Infrastructure control

kFleet

Your virtual machines, your containers, your Kubernetes, your firewall, your DNS, your certificates and your remote access: one console, one set of permissions, one audit trail. Running a hybrid infrastructure today means assembling eight tools that do not talk to each other, then maintaining the glue between them. kFleet replaces the assembly.

Self-hostableTwenty-four domainsVersioned configurationPriced per managed node

What the assembled stack costs

Nobody chose to run eight consoles. They were added one at a time, each for a good reason, and the cost only shows up once the whole thing is in place.

  • A hypervisor on one side, a container orchestrator on the other, a third tool for Kubernetes: three permission models, three directories, three logs.
  • The firewall, DNS and certificates live in yet other tools — often in scripts, sometimes in one person's head.
  • The glue between all of it has to be maintained: it serves no business purpose, and it breaks the moment you look away.
  • The day an auditor asks who changed what, the trail is reconstructed by hand, tool by tool — when it still exists at all.

What kFleet replaces

The honest way to describe kFleet is to start from what a team already maintains. The third column matters most: it separates what serves you on day one from what first needs your estate described.

Maintained todayWhat kFleet bringsOn install
Proxmox, vCenter, virt-managerlibvirt (KVM/QEMU), Lima and VirtualBox virtualisation: machine lifecycle, browser console, snapshots, cloud-init, live migration between hypervisors.Usable as is
Portainer, Rancher, kubectlDocker, Podman, LXD, Incus and LXC containers, and multi-cluster Kubernetes across thirteen resource types — one console for all three families.Usable as is
pfSense, nftables scriptsA driven nftables firewall: profiles, zones, ordered rules, a diff before applying and lock-out protection.Foundation to describe
BIND, dnsmasq, Kea, ISC DHCPDNS across six supported engines and DHCP across three: zones, records, scopes, reservations, all versioned.Foundation to describe
cert-manager, Caddy, ACME scriptsAuthorities, certificates and distribution: ACME with nine challenge types, renewal and installation on targets.Foundation to describe
Guacamole, home-grown bastionsRDP, VNC and SSH consoles in the browser, through a jump host, with encrypted credentials and a traced session.Usable as is
Ad-hoc Ansible, Foreman, SpacewalkSoftware estate: aggregated inventory, per-machine version gap, a security-only filter, bulk apply and follow-up.Usable as is
Terraform, cloud consolesAWS and Cloudflare: templates, planning, apply and continuous drift detection, with no local Terraform.Foundation to describe
Lucidchart, Visio diagramsA map built from the real inventory — machines, containers, pods, rules, tunnels — rather than redrawn by hand.Usable as is

“Foundation to describe” means the engine, the model and the screens are there, and your estate still has to be entered or imported: a driven firewall without your zones, a DNS without your domains replace nothing until they are configured. It is fast because the foundation exists; it is not instant, and we would rather say so beforehand.

What kFleet drives

Breadth is not the argument. The argument is that a certificate, the firewall rule protecting the service, the machine hosting it and the risk documenting its flaw are all driven from the same place, with the same permissions and the same log. No gateway, no cross-export, no extra console.

Virtual machines

libvirt (KVM/QEMU), Lima and VirtualBox behind one interface. Creation from an image, start and stop, snapshots, cloud-init, a console in the browser, live migration from one hypervisor to another. A machine's configuration is versioned like everything else: compare two states, roll one back.

The estate’s hypervisors, whatever their type.
Machines from every hypervisor, in a single list.

Containers, four engines

Docker, Podman, LXD/Incus and LXC. Engines are connected, containers are listed, started, read — logs included — and their configuration is versioned. A mixed estate does not require two tools.

Multi-cluster Kubernetes

Thirteen resource types — namespaces, deployments, pods, services, ingresses, volumes, jobs, cron jobs, secrets, config maps, storage classes, nodes — across as many clusters as you run. Logs, exec into a pod, port forwarding: from the browser.

Four clusters, three distributions, one console.

nftables firewall

The firewall is described as profiles: zones, ordered rules, a policy per chain. kFleet computes the diff before applying, refuses a rule that would cut off your own access, snapshots the rules in place and can roll back in one click.

