Architecture
Every control plane is a set of parts ctrlplane runs for you, plus one optional part you run yourself: the connector that opens a path into your network.
you ──kubectl / site──▶ your API server (hosted by ctrlplane) ▲ │ watch, update your controllers (hosted, sandboxed) │ │ tunnel ▼ your network (VMs, databases, …)The parts
Section titled “The parts”| Part | Where it runs | What it does |
|---|---|---|
| Your API server | ctrlplane | A Kubernetes API server with its own storage, CA and RBAC, at https://<id>.api.ctrlplane.run. It serves CRDs, your custom resources, namespaces, Secrets, ConfigMaps, RBAC and events. |
| Your controllers | ctrlplane | Each controller image you deploy runs as its own sandboxed workload, with a kubeconfig for your API server. |
| The tunnel | ctrlplane | Optional. A SOCKS5 proxy your controllers use to reach your network. |
| The connector | your network | Optional. Dials out to your tunnel, so nothing in your network is opened inbound. Or use Tailscale instead. |
| The site | ctrlplane | app.ctrlplane.run: create control planes, deploy controllers, see logs, metrics and events. |
How a request travels
Section titled “How a request travels”You → your API server. kubectl connects to https://<id>.api.ctrlplane.run. ctrlplane
routes the connection by hostname without decrypting it, so TLS ends at your own API
server, whose certificate is signed by your control plane’s own CA (it’s in your kubeconfig).
You sign in with GitHub through OpenID Connect; see Access and authentication.
Controllers → your API server. Each controller gets a client certificate from your control
plane’s CA, as the service account system:serviceaccount:<namespace>:<controller>. It may do
anything in your control plane’s namespace and with your own API types, and nothing else.
Controllers → your network. With a tunnel turned on, controllers get HTTPS_PROXY pointing
at it, and the tunnel carries their connections to your network. See
Networking.
Isolation
Section titled “Isolation”- Per control plane: its own CA and service-account signing key. A certificate or token from one control plane is worthless at another.
- Controllers: run without privileges (non-root, no capabilities, seccomp, Pod Security
restricted). They can reach the public internet and their own control plane; private networks only through your tunnel. They can’t reach other customers, ctrlplane’s own services, or cloud metadata. - Metrics and logs: every query your API server answers is pinned to your control plane.
- Audit: your API server records who did what (metadata only, never object contents).