Self-hosting
ctrlplane.run is ctrlplane run as a service. The same software installs into your own cluster with one Helm chart, if you’d rather host control planes yourself.
What you need
Section titled “What you need”- Kubernetes 1.30 or newer, used only for ctrlplane. The platform manages namespaces, Secrets and RBAC cluster-wide.
- A Gateway API implementation with
TLSRoute, for example Envoy Gateway. Tenant API servers and tunnels are routed by hostname without decrypting their TLS. - DNS for
app.<domain>,auth.<domain>,*.api.<domain>and*.tunnel.<domain>, pointing at the Gateway. - A certificate for
app.<domain>andauth.<domain>, or cert-manager with a DNS-01 issuer. - NetworkPolicies that are enforced. Tenant isolation depends on them; most CNIs enforce them, some (and some k3s setups) don’t.
- For production, a sandboxed container runtime such as gVisor, since controllers run their owners’ images.
Install
Section titled “Install”helm install ctrlplane oci://ghcr.io/alperencelik/ctrlplane/charts/ctrlplane --version <x.y.z> \ -n platform-system --create-namespace \ --set domain=<domain> --set 'platform.admins={github:<you>}' -f my-values.yamlmy-values.yaml adds your identity providers (GitHub, or any Dex connector), backups (any S3
bucket) and, for production, high availability. Behind a TCP relay or load balancer that sends
PROXY protocol headers, set gateway.proxyProtocol=true.
The chart’s values.yaml and the project README document every setting.