Fixed-fee audit · Delivered in 5 business days

Kubernetes Upgrade
Readiness Audit.

Know exactly what breaks on your next Kubernetes version — before the forced-upgrade deadline hits. In five business days we connect a read-only agent, find every upgrade blocker and the CVEs that ride along with them, and hand you a prioritized, effort-estimated fix plan. Flat $2,500. Nothing leaves your cluster.

What's included
✓ Flat $2,500 — no "from" ✓ 5 business days ✓ Read-only agent ✓ Nothing leaves your cluster ✓ 60-min live readout ✓ Fix plan is yours to keep
$2,500 Flat fee, fixed scope
5 days Kickoff to readout
1 cluster Up to 25 workloads
audit — upgrade-readiness.md
## Upgrade Readiness Audit — EKS 1.28 → 1.31

Scope
   1 cluster · up to 25 workloads
   every removed / deprecated API + CRD
   image CVEs on the blocking workloads

You get
   prioritized "fix first" list
   effort-estimated remediation plan
   60-min live readout with your team

Timeline  5 business days   Fee  $2,500 flat
→ read-only · nothing leaves your cluster

Book the audit

$2,500 flat · 5 business days · read-only. Pick a 30-minute slot and we'll confirm scope and timing.

Prefer email? hello@runtimez.io

One fixed-fee audit —
everything you need to upgrade safely.

Upgrade blocker report

Every version-breaking change, by kind
  • Removed & deprecated APIs on your target version
  • Deprecated CRDs your operators still serve
  • Manifests pinned to dead apiVersions
  • Aggregated by kind — every namespace affected, not a sample
  • Runtime signals confirm which deprecated APIs are actually called

Fix plan + live readout

Sequenced, effort-estimated, yours to keep
  • A prioritized "fix first" list, ranked by blast radius
  • Effort estimate and blast-radius note per change
  • Validated rollback path for the version bump
  • 60-minute live readout with your team
  • The full report & plan delivered as a doc you own
$2,500 flat · 5 business days · 1 cluster, up to 25 workloads · read-only

Secret values, pull secrets, and images never leave your cluster — we work from metadata and findings only.

From kickoff to fix plan
in five business days.

1

Book & kick off

A 30-minute kickoff to confirm your cluster, target version, and deadline. Flat $2,500 — no scoping games, no "it depends." Then we schedule the read-only install.

cluster 1 × EKS 1.28
target 1.31 by Q3
booked · read-only
2

Connect the agent

One read-only Helm install, least-privilege — no kubeconfig handover. Ephemeral in-cluster jobs scan images and config; secret values and images never leave.

agent connected
304 objects · 15 ns
images scanned in-cluster
3

Analyze & correlate

We find every upgrade blocker, scan for CVEs, and join them by workload — so you see which fixes retire an upgrade blocker and a critical vulnerability at once.

6 blockers · 3 w/ CVEs
readiness + cost flags
fix-first list ready
4

Readout & fix plan

A 60-minute live readout with your team, plus a prioritized, effort-estimated remediation plan you keep — with a validated rollback path for the version bump.

readout ✓ 60 min
fix-first ✓ 3 → 0
plan ✓ handed over
What we typically find

Six blockers. Three also carry critical CVEs.

A representative audit on a cluster stuck on 1.28: removed HPA & Ingress APIs, a deprecated CRD an operator still serves, batch/v1beta1 CronJobs across four namespaces, single-replica workloads with no PodDisruptionBudget — and three of the blocking workloads also running images with critical CVEs. One change each retires both risks. (Illustrative — numbers vary by cluster.)

✓ Removed / deprecated APIs & CRDs ✓ CVEs on the blocking workloads ✓ CronJobs that stop scheduling ✓ Single-replica, no-PDB workloads ✓ :latest tags & over-sized limits ✓ Unowned, public-facing services
See a full sample teardown →

Questions, answered.

Is the audit read-only? Does anything leave my cluster?

Yes — it's read-only and least-privilege, with no kubeconfig handover. Image and config scanning runs in ephemeral in-cluster jobs. Secret values, pull secrets, and images never leave your cluster; we work from metadata and findings only.

How long does the audit take and what does it cost?

Five business days from kickoff to readout, for a flat $2,500. Scope is one cluster with up to 25 workloads.

What do I get at the end?

A prioritized, effort-estimated fix plan that correlates upgrade blockers with the CVEs on the same workloads, a validated rollback path for the version bump, and a 60-minute live readout with your team. The report and plan are yours to keep.

Do you fix the issues too?

The audit finds and prioritizes the work. If you want us to clear the blockers and execute the upgrade with your team, we offer a done-with-you Upgrade Sprint as a follow-on — but the audit stands alone and is yours to run internally.

Beat the deadline

Know what breaks — before it breaks production.

Flat $2,500, five business days, read-only. Book the Upgrade Readiness Audit and walk into your version bump with a prioritized fix plan instead of a prayer.