Fastest path to product evaluation
Use the hosted dashboard, project Quickstart, managed service endpoints, and Hermetiq Cloud MCP endpoint.
Understand the hosted and customer-managed deployment paths, including identity, telemetry authentication, and data boundaries.
Hermetiq supports a hosted product path and customer-managed deployment paths. The right choice depends on security, identity, networking, data-boundary, and Buildbarn ownership requirements.
Use the hosted dashboard, project Quickstart, managed service endpoints, and Hermetiq Cloud MCP endpoint.
Deploy Hermetiq services and supporting infrastructure in a customer-controlled Kubernetes environment.
Hermetiq operates the application and service endpoints. Projects use the hosted dashboard, authentication, Quickstart, and MCP URL.
The Helm installation is tested on GKE 1.33.x. The guide includes GKE-oriented examples for storage, workload identity, Gateway, DNS, and TLS.
Conformant Kubernetes 1.32+ is supported when the cloud database, storage classes, ingress or Gateway, identity, DNS, and TLS pieces are mapped to provider equivalents.
Helm 3.8+ is required for OCI charts. Hermetiq, Buildbarn, and worker-operator charts are distributed through the private ghcr.io/hermetiq registry.
kubectl, DNS and TLS ownership, and access to the private chart registry.Optional components include VictoriaMetrics, Grafana, OpenTelemetry Collector, KEDA, and the Buildbarn worker operator.
The full customer installation and operations guide is supplied with customer-managed evaluation or licensing access. It covers registry authentication, values files, PostgreSQL, OIDC/JWKS, workload identity, NATS, routing, telemetry, Buildbarn, licensing, upgrades, and air-gapped considerations.
Authenticated through the hosted Stytch integration.
The documented deployment path uses oauth2-proxy with the customer’s OIDC provider.
Customer-managed deployment tooling supports JWKS-based machine authentication for BEP ingestion.
Use the hosted OAuth flow or the authentication configuration for the customer-managed endpoint.
Treat chart and dependency updates as controlled infrastructure changes:
Operational ownership should cover certificates, registry access, database migrations and backups, NATS health, telemetry retention, Buildbarn capacity, and license renewal.
In customer-managed deployments, the application services and configured data stores run in the customer environment. The exact boundary still depends on the deployment’s external identity provider, cloud-managed services, artifact storage, and any integrations the customer chooses to enable.