Security model

Local process. Existing identity. Kubernetes decides what is allowed.

Fortem uses the kubeconfig and context you select. Its default incident engine runs locally. It does not replace your identity provider, VPN, private endpoint access, or cluster RBAC.

Download the security packet ↓

Runs on your machine

The Go process serves the embedded web interface locally. No Fortem component is required inside the Kubernetes cluster.

Loopback by default

The HTTP server listens on 127.0.0.1 by default. Listening on a non-loopback address requires an explicit override.

Credentials stay in the backend process

The browser does not receive kubeconfig contents or authentication credentials. The Go Kubernetes client performs API requests.

Existing authentication still applies

Exec credential plugins, AWS CLI, gcloud/GKE auth, Azure CLI, kubelogin or OIDC login, credential expiry, VPN access, and private cluster endpoints remain your responsibility.

Read-only unless enabled

Management endpoints are blocked unless Fortem starts with management enabled, even when the selected kubeconfig identity has broad permissions.

RBAC remains authoritative

Fortem surfaces permission errors and checks authorization before a supported mutation. It does not bypass Kubernetes RBAC.

Trust boundaries

What crosses which boundary.

Kubeconfig

Kubeconfig bytes and credential values stay in the local Go process and are not included in browser-facing API responses.

Cluster data

Kubernetes objects and logs are rendered in the local browser. Default mode makes no connection to a Fortem- or Cybrix-operated service.

Logs

Requested from Kubernetes on demand and displayed locally; access depends on RBAC.

Metrics

Queried only from configured, reachable sources. Missing sources are reported as unavailable.

Incident analysis

The default deterministic engine runs locally. The current BYOK preview lets users opt into the experimental Jev adapter with `fortem jev configure` and `--decision-provider jev`; only normalized counts, reasons, hashed revision metadata and reduced log-pattern labels cross that boundary—never raw logs, kubeconfig data, namespace names or workload names. Jev cannot authorize a mutation and local rules remain the fallback.

Mutations

Limited to implemented operations, explicit enablement, confirmation, and an authorization check.

Read-only permissions

What Fortem reads today.

Core reads cover Namespaces, Pods, Deployments, StatefulSets, DaemonSets and Nodes. Environment details add Events, Services, Ingresses and EndpointSlices; logs require the pods/log subresource.

Metrics API reads and an explicitly configured Prometheus endpoint are optional. Fortem does not read Secret values, ConfigMaps, custom resources or cloud billing APIs in the current live mode.

An explicit namespace scope can avoid cluster-wide Namespace discovery. Withheld permissions become unavailable or partial data instead of fabricated zeroes.

Current release security posture.

Release checksums are part of the distribution path. Code signing, notarization, SBOM publication, SOC 2, SSO and SCIM must not be assumed until this page names them as verified. Review the source revision, exact permissions, network path, data handling and supported operations against your policy.

Verify the local boundary yourself.

Install with your coding agent, inspect the downloaded release and checksum, then start in demo mode before selecting a kubeconfig context.

or install yourself

Local install · read-only first · no Helm chart