  • The diff is read before the apply, not after.
  • A rule that would close your own access is refused before it is installed.
  • A snapshot of the rules before every apply, and a one-click rollback.
The estate’s profiles, and how many rules each carries.
One profile’s rules, in the order the chain evaluates them.

DNS and DHCP

Six supported DNS engines (BIND, dnsmasq, CoreDNS, PowerDNS, Route 53, Cloudflare) and three DHCP engines (Kea, ISC DHCP, dnsmasq). Zones, records, scopes, subnets and reservations are entered once and deployed to whichever engine serves you — the model does not change when the engine does.

A zone and its records.
A scope’s reservations: every machine in the inventory has its address here.

VPN and remote access

Eight VPN adapters — WireGuard, OpenVPN, IPsec, cloudflared, NordVPN, AWS, GCP and Azure — with their peers. And to work on a machine, an RDP, VNC or SSH console in the browser, through a jump host, with encrypted credentials and a traced session: no fat client, no bastion to maintain.

Certificates and PKI

Authorities, challenge providers and distribution targets. ACME issuance with six DNS-01 and three HTTP-01 challenges, then installation on the declared targets. The most direct consumer of that chain is the same product's Zero Trust edge — which is what guarantees it is exercised.

Application catalogue

Ninety-five ready-to-deploy applications, sorted by category, with variable substitution and a post-install phase. For a Helm repository, deployment is guided the same way.

The catalogue: 42 Helm charts, 53 manifests, 14 categories.

Software estate and patching

Software inventory aggregated across the fleet, a per-machine version gap, a security-only filter, bulk apply and real-time follow-up. A patching campaign becomes one operation instead of N scripts.

Security scanning and DAST

Twenty-three wired tools — dependency analysis, container images, system hardening, CIS baselines — and an authenticated application scan with replay. A scan result becomes an assessed risk, then a traced incident, then a report: with no re-export and no second tool.

The scan profiles shipped with the product.

Serverless and jobs

Knative jobs, their sources, revisions and triggers, with the runtime images shipped out of the box. An invocation is triggered and followed from the same console.

The runtime images shipped out of the box.

Estate map

A graph built from the real inventory — machines, containers, pods, firewall rules, tunnels, certificates, cloud resources — rather than redrawn by hand. It stays current because the product's own events feed it, not because someone remembered to update it.

Nodes and collectors

Every driven machine carries an agent reporting its state: hardware, storage, network, installed software. That collected state feeds the inventory, the map and the software estate — one report, several screens.

Zero Trust edge

A self-hosted access gateway whose configuration is compiled, signed and verified before being applied, keeping the last known-good version. It is an adjacency of the control surface, not a standalone access product — but the chain of trust reaches the data plane.

On the Kore platform

Users, roles and fine-grained permissions, organisations, a sealed audit trail, a single GraphQL API, workflows, documents: kFleet rewrote none of these, it inherits them from the platform. That is why an infrastructure control surface arrives with permission management and an audit trail worth the name.

kFleet does not start from scratch

An infrastructure control surface needs users, roles, organisations and an audit trail before it needs a hypervisor. kFleet did not rewrite them.

The Kore platform

Identity and access, nested organisations, fine-grained permissions, a sealed audit trail, a single GraphQL API, workflows, documents and artefacts. kFleet inherits them rather than rebuilding them — and Kore is also the module's technical and contractual prerequisite.

See the Kore platform

Sovereign, with no asterisk

Deployed on your own servers, including off-network. Go and PostgreSQL, no proprietary format, and no third-party UI components left: this is the argument for public-sector and regulated IT departments, and almost no competitor can tick it.

The three pillars

In this order. It is the order in which the argument holds: consolidate first, operate next, prove last.

You consolidate

One tool instead of eight: fewer licences, fewer accounts to manage, less training, one place to look. Thirty-two modules and more than forty adapters, under one console and one permission model.

You operate, not just deploy

Every configuration is versioned, comparable and revertible in one click — machines, containers, firewall, DNS, DHCP, VPN, cloud templates. Drift is detected continuously, not at the next deployment.

