Docs
Overview
What Firekeeper is, what it does by default, and what is not built yet.
On this page
Firekeeper is a security sentinel for AWS and Kubernetes (EKS). It is self-hosted: it runs inside your own cluster, under roles you create. Nothing runs on our side.
Firekeeper is not released. There is no installer, no image and no release yet. These docs describe how it works and what an install will need, so you can judge it before it ships.
What it does
By default Firekeeper has one nature, called Watch. Watch is read-only.
- On a schedule, it reads your AWS accounts and EKS clusters through read-only roles that you create.
- It keeps a receipt for every read.
- Rules turn the evidence into findings.
- Every finding links to the records that prove it. If it cannot prove something, it does not report it.
- Every run states plainly what it could not check.
Findings are written up by one AI model and checked by a second model from a different maker, whose only job is to refute the first. If the check fails, the report falls back to the rules alone.
One install per estate
An estate is one AWS organization and the EKS clusters in it. You install Firekeeper once per estate. One hub watches the whole estate.
What it does not do
- In Watch, it does not change your resources. The roles you give it are read-only.
- It does not phone home. Your license is a signed file checked offline when Firekeeper starts.
- It does not report what it cannot prove.
What is not built yet
Defend is a second, optional nature: a small set of reversible actions, each signed by an operator and recorded. It is in development. Nothing in these docs depends on it, and no install will turn it on.
Where to go next
- Concepts: Watch and Defend, evidence and receipts, findings and runs.
- Security model: what Firekeeper can touch, and what leaves your estate.
- Licensing: the license file, how it is checked, how to get one.
- Install: what an install will need, and what the installer will and will never do.