Where your agents run, where the control plane runs, and how to choose.
The Komodor Agentic Operation Platform (KAOP) has three parts: the control plane, the SDK, and the
agents. Two of them are deployed somewhere and matter for a network and security review: the
agents, which do the work and need access to the systems they work on, and the control
plane, the service behind the console that runs them and keeps the record. The SDK is a library
inside each agent, not something you run. Each of the two can run on Komodor’s infrastructure or on
yours, and the choices are independent.
Deploy from the console; Komodor runs the agent. Nothing to install. Choose this when everything
the agent needs is reachable over public APIs: Datadog, your cloud provider, GitHub. Most catalog
agents run this way.
Run the agent in your own cluster or VM; it connects out to the control plane and appears in your
fleet like any other. Choose this when the agent needs something only reachable from inside your
network. The agent needs outbound HTTPS to the control plane and nothing else. No inbound firewall
rule, no VPN.The choice is per agent, so hosted and self-hosted agents share one fleet and one evidence trail.
For organizations that cannot use a hosted service, the control plane itself runs in your own
environment: everything the platform stores stays with you, and the only outbound traffic is to
the model and the systems you connect. It ships as an umbrella Helm chart that bundles
every component, so it installs as a single release.
Beta. Self-hosting the control plane is available under agreement, not as a self-service
install. Talk to your account team before planning a rollout around it.