Skip to main content
The Komodor Agentic Operation Platform (KAOP) has three parts: the control plane, the SDK, and the agents. Two of them are deployed somewhere and matter for a network and security review: the agents, which do the work and need access to the systems they work on, and the control plane, the service behind the console that runs them and keeps the record. The SDK is a library inside each agent, not something you run. Each of the two can run on Komodor’s infrastructure or on yours, and the choices are independent.

Komodor-hosted agents

Komodor runs both the control plane and the agents; your network has nothing to install. Hosted agents reach public APIs such as Datadog, AWS and PagerDuty. Deploy from the console; Komodor runs the agent. Nothing to install. Choose this when everything the agent needs is reachable over public APIs: Datadog, your cloud provider, GitHub. Most catalog agents run this way.

Self-hosted agents

Agents run in your network beside the private systems they reach, with one outbound HTTPS connection to the Komodor-hosted control plane. Run the agent in your own cluster or VM; it connects out to the control plane and appears in your fleet like any other. Choose this when the agent needs something only reachable from inside your network. The agent needs outbound HTTPS to the control plane and nothing else. No inbound firewall rule, no VPN. The choice is per agent, so hosted and self-hosted agents share one fleet and one evidence trail.

Self-hosted control plane

Control plane, agents and private systems all run in your network; outbound traffic goes only to the model endpoint and the systems you connect. For organizations that cannot use a hosted service, the control plane itself runs in your own environment: everything the platform stores stays with you, and the only outbound traffic is to the model and the systems you connect. It ships as an umbrella Helm chart that bundles every component, so it installs as a single release.
Beta. Self-hosting the control plane is available under agreement, not as a self-service install. Talk to your account team before planning a rollout around it.

Next steps

Network & egress control

What agent traffic may reach, and how to scope it.

Data handling & redaction

What a run records, and what never leaves your network.

Architecture

How the control plane and agents communicate.