DevOps, BYOC, Air-Gap at Scale.
Bring Your Own Cloud means your product runs on infrastructure you do not operate: a customer's VPC, a partner's cluster, an air-gapped site. CI cannot push there, and once it ships nobody can say which version is live. ReARM holds the plan; ReARM CD inside each cluster pulls it, applies it, and reports back.
Each target is an instance
Every cluster, namespace or site you deploy into is registered as an instance in ReARM, grouped into clusters, with its own secrets and configuration. Customer infrastructure becomes a first-class object in ReARM.
↳ Deployment ModelShip by pointing, not pushing
A feature set pins the exact component and product releases that ship together. Point an instance at it and ReARM records the target. Nothing is pushed from CI, and no CI credentials ever reach the customer's cloud.
↳ Feature SetsReARM CD pulls it in
A small open-source agent installed in the customer's cluster connects outbound to ReARM, watches the instance's target, reconciles the running workloads to match, and reports what actually landed. Sensitive configuration is transmitted securely: encrypted for that cluster alone, so only it can open it.
↳ ReARM CDPromotion follows approvals
Which releases each environment takes is configurable per environment: for example, test instances take every release while staging and production take only releases that passed the approval gates you define. Promotion is a change of target in ReARM, and rollback is the previous feature set.
↳ Release PoliciesPlan versus actual, per instance or per customer
Every instance shows expected against observed state side by side. When a cluster drifts, a manual hotfix or a failed rollout, it is visible immediately, not at the next support call.
↳ Drift DetectionEvidence follows the deployment
What was approved, what was targeted, what ran and when, per instance, in one immutable history. The SBOM, findings and approvals attached to a release travel with it into the deployment record.
↳ Audit EvidenceAir-gapped sites
Where nothing can connect, the release goes out instead of the agent coming in. The CLI resolves which release an environment is cleared for under your approvals, packages it with its artifacts and evidence as a bundle you carry across the gap, and ReARM records the transfer against the site, as a distribution target or a placeholder instance, so what landed there is still on record.
↳ DistributionNOTE: Instances, secrets, feature-set deploys and ReARM CD control are part of ReARM Pro.
