Skip to content

Self-hosting

ctrlplane.run is ctrlplane run as a service. The same software installs into your own cluster with one Helm chart, if you’d rather host control planes yourself.

  • Kubernetes 1.30 or newer, used only for ctrlplane. The platform manages namespaces, Secrets and RBAC cluster-wide.
  • A Gateway API implementation with TLSRoute, for example Envoy Gateway. Tenant API servers and tunnels are routed by hostname without decrypting their TLS.
  • DNS for app.<domain>, auth.<domain>, *.api.<domain> and *.tunnel.<domain>, pointing at the Gateway.
  • A certificate for app.<domain> and auth.<domain>, or cert-manager with a DNS-01 issuer.
  • NetworkPolicies that are enforced. Tenant isolation depends on them; most CNIs enforce them, some (and some k3s setups) don’t.
  • For production, a sandboxed container runtime such as gVisor, since controllers run their owners’ images.
Terminal window
helm install ctrlplane oci://ghcr.io/alperencelik/ctrlplane/charts/ctrlplane --version <x.y.z> \
-n platform-system --create-namespace \
--set domain=<domain> --set 'platform.admins={github:<you>}' -f my-values.yaml

my-values.yaml adds your identity providers (GitHub, or any Dex connector), backups (any S3 bucket) and, for production, high availability. Behind a TCP relay or load balancer that sends PROXY protocol headers, set gateway.proxyProtocol=true.

The chart’s values.yaml and the project README document every setting.