From cluster signal to a safe next action.
Every major view follows the selected cluster. Drill into evidence before applying a change, and use workspace access controls to decide who can see and manage each environment.
Your first automatic review
After the first accepted agent report, KrevoPilot maps applications, pod readiness, Kubernetes warnings, resource usage and supported topology relationships. It does not change the cluster from Overview.
Overview
Overview is the decision page for the selected cluster. Its health, application, optimization, activity and capacity numbers come from the same cluster snapshot or stored analysis.
Cards and rows are interactive. Select a segment or issue to open focused details; application links should resolve to the exact application or pod rather than the general list.
Clusters
Clusters is the connection control center. It distinguishes healthy agents, offline saved connections and incomplete setup. Each row shows the last report, detected environment, agent/image/chart version and available update.
- Open cluster selects it for the dashboard.
- Fix connection preserves the saved record and history.
- Upgrade generates a release-specific command.
- Technical details exposes safe identifiers and diagnostic status.
Applications and topology
Applications groups Kubernetes controllers into recognizable application names using real agent data. Open a card to see its namespace, controller, pods, services, EndpointSlices, ingress, configuration references and storage relationships when collected.
A line is shown only when Kubernetes ownership, selectors, references or endpoints support the relationship. Select a component to inspect its health and available YAML, events, metrics or logs.
Real resource names appear when identifier collection is enabled. Privacy aliases are used when a workspace intentionally hides identifiers; they should not coexist as duplicate rows for the same application.
Operational dashboards
Dashboards opens a graph-first view for the selected cluster. Use the dashboard selector for built-in or saved views, or choose Browse dashboards to open the filterable dashboard library.
Charts are built from accepted agent snapshots and stored metric history. Missing telemetry is shown as unavailable; KrevoPilot does not draw synthetic lines. Historical log widgets work only when a customer-controlled Loki connection is configured and reachable, and the current Loki state is displayed above the dashboard.
Krevo AI investigations
Select an unhealthy pod and run an investigation. The result opens on Fix and keeps Verdict, Evidence, Logs, Events, YAML, Timeline, Verification and Hypotheses one click away.
Commands are recommendations, not automatic execution. Validate the cluster context, object name and generated change. See the published benchmark for bounded accuracy and limitations.
Optimize
Optimize analyzes resource requests against observed usage history. CPU and memory are evaluated separately, so a workload can need less CPU and more memory at the same time.
| Observed history | Confidence label | Meaning |
|---|---|---|
| 3 days | Preliminary | Minimum history for early recommendations. |
| 7 days | Recommended | Normal production confidence target. |
| 14 days | Strong | More operating patterns captured. |
| 30 days | Highest | Better coverage of periodic workloads. |
A recommendation shows current request, average, P95, peak, suggested request, samples, history, confidence and evidence. Zero meaningful use is categorized as an idle-workload review rather than a normal request of zero. When requests or limits change, a new resource-configuration epoch starts so old settings do not drive the new recommendation.
Potential savings estimate the opportunity. Recommended savings include mature candidates. Applied and verified savings require the change to be tracked and observed after rollout.
Deploy and GitOps
Start with a ready-made tool, your container image or a plain-language plan. Choose the target cluster, cluster type and delivery method. GitOps can push generated files to a connected repository for Argo CD to sync; download mode keeps delivery manual.
- Required fields have an asterisk and turn red when missing.
- Review generated manifests before deployment.
- Saved deployments are isolated to the workspace and can be deleted.
- Cluster facts such as namespaces, storage classes, ingress classes and Argo CD detection are clickable when available.
Integrations and notifications
Owners and permitted administrators configure integrations in Settings → Integrations. Test delivery before enabling an alert destination. Webhook secrets are encrypted at rest and are not shown again; recent delivery status is retained for operational review.
Teams & Access
Owners and permitted Admins manage workspace roles, team membership and cluster visibility. A member can receive clusters through a team or through a direct cluster grant. Viewer and Developer accounts with no assignment correctly see no customer-cluster data.
| Role | Typical use |
|---|---|
| Owner | Workspace security, SSO, access and all administration. |
| Admin | Manage operational access and users as permitted. |
| Developer | Investigate and work with assigned clusters. |
| Viewer | Read-only product access to assigned scope. |
The workspace role decides which actions a user may perform. Team and direct assignments decide which clusters the user may see. Frontend visibility never replaces backend authorization checks.
Role, team and cluster-access changes retain actor attribution for audit review.
SSO / OIDC
- An Owner opens Teams & Access → Single sign-on.
- Register KrevoPilot’s exact callback URL with the identity provider.
- Enter issuer URL, client ID, secret and one or more company domains.
- Test the provider, enable SSO, then complete one real sign-in.
- Choose whether permitted-domain users are pre-provisioned or automatically created.
- Optionally map exact OIDC group names to Viewer, Developer or Admin. Owner is never assigned automatically.
- After validation, optionally require SSO while retaining the documented Owner recovery path.
Domains such as gmail.com would allow unrelated accounts to match. Automatic provisioning is for customer-controlled domains such as otto.de.
At each sign-in, the highest matching group mapping can update the member’s workspace role. If no mapping matches, the configured default role applies. New members still require a team or direct cluster assignment before they can see customer-cluster data.
