Know what your next Kubernetes upgrade breaks — before you book the window.
Pick a target version and get every resource that breaks, ranked by blast radius. Each of the 557 upgrade rules quotes the vendor's release note word for word and ships a read-only kubectl command, so you can check every verdict yourself.
one helm install · get, list, watch only · first findings in minutes
What the next version breaks
The rule corpus that replaces a week of release-note reading.
Upgrade Breakage Radar
Pick a target version and get every resource that breaks, ranked by blast radius.
Rules you can audit line by line
72 hand-authored Kubernetes rules for 1.30 → 1.37, with 569 exclusions. Each rule quotes the vendor release note and ships a read-only kubectl verify command. No LLM guesswork.
Add-ons break before Kubernetes does
480 release-note rules for Traefik, Istio, CoreDNS, Argo CD, Karpenter, cert-manager and kube-proxy. Each catalog turns on automatically when the add-on is detected.
Config breakers scanners can't see
Reads kubelet /configz and control-plane flags to catch settings the target release removes. Manifest scanners like pluto and kubent can't see these.
CRD and operator deprecations
Counts the custom resources that will be orphaned, not just which CRD version is old.
Webhook and node-runtime skew
Admission-webhook and node-runtime checks, plus 5 version-skew rules. These are the two things that stall a control-plane roll halfway through.
Plan it, prove it, schedule it
Turn an engineering task into a budget conversation.
Forced-upgrade deadline in dollars
An end-of-support countdown, the extended-support cost of waiting, and the effort to upgrade, side by side.
Fleet breakage ranking
Which cluster to upgrade first, ranked by risk and deadline.
Gate ledger
Pass or fail per rule, with the objects named and the command to re-check it yourself.
Coverage self-assessment
Tells you what it could not see, so you can trust a green verdict.
Check manifests before they exist
The same rules run against a rendered bundle at PR time.
kube-upgrade-check (open source)
The same rule catalogs, byte for byte, as an offline CLI for CI. Try the CLI →
How it compares
They read manifests. Runtimez also reads CRDs, webhooks, kubelet flags, node runtimes and nine add-ons, and keeps watching after the scan.
One agent, the rest of the platform
Every product runs off the same read-only sweep and feeds the same ranked queue.
See it on your own cluster in under an hour.
Free for your first cluster. Read-only by default. Uninstall is one helm command.
