Catch the risky change in the pull request, not in production.
Runtimez checks every change against what is actually running, then tracks each rollout and the diff behind it. When something breaks, you can see what changed right before it.
one helm install · get, list, watch only · first findings in minutes
PR-time deployment gate
The verdict lands on the pull request before merge.
60+ static manifest rules
Covers RBAC, pod security, probes, HPA, rollout strategy, resources, Jobs and CronJobs, networking, scheduling, hygiene, supply chain and deprecated APIs.
Live-diff rules
Compares the PR with what is actually running and flags: probe removed, PDB weakened, replicas cut, limits reduced, anti-affinity dropped, ingress TLS removed, service exposed, PVC shrunk.
GitOps-aware drift
Recognizes fields managed by Flux or Argo CD instead of flagging every reconcile.
Config blast radius
Shows whether a changed ConfigMap feeds one workload or forty.
Predictions that grade themselves
Records each predicted outcome and publishes its own accuracy, including the false-positive rate.
Upgrade rules at PR time
The Upgrade Readiness rules run against the rendered bundle, so a removed API never reaches the cluster.
Change intelligence
Who changed what, right before it broke.
Deployment history and outcomes
Every rollout is classified as success, failure or rollback.
Workload diff engine
A field-level diff between any two points in time.
Change forensics timeline
An append-only history of every workload change, built from snapshot diffs.
Cluster diff sessions
A live A/B diff over a time span, with evidence bundles and anomaly evaluation, for comparing a canary or release.
Version change summary
What changed between two cluster versions.
How it compares
They enforce the rules you wrote. Runtimez ships the 200+ rules you didn't know to write, and checks changes against what is actually running.
One agent, the rest of the platform
Every product runs off the same read-only sweep and feeds the same ranked queue.
See it on your own cluster in under an hour.
Free for your first cluster. Read-only by default. Uninstall is one helm command.
