AWS. EKS
IRSA gives pods short-lived role credentials. The workload assumes cross-account read-only roles in the target AWS accounts. RDS Postgres, ElastiCache Redis, and S3 for artifacts all stay in your VPC.
Install GrandLine inside your own Kubernetes cluster with a single Helm chart. Data never leaves your boundary. Cloud access uses agentless, read-only credentials issued by your own identity provider.
Pick the one that matches your control plane.
IRSA gives pods short-lived role credentials. The workload assumes cross-account read-only roles in the target AWS accounts. RDS Postgres, ElastiCache Redis, and S3 for artifacts all stay in your VPC.
Workload Identity binds a Kubernetes service account to an Entra federated credential. Cloud reads go through that federated identity. Postgres Flexible Server and Azure Cache for Redis run inside your VNet.
Workload Identity maps a K8s SA to a Google service account. WIF covers cross-org reads if you manage multiple organizations. Cloud SQL for Postgres and Memorystore Redis live in your VPC.
Bring your own Postgres and Redis. Install the Helm chart with values.yaml pointing at in-cluster or external services. We publish signed container images and SBOMs with every release.
One chart. Reasonable defaults. Override what you need.
See Docs for full values reference, air-gapped install notes, HPA and PDB examples, and upgrade procedure.
Everything that matters.
Discovered resources, relationships, tags, configurations. all stored in your Postgres.
Security findings and remediation state never leave your cluster.
PDFs, DOCX, PNGs, SVGs are rendered by an in-cluster worker and stored in S3-compatible object storage you own.
We publish a hardened container image signed with cosign, an SPDX SBOM per release, and a Trivy scan report. We do not phone home. License keys are validated offline.
Agentless, read-only access, issued by your own identity provider.
IRSA in the GrandLine namespace plus cross-account read-only IAM roles in each target account, trusted with an external ID. AWS Organizations onboarding is supported.
AKS Workload Identity binds to an app registration with a federated credential. The app has Reader + a narrow list of data-plane roles (e.g., Storage Blob Data Reader) per subscription or Management Group.
GKE Workload Identity plus an organization-level service account with roles/viewer and roles/iam.securityReviewer. Cross-org federation via WIF.
Day-2 ready.
OpenTelemetry traces, Prometheus metrics, structured JSON logs.
Rolling deployment with HPA and PDB. Zero-downtime migrations via helm upgrade.
Your Postgres backups. We document PITR expectations and a restore runbook.
Mirror our registry, bring your own CA bundle, validate the signed bundle offline.
GrandLine runs entirely inside your own Kubernetes cluster. Metadata never leaves your boundary - ideal for GovCloud, classified, or tightly regulated environments your security team has already approved.
Pull a new chart version when it suits your change windows. Releases are signed and digest-pinned; nothing auto-updates underneath you.