HermetiqDocsOpen dashboard
Deployments
Deployments

Choose the right deployment boundary

Understand the hosted and customer-managed deployment paths, including identity, telemetry authentication, and data boundaries.

Hosted or customer-managed Kubernetes

Deployment options

Hermetiq supports a hosted product path and customer-managed deployment paths. The right choice depends on security, identity, networking, data-boundary, and Buildbarn ownership requirements.

Hermetiq-hosted

Fastest path to product evaluation

Use the hosted dashboard, project Quickstart, managed service endpoints, and Hermetiq Cloud MCP endpoint.

Customer-managed

Run the platform inside your environment

Deploy Hermetiq services and supporting infrastructure in a customer-controlled Kubernetes environment.

Hermetiq-hosted

The hosted path uses Hermetiq’s dashboard and project-scoped Quickstart flow. Hosted authentication uses Stytch, while build ingestion and optional data sources use the project-specific credentials and endpoints generated for the project.

Open the hosted dashboard →

Customer-managed

Hermetiq maintains customer-managed Kubernetes deployment paths, including Pulumi-based infrastructure for Azure Kubernetes Service and Helm-based installation guidance tested for Google Kubernetes Engine.

These deployments include Hermetiq application services and can integrate supporting components such as PostgreSQL, NATS JetStream, VictoriaMetrics, OpenTelemetry Collector, Grafana, and Buildbarn according to the selected topology.

Identity and authentication

Hosted users

Authenticated through the hosted Stytch integration.

Customer-managed users

The documented deployment path uses oauth2-proxy with the customer’s OIDC provider.

Machine ingestion

Customer-managed deployment tooling supports JWKS-based machine authentication for BEP ingestion.

MCP

Use the hosted OAuth flow or the authentication configuration for the customer-managed endpoint.

Data boundary

In customer-managed deployments, the application services and configured data stores run in the customer environment. The exact boundary still depends on the deployment’s external identity provider, cloud-managed services, artifact storage, and any integrations the customer chooses to enable.