Security sentinel for AWS and Kubernetes

Something has to stay awake.

Firekeeper watches your AWS accounts and EKS clusters from inside your own cluster. It reads through read-only roles, keeps a receipt for every read, and reports only what it can prove.

curl -fsSL https://firekeeper.sh/install | sh

Not released There is no release yet. Today the script prints the status and changes nothing.

Two natures

Still by default.

Firekeeper has two natures. Watch is the default. Defend is optional and in development.

Watch

Default

It reads. It does not write.

Read-only. On a schedule, Firekeeper reads your AWS accounts and clusters through read-only roles and keeps a receipt for every read. Rules turn the evidence into findings, and every finding links to the records that prove it.

  • Read-only roles that you create
  • A receipt for every read
  • Each run says what it could not check

Defend

In development

It acts only when you say so.

Optional runtime defense: a small set of reversible actions, each signed by an operator and recorded. It is not built yet.

  • Off unless you turn it on
  • Every action reversible
  • Every action signed by an operator and recorded

How it works

Collect. Prove. Tell.

  1. Collect

    On a schedule, the hub reads each account and cluster through the read-only roles you created. Every read leaves a receipt.

  2. Prove

    Rules turn evidence into findings. Every finding links to the records that prove it. A run also states plainly what it could not check.

  3. Tell

    One AI model writes up the findings. A second model, from a different maker, has one job: to refute the first. If that check fails, the report falls back to the rules alone.

Yours to run

It runs in your cluster, under your roles.

Self-hosted

Firekeeper runs inside your own cluster under roles you create. Every permission it holds is one you granted.

No phone-home

Your license is a signed file, checked offline when Firekeeper starts. Nothing calls back to us.

One install per estate

An estate is one AWS organization and the EKS clusters in it. One hub watches the whole estate.