Know exactly what breaks on your next Kubernetes version — before the forced-upgrade deadline hits. In five business days we connect a read-only agent, find every upgrade blocker and the CVEs that ride along with them, and hand you a prioritized, effort-estimated fix plan. Flat $2,500. Nothing leaves your cluster.
## Upgrade Readiness Audit — EKS 1.28 → 1.31 Scope ✓ 1 cluster · up to 25 workloads ✓ every removed / deprecated API + CRD ✓ image CVEs on the blocking workloads You get ✓ prioritized "fix first" list ✓ effort-estimated remediation plan ✓ 60-min live readout with your team Timeline 5 business days Fee $2,500 flat → read-only · nothing leaves your cluster
$2,500 flat · 5 business days · read-only. Pick a 30-minute slot and we'll confirm scope and timing.
Prefer email? hello@runtimez.io
WHAT'S INCLUDED
apiVersionsSecret values, pull secrets, and images never leave your cluster — we work from metadata and findings only.
HOW THE AUDIT WORKS
A 30-minute kickoff to confirm your cluster, target version, and deadline. Flat $2,500 — no scoping games, no "it depends." Then we schedule the read-only install.
One read-only Helm install, least-privilege — no kubeconfig handover. Ephemeral in-cluster jobs scan images and config; secret values and images never leave.
We find every upgrade blocker, scan for CVEs, and join them by workload — so you see which fixes retire an upgrade blocker and a critical vulnerability at once.
A 60-minute live readout with your team, plus a prioritized, effort-estimated remediation plan you keep — with a validated rollback path for the version bump.
A representative audit on a cluster stuck on 1.28: removed HPA & Ingress APIs, a deprecated CRD an operator still serves, batch/v1beta1 CronJobs across four namespaces, single-replica workloads with no PodDisruptionBudget — and three of the blocking workloads also running images with critical CVEs. One change each retires both risks. (Illustrative — numbers vary by cluster.)
FAQ
Yes — it's read-only and least-privilege, with no kubeconfig handover. Image and config scanning runs in ephemeral in-cluster jobs. Secret values, pull secrets, and images never leave your cluster; we work from metadata and findings only.
Five business days from kickoff to readout, for a flat $2,500. Scope is one cluster with up to 25 workloads.
A prioritized, effort-estimated fix plan that correlates upgrade blockers with the CVEs on the same workloads, a validated rollback path for the version bump, and a 60-minute live readout with your team. The report and plan are yours to keep.
The audit finds and prioritizes the work. If you want us to clear the blockers and execute the upgrade with your team, we offer a done-with-you Upgrade Sprint as a follow-on — but the audit stands alone and is yours to run internally.
Beat the deadline
Flat $2,500, five business days, read-only. Book the Upgrade Readiness Audit and walk into your version bump with a prioritized fix plan instead of a prayer.