FOR PLATFORM + DEVOPS TEAMS, AND VENDORS SHIPPING INTO CUSTOMER CLOUDS

DevOps, BYOC, Air-Gap at Scale.

Bring Your Own Cloud means your product runs on infrastructure you do not operate: a customer's VPC, a partner's cluster, an air-gapped site. CI cannot push there, and once it ships nobody can say which version is live. ReARM holds the plan; ReARM CD inside each cluster pulls it, applies it, and reports back.

HOW TEAMS USE ReARM FOR THIS
01

Each target is an instance

Every cluster, namespace or site you deploy into is registered as an instance in ReARM, grouped into clusters, with its own secrets and configuration. Customer infrastructure becomes a first-class object in ReARM.

↳ Deployment Model
02

Ship by pointing, not pushing

A feature set pins the exact component and product releases that ship together. Point an instance at it and ReARM records the target. Nothing is pushed from CI, and no CI credentials ever reach the customer's cloud.

↳ Feature Sets
03

ReARM CD pulls it in

A small open-source agent installed in the customer's cluster connects outbound to ReARM, watches the instance's target, reconciles the running workloads to match, and reports what actually landed. Sensitive configuration is transmitted securely: encrypted for that cluster alone, so only it can open it.

↳ ReARM CD
04

Promotion follows approvals

Which releases each environment takes is configurable per environment: for example, test instances take every release while staging and production take only releases that passed the approval gates you define. Promotion is a change of target in ReARM, and rollback is the previous feature set.

↳ Release Policies
05

Plan versus actual, per instance or per customer

Every instance shows expected against observed state side by side. When a cluster drifts, a manual hotfix or a failed rollout, it is visible immediately, not at the next support call.

↳ Drift Detection
06

Evidence follows the deployment

What was approved, what was targeted, what ran and when, per instance, in one immutable history. The SBOM, findings and approvals attached to a release travel with it into the deployment record.

↳ Audit Evidence
07

Air-gapped sites

Where nothing can connect, the release goes out instead of the agent coming in. The CLI resolves which release an environment is cleared for under your approvals, packages it with its artifacts and evidence as a bundle you carry across the gap, and ReARM records the transfer against the site, as a distribution target or a placeholder instance, so what landed there is still on record.

↳ Distribution

NOTE: Instances, secrets, feature-set deploys and ReARM CD control are part of ReARM Pro.

SCREENSHOT 8: instances page, plan vs actual side by side
EVIDENCE
Plan vs ActualDrift Detection
INSTANCES · ENVIRONMENTS · FEATURE-SET TARGETING · RUNTIME EVIDENCE

See your releases the way ReARM sees them.