About

A Kubernetes control plane built around the protection-window primitive.

telark exists to make admission policy something you can pin to an application boundary and a clock. The rest of the product — discovery, snapshots, rollback, RBAC — exists because the protection-window primitive needed them to be honest.

What it does today

  • Time-bounded protection plans, scoped to applications or namespaces, mode-flagged audit or enforce.
  • Nine built-in policy templates with parameterised inputs where the behaviour demands it.
  • Live cluster-truth plan health with drift detection and a violations feed.
  • Live application discovery, change classification, and snapshot-backed rollback as the operational floor.
  • Passkey-first auth, Google SSO, and CRD-based RBAC.

What it does not do

  • Multi-cluster federation. Single-cluster, single-tenant only.
  • Hosting itself. Self-hosted by license and by design.
  • Generic policy-as-library positioning. telark is a protection-window product, not a CI gate.

Get in touch

telark is early access. Open an issue or start a discussion at https://github.com/telark/telark, or email contact@telark.io.