Runtimezruntimez
runtimez / product / safe-deployments
product · safe deployments

Catch the risky change in the pull request, not in production.

Runtimez checks every change against what is actually running, then tracks each rollout and the diff behind it. When something breaks, you can see what changed right before it.

one helm install · get, list, watch only · first findings in minutes

60+PR-time manifest rules
8live-diff regressions checked against running state
0mutating verbs: read-only, always

PR-time deployment gate

The verdict lands on the pull request before merge.

60+ static manifest rules

Covers RBAC, pod security, probes, HPA, rollout strategy, resources, Jobs and CronJobs, networking, scheduling, hygiene, supply chain and deprecated APIs.

60+ rules

Live-diff rules

Compares the PR with what is actually running and flags: probe removed, PDB weakened, replicas cut, limits reduced, anti-affinity dropped, ingress TLS removed, service exposed, PVC shrunk.

vs. running state

GitOps-aware drift

Recognizes fields managed by Flux or Argo CD instead of flagging every reconcile.

FluxArgo CD

Config blast radius

Shows whether a changed ConfigMap feeds one workload or forty.

ConfigMaps

Predictions that grade themselves

Records each predicted outcome and publishes its own accuracy, including the false-positive rate.

published accuracy

Upgrade rules at PR time

The Upgrade Readiness rules run against the rendered bundle, so a removed API never reaches the cluster.

deprecated APIs
Runtimez Deployment Reliability: deploys, change-failure rate, fragile workloads and gate precision over 30 days
Runtimez Deployment Reliability: deploys, change-failure rate, fragile workloads and gate precision over 30 days

Change intelligence

Who changed what, right before it broke.

Deployment history and outcomes

Every rollout is classified as success, failure or rollback.

rollout verdicts

Workload diff engine

A field-level diff between any two points in time.

field-level

Change forensics timeline

An append-only history of every workload change, built from snapshot diffs.

append-only

Cluster diff sessions

A live A/B diff over a time span, with evidence bundles and anomaly evaluation, for comparing a canary or release.

canaryA/B

Version change summary

What changed between two cluster versions.

cluster versions

How it compares

vs Kyverno / OPA

They enforce the rules you wrote. Runtimez ships the 200+ rules you didn't know to write, and checks changes against what is actually running.

See it on your own cluster in under an hour.

Free for your first cluster. Read-only by default. Uninstall is one helm command.