Skip to content

Architecture

Every control plane is a set of parts ctrlplane runs for you, plus one optional part you run yourself: the connector that opens a path into your network.

you ──kubectl / site──▶ your API server (hosted by ctrlplane)
▲
│ watch, update
your controllers (hosted, sandboxed)
│
│ tunnel
▼
your network (VMs, databases, …)
Part Where it runs What it does
Your API server ctrlplane A Kubernetes API server with its own storage, CA and RBAC, at https://<id>.api.ctrlplane.run. It serves CRDs, your custom resources, namespaces, Secrets, ConfigMaps, RBAC and events.
Your controllers ctrlplane Each controller image you deploy runs as its own sandboxed workload, with a kubeconfig for your API server.
The tunnel ctrlplane Optional. A SOCKS5 proxy your controllers use to reach your network.
The connector your network Optional. Dials out to your tunnel, so nothing in your network is opened inbound. Or use Tailscale instead.
The site ctrlplane app.ctrlplane.run: create control planes, deploy controllers, see logs, metrics and events.

You → your API server. kubectl connects to https://<id>.api.ctrlplane.run. ctrlplane routes the connection by hostname without decrypting it, so TLS ends at your own API server, whose certificate is signed by your control plane’s own CA (it’s in your kubeconfig). You sign in with GitHub through OpenID Connect; see Access and authentication.

Controllers → your API server. Each controller gets a client certificate from your control plane’s CA, as the service account system:serviceaccount:<namespace>:<controller>. It may do anything in your control plane’s namespace and with your own API types, and nothing else.

Controllers → your network. With a tunnel turned on, controllers get HTTPS_PROXY pointing at it, and the tunnel carries their connections to your network. See Networking.

  • Per control plane: its own CA and service-account signing key. A certificate or token from one control plane is worthless at another.
  • Controllers: run without privileges (non-root, no capabilities, seccomp, Pod Security restricted). They can reach the public internet and their own control plane; private networks only through your tunnel. They can’t reach other customers, ctrlplane’s own services, or cloud metadata.
  • Metrics and logs: every query your API server answers is pinned to your control plane.
  • Audit: your API server records who did what (metadata only, never object contents).