Running production workloads
Use this checklist when a demo app is ready to become a real workload.
Work through each area once per app. Each card links to the feature or guide page that covers it in depth; there is no new content on this page.
Reliability
Section titled “Reliability” Set requests, limits, and probes What a production-ready Deployment looks like on Kupe Cloud.
GitOps delivery patterns Promote changes between environments with Argo CD and Git.
Traffic and routing
Section titled “Traffic and routing” HTTP routes Route traffic with Gateway API HTTPRoutes on the shared gateway.
Custom domains Serve the app on your own domain, with DNS automation.
TLS and certificates Automatic certificates for `*...clusters.kupe.cloud` hostnames and your own domains.
Secrets
Section titled “Secrets” Managed secrets Store values once and sync them into one or more clusters.
Create and sync secrets Step-by-step walkthrough of the sync flow.
Observability
Section titled “Observability” Alerting Write alert rules that fire on symptoms your users feel.
Notifications Route alerts to Slack, PagerDuty, Teams, email, or webhooks.
Dashboards Built-in dashboards and how to customise them for your app.
Security
Section titled “Security” Cluster policies Policies enforced by the platform on every tenant cluster.
Vulnerability scanning Continuous CVE and misconfiguration scanning for your workloads.
Network isolation How tenant and namespace boundaries are enforced on the network.
Day-2 operations
Section titled “Day-2 operations” Upgrade clusters Day-2 upgrades of the Kubernetes version and platform components.
Platform limits Practical bounds to plan capacity against.