Platform · Guided Shipping
Zero to shipped, in minutes.
A guided wizard takes you from cloud pick to production-ready in one flow, no Terraform, no YAML archaeology, no console tab-juggling. No fuss, no muss.
- Guided wizard, no YAML, no problem
- Production-ready in under 15 minutes
- AWS, GCP, Azure & self-managed
Overview
Why teams reach for Guided Shipping
Standing up a production cluster the old way means stitching together a VPC, subnets, NAT gateways, IAM roles, an OIDC provider, a node group, a CNI, an ingress controller and cert management, a few hundred lines of Terraform behind a wiki page that went stale two quarters ago. Guided Shipping collapses that sequence into one validated wizard: pick cloud, region, Kubernetes version and node size, and Kubentic provisions the infrastructure and control plane with production defaults already wired in. The result is a live, reachable cluster in under 15 minutes with zero lines of YAML from you.
The wizard is a thin front end over a declarative provisioning engine. Each answer narrows the next: pick GCP and a region, and the machine families and GKE version matrix update to only what that provider offers there, so you can't select an invalid combination. When you ship, Kubentic plans the full resource graph, applies it through your cloud's own APIs using the scoped, short-lived token you granted, and streams progress phase by phase. The moment the API server answers, Live Monitoring, the browser terminal and Foresight AI attach on their own, the cluster is managed from birth, not handed to a separate onboarding step.
Guided Shipping
Everything the wizard handles, so you don't have to.
No YAML, no problem
Cloud, region, version and node size, picked in a wizard that validates every step before you ship.
Every major cloud
AWS, GCP and Azure, plus self-managed, one guided flow across all of them.
Secure by construction
Networking, IAM and core add-ons ship on sane, production defaults out of the box.
Capabilities
Everything inside Guided Shipping.
Provider-aware option matrix
The wizard queries each cloud's live capability API, so the regions, machine families and Kubernetes versions you see are only what that provider supports right now. A deprecated version or an instance type absent from your chosen region is never selectable.
Private network topology, sized for you
Kubentic lays down the VPC, per-AZ subnets, route tables and NAT egress with sane CIDR sizing, so nodes and pods land in a private topology by default. You never hand-write a network block or do subnet math.
Least-privilege IAM bound at ship time
Node roles, the cluster service account, and the workload-identity binding, IRSA on AWS, Workload Identity on GCP, are created scoped to exactly what the cluster needs, not blanket admin. Your grant stays a short-lived token that Kubentic uses and discards.
Core add-ons pre-configured for real workloads
CNI, cluster DNS, the metrics server and an ingress path arrive installed and configured, so the cluster accepts workloads the instant it's live instead of being an empty control plane you still have to bootstrap.
Resumable, error-surfacing ship runs
Every phase, network, IAM, control plane, node group, add-ons, reports live in the UI and terminal. A quota cap or throttled API surfaces the exact cloud-side error at the step it hit, and you re-run without hand-cleaning half-created resources.
Self-managed, same wizard
The self-managed path stands Kubernetes up directly on your own infrastructure through the identical flow, for teams who want cluster-level control and no managed control-plane fee. The steps don't change whether you're shipping EKS, GKE, AKS or a self-managed cluster.
How it works
From sign-up to shipped in three steps.
01
Connect your cloud
Authenticate once with AWS, GCP or Azure. Kubentic stores nothing, just short-lived, scoped tokens.
02
Configure in a wizard
Pick provider, region, version and node size. Every choice is validated before you ship.
03
Ship & watch
Your environment goes live, Foresight starts watching, and the browser terminal is ready.
Built for real work
Where Guided Shipping earns its keep.
A startup with no platform team
An engineer who has never touched Terraform needs a production cluster for their first real ship. They connect AWS, answer four questions, and get a private-networked EKS cluster with scoped IAM and ingress in under 15 minutes, no tribal knowledge, no platform hire.
A mirror environment in a new region
A team expanding to eu-west needs a copy of their us-east setup on GCP for data residency. Rather than fork and edit a Terraform module, they run the same wizard against the new region and get a validated, drift-free match of the original.
A throwaway cluster for a proof of concept
A staff engineer needs a short-lived self-managed cluster to trial a workload before committing. Guided Shipping brings it up in minutes with monitoring and a terminal already attached, so evaluation starts at once and teardown is a single action later.
At a glance
The technical details.
- Clouds
- AWS, GCP, Azure + self-managed
- Cluster types
- EKS, GKE, AKS, self-managed Kubernetes
- Time to live cluster
- Under 15 minutes, end to end
- Config you write
- 0 lines of YAML or Terraform
- Cloud auth
- Scoped, short-lived tokens, nothing stored
- Networking default
- Private VPC, per-AZ subnets, NAT egress
- To shipped
- < 15 min
- Lines of YAML
- 0
- Cluster types
- 4
- Clouds
- 3
To shipped
Lines of YAML
Cluster types
Clouds
FAQ
Questions, answered.
What gets provisioned, do you touch my existing cloud resources?
Guided Shipping creates a fresh, self-contained cluster: its own VPC, subnets, NAT egress, IAM roles, control plane, node group and core add-ons. It never modifies or adopts resources you already run, Cloud Discovery maps those separately. Everything it stands up is tagged, so you can see exactly what Kubentic created.
How does cloud authentication work, and do you keep my credentials?
You authenticate once and Kubentic receives a scoped, short-lived token, an assumed IAM role on AWS, a service account on GCP, the equivalent on Azure. We provision with it and discard it; long-lived keys are never stored. The grant is scoped to the resources the wizard creates, not blanket admin.
Which Kubernetes versions and instance types can I pick?
The wizard pulls each provider's live version matrix and machine-family catalog for your selected region, so you're offered exactly what that cloud supports today, no deprecated versions, no instance types missing from that region. Provider and region filter everything downstream, so an invalid combination can't be shipped.
Is a wizard-shipped cluster production-grade, or just a demo?
Production-grade by default: private node networking across availability zones, least-privilege IAM, and core add-ons configured for real workloads. You layer your own policies and workloads on top, but you never start from an insecure or empty baseline, the defaults are the ones you'd otherwise spend a sprint hardening.
What happens if a ship fails partway through?
Each phase streams its status, so a failure, a quota cap, a throttled API, a region capacity issue, surfaces the exact cloud-side error at the step where it occurred, not a generic timeout. You fix the cause (raise the quota, pick another instance family) and re-run; Kubentic reconciles the graph rather than leaving you to clean up half-created resources.
“We went from zero to a production-grade self-managed cluster in under 15 minutes. The wizard just works, no tribal knowledge required.”
Your first environment is
15 minutes away.
No credit card. No infrastructure expertise. Just a cloud account and a browser, and you're shipping.
Free plan · No credit card · Cancel any time