Docs
Concepts
Watch and Defend, evidence and receipts, findings, and what a run reports it could not check.
On this page
A few words carry most of the meaning in Firekeeper. This page defines them.
Estate and hub
An estate is one AWS organization and the EKS clusters in it. The hub is the one Firekeeper install that watches the whole estate. There is one install per estate, and a license names the estate it is for.
Watch and Defend
Firekeeper has two natures.
Watch is the default. It is read-only. It reads your accounts and clusters, records what it read, and reports what it can prove. It cannot change your resources, because the roles you give it do not allow writes.
Defend is optional runtime defense: a small set of reversible actions, each signed by an operator and recorded. Defend is in development and not built. Until it ships, Firekeeper is Watch only.
Still by default. It acts only when you say so.
Evidence and receipts
Evidence is what Firekeeper reads from your accounts and clusters through its read-only roles.
A receipt is the record of a single read. Firekeeper keeps one for every read it makes. Receipts let you see exactly what was read to reach a conclusion. What keeps Watch from writing is the read-only roles, not the receipts.
Findings
A finding is a conclusion that rules reach from evidence. Rules decide what is a finding. The AI models do not.
Every finding links to the records that prove it. If the evidence does not prove something, Firekeeper does not report it. You can follow any finding back to the reads behind it.
How a finding is written up
- Rules produce the findings and the records behind each one.
- One AI model writes up the findings in plain language.
- A second model, from a different maker, checks the write-up. Its only job is to refute the first.
- If the check fails, the report falls back to the rules alone.
The write-up is there to make findings easier to read. The findings, and the records behind them, come from the rules.
Runs
A run is one pass over your estate. Runs happen on a schedule.
Every run states plainly what it could not check. If a role is missing or a cluster cannot be reached, the run says so instead of passing over it. An account that was not checked is always named as not checked.
Licenses
A license is a signed file that names your estate. Firekeeper checks it offline when it starts. See Licensing.