Every cluster.
Every signal.
One console.
220+ features across 15 pillars — causal correlation, blast-radius, GitOps, secrets chain, AI root-cause — install the agent in 2 minutes.
15 pillars. One install.
Not a roadmap — every card below ships today.
Causal correlation
Events → effect chains with confidence scoring
Blast radius
Sub-300ms BFS from any failing resource
Vulnerability suite
Trivy CVEs, Kyverno policies, Trivy secrets
Secret chain
Conjur ↔ ESO ↔ Secret full resolution
ArgoCD native
Applications, AppSets, AppProjects + sync actions
Kargo pipeline
Freight, Stages, Promotions visualized
Metrics + logs
Per-UID drawer: Prometheus + Loki correlated
Real kubectl exec
WebSocket terminal through Cloudflare Worker
Multi-cluster
Agent per cluster, aggregate or switch
17 plug-ins
First-party integrations auto-detected on install
Root-cause AI
Claude Opus / Sonnet / GPT tiered routing
Per-pod cost
Prometheus → $0.031/core × 730h
Cilium + Istio
BGP, Hubble, VirtualServices, mTLS
DB operators
CNPG + Percona PG/PSMDB/PXC
Enterprise auth
Clerk SSO, RLS, audit 90j, 2FA admin
Find the cause. In three clicks.
A property graph + event window, pinned to each cluster. Blast-radius BFS in under 5 ms. Causal-chain detection combining pattern matching, graph proximity, and temporal ordering. Confidence scores on every link.
- Sub-300ms blast-radius on 5000-node graphs
- Event clustering with natural-language summaries
- Pattern catalog: OOMKilling → BackOff, node drain → reschedule
- Interactive graph canvas (xyflow + dagre + elk layout)
Vulns, policies, secrets — all on one UID.
Trivy aggregates per workload. Kyverno scores as a compliance %. Conjur ↔ ExternalSecrets ↔ K8s Secret chain resolution flags broken links instantly. cert-manager + Vault PKI in the same view.
- Per-workload vulnerability aggregation (critical / high / medium / low)
- Kyverno compliance score + per-policy drill-down
- Secret chain status: full / partial / unresolved / conjur-native
- Cert-manager + Vault PKI chain walker
10 tabs. Same UID. Zero context loss.
The drawer reads five data sources — metrics-server, Prometheus, Loki, the Events API, and pod log streams — and joins them on metadata.uid. No tab-switching between tools. No correlation by guess.
- Metrics-server live + 10-point CPU/memory sparkline
- Loki error-rate + anomaly tier (normal → critical)
- Real kubectl exec + streaming logs (xterm + virtual viewer)
- Events timeline per resource + cross-cluster
ArgoCD and Kargo in the same frame.
Applications, ApplicationSets, AppProjects on one side. Freight, Stages, Promotions, Warehouses on the other. Every workload managed by either shows both badges in the drawer. Pipeline visualizer + inline Promote / Abort.
- Per-workload sync + health badges (Synced / OutOfSync / Degraded)
- Kargo pipeline as a flow-graph with inline actions
- GitOps maturity score + gap analysis per cluster
- Helm release provenance decoded from cluster Secrets
Why not k9s, Lens, or Rancher?
Per cluster. Unlimited seats, every plan.
You pay for the clusters we correlate, not the engineers that watch them. Annual saves 17 %. Overage at $2/node past the included cap — no surprise invoice.
- ✓3 clusters · 10 nodes each
- ✓Unlimited seats
- ✓Correlation engine · 24 h window
- ✓Blast radius + multi-cluster view
- ✓All 30+ enrichments, all 17 plug-ins
- ✓7-day event retention
- ✓Community support
- ✓Up to 25 clusters · 50 nodes each (+$2/node overage)
- ✓Unlimited seats
- ✓30-day correlation window · 1-year snapshots
- ✓90-day event retention
- ✓MCP endpoint · 120 req/min for your AI agents
- ✓Alerts → Slack, email, PagerDuty, webhooks
- ✓Google / GitHub SSO · 90-day audit log
- ✓Email support · 24 h response
- ✓Unlimited clusters and nodes
- ✓SAML / OIDC SSO + SCIM provisioning
- ✓BYOC agent — telemetry stays in your VPC
- ✓Audit log export: S3, Splunk HEC, Datadog Logs
- ✓1–3-year retention · data residency (EU / US / APAC)
- ✓Private MCP endpoint with mTLS + IP allowlist
- ✓99.9 % SLA with service credits
- ✓Dedicated CSM + onboarding engineer
The correlation engine, blast radius, multi-cluster graph, and all 30+ enrichments are in every plan. Paid tiers scale capacity — more clusters, longer retention, the MCP endpoint — and unlock compliance features (SSO, SIEM export, BYOC) in Enterprise.
Two commands. Three minutes.
Mint a token
Settings → API Keys → Generate registration key.
Helm install
helm install klstr-agent ... --set agent.registrationToken=...
Cluster appears
Live pods, events, graph in under 30 seconds.



