Trust & Privacy

Full Transparency Over Your Data

A single lightweight agent that reads Kubernetes metrics.

Minimal RBAC

Only list and watch verbs on cluster resources. Zero write or delete permissions.

No Sensitive Data

Never collects Secrets, ConfigMaps, environment variables, container logs, or network traffic.

Full Control

Install or remove with a single helm command. Your cluster, your decision.

Data Collection

Exactly What We Collect

Resource metadata and usage metrics only.

Resource Metrics

  • Pod CPU and memory usage (per container)
  • Node CPU and memory capacity and usage
  • Resource requests, limits, and ephemeral storage
  • StorageClasses, PVs, PVCs, and CSI volume sources
  • Per-container GPU resource allocation

Kubernetes State

  • Pod status, phases, QoS class, and conditions
  • Node system info, conditions, and taints
  • Namespace metadata and pod distribution
  • Service types, IPs, ports, and load balancers
  • Ingress rules, hosts, and routing paths
  • Kubernetes cluster version

Workload Controllers

  • Deployments, StatefulSets, DaemonSets
  • Jobs, CronJobs, and execution schedules
  • HPA and VPA configurations
  • PodDisruptionBudgets and PriorityClasses
  • Karpenter NodePools and custom CRD workloads
  • Replica counts, update strategies, and conditions

Resource Metadata

  • Container image names and image IDs
  • Labels and annotations on all resources
  • Service account names
  • Node instance types, zones, and architecture
  • Pod and node IP addresses, pod CIDRs
  • Container ports, init containers, and owner references
  • Resource UIDs and creation timestamps

Scheduling & Quotas

  • LimitRanges (default requests and limits)
  • ResourceQuotas (namespace-level caps)
  • Pod priority and scheduler configuration
  • Cloud provider and region detection

GPU Metrics

  • GPU utilization and tensor activity
  • Memory used, free, and total bytes
  • Memory copy utilization (bandwidth)
  • Temperature and power usage
  • Device model, driver version, MIG support
Data Flow

Single Network Endpoint

The agent reads from the Kubernetes API server and sends data to one outbound endpoint. All traffic is encrypted with TLS.

Kubeadapt AgentSingle binary, in-cluster
Kubernetes APIlist + watch API calls
Kubeadapt CloudTLS + zstd compressed

You have full control over your data. Stop metric collection at any time by removing the agent from your cluster.

See how we use these metrics on our Cost Monitoring and Workload Rightsizing pages.

Ready to see it in action?

Deploy the agent in minutes. One helm command. Full transparency.