You prove

A scan result becomes an assessed risk, then a traced incident, then a report. No re-export, no second tool, and the platform's audit trail underneath every step.

kFleet is a licensed module on top of the Kore platform, which is its technical and contractual prerequisite.

What changes, task by task

The everyday tasks of an infrastructure team, and what the product does in their place.

TaskWhat kFleet doesOrder of magnitude
An urgent firewall ruleA diff before applying, lock-out protection, a snapshot of the rules, a one-click rollback.< 2 min (vs 15 min)
A complete development environmentThree machines, an address reservation, an updated DNS zone, a browser console — without leaving the page.< 5 min (vs 30–45 min)
A fleet-wide patching campaignAggregated inventory, per-machine version gap, a security-only filter, bulk apply and real-time follow-up.1 operation (vs N scripts)
Working on an unreachable machineAn RDP, VNC or SSH session in the browser, through a jump host, encrypted credentials, a traced session.No fat client, no bastion
Preparing an auditTwelve months of log, firewall changes with author and timestamp, access, certificates — pulled from one place.2 days (vs 10 days)

These durations are orders of magnitude observed under reference conditions, not commitments. They are recalibrated against your estate during scoping — a duration presented as a commitment is a trap that springs at the first real deployment.

What holds below the waterline

Five properties that do not show in a demo, and that decide the renewal.

  • Configuration is versioned across every domain — machines, containers, firewall, DNS, DHCP, VPN, cloud templates. Comparison and rollback everywhere.
  • A long-running operation survives a service restart: scans, patches and deployments resume where they left off.
  • A firewall rule that would cut off your access is refused before it is installed.
  • The audit trail is off-box: it does not depend on the machine being audited.
  • No third-party UI components: the entire software is owned and self-hostable, with no external component dependency.

Three editions, priced per managed node

No per-user pricing: spreading the tool through your team should not cost you more. You pay for the machines kFleet drives, and nothing else.

Up to 3 nodes

Community

Machines, containers and Kubernetes. Firewall, DNS, DHCP and VPN. Application catalogue and remote console. Community support.

4 to 50 nodes

Pro

Everything in Community, plus cross-domain versioning and rollback, AWS and Cloudflare with drift detection, software estate and fleet patching, cross-technology mapping, single sign-on, fine-grained permissions and audit, multi-tenancy for managed service providers, and 5-day support with next-business-day response.

Unlimited

Enterprise

Everything in Pro, plus authenticated application scanning and posture reporting, a risk register with timed incidents, a self-hosted Zero Trust edge with signed configuration, long-term support releases with security backports, and 7-day support with a 4 business-hour response.

Prices are not listed here: they are provided on a separate sheet. Separating the two lets the pricing evolve without reprinting the argument, and puts the price after the value.

What kFleet does not do

Better said now than in month two. These gaps are acknowledged and documented; they are not worked around with careful wording.

  • No built-in virtual machine backup, and no Velero-style Kubernetes backup. Your backup chain stays yours.
  • No physical server provisioning: no BMC, no IPMI, no PXE. kFleet drives what exists, it does not install it from bare metal.
  • The cloud pivot covers AWS and Cloudflare. Azure and GCP are described in the model but their adapters are not written.
  • Drift detection is in place on the cloud side; on machines, firewall and Kubernetes it still has to be extended.
  • No native high availability of the platform itself, and no hypervisor cluster with automatic failover.
  • No policy as code (OPA, Kyverno), no container image admission, no Vault integration.
  • No FinOps or showback, no predictive capacity planning.
  • The Hyper-V adapter is a scaffold, and fine-grained VPN peer orchestration (key rotation, mobile QR codes) is unfinished.

Convergence audit — free

One hour on your current stack: what you run, with how many tools, and what convergence would save you. No commitment, and no product demo — it is your infrastructure we look at, not ours.

  • Scoping, 3 days: an inventory of your estate, a map of the current stack, a costed convergence plan using your own numbers. Written deliverable, deductible from the first subscription.
  • Commissioning, 8 days: installation, connection to your directory, machines connected, two domains enabled, one day of training.
  • Migration or compliance, tailored: leaving VMware for KVM with a progressive cutover, or industrialising firewall, certificates and the evidence chain for NIS2 and ISO 27001.
Get in touch