · Who owns it? · Can we roll back?
A read-only Kubernetes deployment intelligence platform that finds upgrade blockers, CVEs, readiness gaps, cost waste, and risky workload changes before they turn into incidents. First production-risk report in under an hour.
A look at the dashboards, upgrade radar, and reports your team lives in — from fleet-wide risk down to a single workload.
Pick a target version and see exactly what breaks — before you touch the cluster. Plus a countdown to your forced-upgrade deadline and the real cost of putting it off.
Upgrade riskSpend mapped to the teams responsible — by namespace, workload, environment, and cluster. Surface unowned cost, over-provisioned requests, and idle workloads before the bill arrives.
The differentiator. Security findings and upgrade blockers aren't siloed — they're joined by workload. "This critical CVE is on the same deployment blocking your 1.31 upgrade." Fix it first, retire two risks with one change.
Security ∩ UpgradeCatch risk in review, not at 2am. On every pull request, Runtimez diffs the proposed workload against live state and posts a verdict — risk score, cost delta, readiness, and the cross-axis "fix first" list — straight onto the PR.
GitHub · SlackEvery workload scored on the things that bite in prod — probes, limits, replicas, rollback. And its requests sized against real usage, flagged good, low, or high, so nothing ships starved or bloated.
Right-sized & readyImage CVE scanning and misconfig posture, in-cluster — images and pull secrets never leave. Per-cluster compliance scorecards against CIS and NSA benchmarks, scored and rolled up across your whole fleet.
CVE · Misconfig · CIS · NSARead owner, team, and service labels to build a map of who runs what — and surface the workloads nobody owns. Recommend the missing labels so accountability gaps and unowned cost get closed.
Owner · Team · ServiceWorkload health, restart counts, rollout status, and CPU/memory from your existing telemetry — no new collector to babysit. Slack alerts when a workload degrades, so you catch the crash loop at 2pm, not 2am.
Prometheus · OpenTelemetry · SlackEverything above rolls into a single fix-first list, ranked by overlapping risk — so one change retires the most exposure.
See how it works →One read-only Helm install. Least-privilege access, no kubeconfig to hand over, nothing exposed. It connects and starts reporting on its own.
helm repo add runtimez \ https://charts.runtimez.io helm install runtimez-agent \ runtimez/runtimez-agent \ --set token=rkc_•••• ✓ agent registered
The agent sweeps the cluster read-only — workloads, services, ingress, nodes, CRDs, and secret names (never values) — and builds a live inventory. Spins up ephemeral Trivy jobs in-cluster to scan images and config.
✓ 304 objects · 15 ns ✓ images scanned in-cluster ✓ 75 CRIT · 863 HIGH CVEs
Findings normalize into two risk axes — upgrade and security — scored per workload and rolled up per cluster and fleet. Then Runtimez joins them by workload to surface what carries both risks.
upgrade → 1.31 HIGH security CRITICAL → 3 workloads block both
Work the fix-first list, gate risky changes on the PR, and get a Slack ping the moment a workload degrades. Prioritize by overlapping risk so one change retires the most exposure.
PR check ✓ posted slack alert crash-loop fix-first 3 → 0
Paid tiers are usage-based and in early access — pricing finalizes at launch. Pay-as-you-go meters: extra deployment checks · active services · connected clusters · observability ingestion · advanced AI analysis.
EKS, GKE, and AKS retire old versions on a clock — and bill you extended-support fees for staying. Runtimez tells you exactly what breaks on the next version, ranks your whole fleet by nearest deadline, and shows the dollar cost of waiting.
Connect one cluster and we'll walk you through your first upgrade-readiness and security posture report — what's deprecated, what's vulnerable, and the workloads that carry both. Read-only, nothing leaves your cluster.
Prefer done-with-you? See the $2,500 Upgrade Readiness Audit →Read-only. One Helm command. Nothing leaves your cluster.
Tell us where to reach you and we'll send the read-only Helm command to get your first risk report — under an hour, nothing leaves your cluster.
Read-only by default. We'll only use your email to help you connect. Or email hello@runtimez.io.
Thanks — we'll be in touch shortly to get your cluster connected and your first risk report generated.