Agent Hub · Part of Nirmata Control Hub

Kubernetes governance with AI agents on your team.

Clusters keep multiplying. Platform teams don't. Agents take on the ongoing work of security, compliance, cost and troubleshooting, so your team reviews results instead of chasing them.

Read-only access Your data is never used for training Included with Control Hub Advanced & Enterprise
workload-troubleshooterRunning · 7 of 8 steps
Resolvenamespaces Pod health Warning events Deployments Node health PVC binding Aggregatefindings Analyze &write reportAI · RUNNING READ-ONLY · IN PARALLEL
Completed read-only stepAI analysis of collected data
Stay securePeriodic access reviewsContinuous RBAC and policy checks
Stay audit-readyScrambling before auditsCompliance evidence on every run
Cut cloud wasteQuarterly cleanupsWeekly right-sizing and cleanup
Fix fasterDigging through events and logsRoot cause, and a fix as a pull request
Where agents run

Run them from Control Hub, in your cluster, or on your desktop.

Nirmata cloud · on demand or scheduled

Managed agents

Launch any agent from Control Hub, now or on a schedule. They run in Nirmata's cloud, so there's nothing to install.

Your cluster · always on · Helm

Remediator (in-cluster)

Runs 24/7 inside your cluster, watches for Kyverno policy violations and opens a pull request with the fix. It never pushes directly.

Your terminal or IDE · nctl ai

Nirmata Assistant

Writes, tests and debugs Kyverno policies from your terminal, or inside Cursor and Claude Desktop as an MCP server.

Agent catalog

An agent for each ongoing job.

Every agent is read-only and ends in a report. Two of them also write the Kyverno policies that keep the problem from coming back.

Secure

Access, policy and compliance posture.

rbac-analyzer

RBAC Analyzer

Maps what every ServiceAccount can actually reach: cluster-admin grants, wildcard permissions, secret access and privilege-escalation paths. Rates each finding by risk, maps it to MITRE ATT&CK for Containers, and gives least-privilege fixes.

MITRE ATT&CKBlast radius
policy-recommender

Policy Recommender

Looks at the workloads actually running in your cluster and generates the Kyverno policies they need for security hardening, resource governance and best practices.

Writes Kyverno policies
compliance-auditor

Compliance Auditor

Scans your cluster against the standard you choose, maps violations to its controls, and gives a pass/fail summary with remediation guidance.

CIS KubernetesCIS EKSCIS AKSCIS GKENSA/CISANIST 800-53ISO 27001PCI-DSSSOC 2RBI

Optimize

Spend and cluster hygiene.

cost-analyzer

Cost Analyzer

Finds over-provisioned resources, idle workloads and orphaned volumes using live metrics and historical Prometheus data, then estimates monthly savings at your cloud prices.

Right-sizingMonthly savings
resource-cleaner

Resource Cleaner

Finds unused and stale resources across 14 categories, from orphaned PVCs to empty namespaces, ranks cleanup by how safe it is, and suggests Kyverno policies that stop them piling up again.

14 resource typesWrites Kyverno policies

Fix

Diagnose failures and draft fixes.

workload-troubleshooter

Workload Troubleshooter

Diagnoses CrashLoopBackOff, OOMKilled, Pending pods, unavailable deployments and unbound PVCs using read-only queries. No exec, no changes. Returns the root cause and safe next steps.

Root causeNo exec
remediator

Remediator (managed)

Generates YAML fixes for Kyverno violations in a namespace, with a before-and-after view, confidence scores and severity. Nothing is applied until you decide.

Confidence scoresNot applied
Remediator (in-cluster)

From policy violation to pull request, without anyone paging through reports.

  1. Step 1Kyverno flags a violationRemediator reads your cluster's policy reports continuously.
  2. Step 2Remediator drafts a fixA compliant change, with a confidence score.
  3. Step 3A pull request opensIn your Git repo. Branch protection is respected.
  4. Step 4You review and mergeYour normal GitOps flow ships the change.
You choose what becomes a PR: high-confidence fixes only, low-confidence fixes for review, or both.
Your choice of model: Nirmata AI, Anthropic Claude, OpenAI, Google Vertex AI and Gemini, AWS Bedrock or Azure OpenAI.
Reports

Every run ends in a report your team can act on.

One place for every resultEvery agent run lands in Control Hub Reports, searchable and labeled.
Shared automaticallySchedule a run and send the report to Slack or email.
Ask Copilot about itCopilot in Control Hub answers questions from your reports.
Copilot in Control Hub
Which namespaces drive most of the waste this month?
From the latest Cost Analyzer report:
  1. analytics: 11 idle deployments
  2. staging: CPU requests 4× actual usage
  3. ml-batch: 6 orphaned PVCs
Example conversation
How agents work

See exactly what every agent did.

Every Agent Hub agent is an OttoFlow workflow: a graph of steps that runs the same way every time, like the one above.

First, read-only steps collect data from your cluster: pods, events, metrics, RBAC bindings. Then AI analyzes only what was collected, to find issues, size resources and write recommendations. It never queries or changes your cluster itself.

Every run keeps its execution graph and full report, so you can audit how each conclusion was reached.

See OttoFlow, the open source engine →

Summary

What the agent found, at a glance.

Execution

Every step it ran, in order, with its status.

Report

Findings, recommendations and fixes, ready to share.

FAQ

Questions security and platform teams ask.

Can I try the agents before buying?

Yes. Start a free Control Hub trial, connect a cluster and run any agent.

Where do managed agents run?

In Nirmata's cloud, as short-lived jobs. They reach your cluster through the Control Hub connection with scoped, read-only permissions.

Does anything change in my cluster?

No. Agents only need read-only access. The one exception is Remediator (in-cluster), and it only opens pull requests for you to review.

Is my data used to train AI models?

No. Customer and cluster data is never used for model training.

What does the AI do, and what doesn't it do?

Read-only workflow steps collect data from your cluster. AI then analyzes that data and writes findings, recommendations and the report. AI never queries or changes your cluster directly.

What's the difference between Copilot and Nirmata Assistant?

Copilot lives in Control Hub and answers questions about your clusters and reports. Nirmata Assistant runs on your desktop, in your terminal or IDE, and helps you write and test policies.

Which AI models do agents use?

Nirmata AI by default. You can also bring your own model: Anthropic Claude, OpenAI, Google Vertex AI and Gemini, AWS Bedrock or Azure OpenAI.

Which plan includes Agent Hub?

Nirmata Control Hub Advanced and Enterprise, and every free trial.

Put agents to work on your clusters.

Connect a cluster, run Workload Troubleshooter or RBAC Analyzer, and read your first report.