The chat can't change anything
The assistant's write commands are blocked. When it finds a fix, you get a button with the exact command on it, not a change that already happened.
Giving any tool access to your cluster is a real decision, so here's exactly how Rigel works. It runs on your own Mac, it asks before it changes anything, and it never reports back to us.
Rigel can dig through your cluster and suggest fixes, but it doesn't make the change itself. It hands you the exact command and waits for you to click.
The assistant's write commands are blocked. When it finds a fix, you get a button with the exact command on it, not a change that already happened.
Anything that touches the cluster shows you the exact command and waits for you to say yes.
Live cluster data comes in over a read-only stream. Changes go through a different, guarded path that only you trigger.
Rigel isn't a server you have to stand up and protect. It's an app on your machine that talks to your clusters directly, so there's nothing exposed to the internet.
It's an app on your machine, not a server. Nothing listens on the network, so there's no public surface to attack.
Rigel reaches your clusters from your Mac using the kubeconfig you already have. There's no Rigel server in the middle to lock down.
Rigel acts as you. If your kubeconfig and your cluster's RBAC don't allow something, neither does Rigel.
Pick a namespace and the whole app narrows to it. Your cluster's RBAC still applies on top of that.
Rigel runs on your Mac. The only thing that ever leaves is what you choose to send to the AI, using your own key.
Rigel runs on your Mac and uses your kubeconfig to reach your clusters directly. There's no Rigel server in between.
No analytics, no tracking, no phone-home. We don't see anything about your cluster.
Chat uses an AI key you provide. That's the one place your cluster's details ever leave your machine.
Alerts go out through a Signal bridge you run yourself, not a third-party paging service.
The optional agent that fixes things while you're away only works inside the limits you set, and it keeps a record of everything it does.
A hard dollar limit on what the agent can spend on its own.
Turn it off whenever you want. If it can't even read its own config, it shuts itself down rather than guess.
It only acts in the namespaces you've put on its allowlist.
The agent runs inside an RBAC cage that leaves Secrets out entirely. It can't read them, so it can't leak them.
It snapshots a resource's YAML before changing it, so nothing it does is one-way.
Every action is recorded with a before-and-after, so you can roll it back.
Download Rigel and connect your first cluster in a couple of minutes. Free while in beta.
Windows and Linux All downloads ↗