An API of your own
Its own API server, CA and RBAC. Install CRDs, create resources, use kubectl as usual.
ctrlplane gives you a Kubernetes control plane of your own: an API server, its storage and
its certificate authority, hosted for you. You install CustomResourceDefinitions, create custom
resources with kubectl or the site, and ctrlplane runs your controllers (operators) next to
it. There are no nodes to run.
It’s for operators that manage things outside Kubernetes, such as virtual machines, DNS
records, databases or SaaS accounts, where you want the Kubernetes API and its tooling
(kubectl, RBAC, GitOps, kubectl wait) without running a cluster to host it.
An API of your own
Its own API server, CA and RBAC. Install CRDs, create resources, use kubectl as usual.
Controllers, run for you
Give ctrlplane an image; it runs it against your API with scoped credentials, logs and metrics included.
Into your network
A tunnel you start lets your controllers reach machines in your own network, without opening anything inbound.
Isolated by design
Every control plane has its own CA and keys, and every controller runs sandboxed with access to its own control plane only.
ctrlplane serves the Kubernetes API, not a cluster to run workloads on. Your control plane
has no Pods, Deployments or Nodes: you can’t kubectl run anything on it. Your controllers are
the only workloads, and ctrlplane runs them for you.