Quickstart
Install Telark, sign in as the first admin, and watch a protection plan record a change. About ten minutes.
You install Telark with one Helm command, enrol yourself as the first admin, and run a protection plan in audit mode against a demo application.
Time: about 10 minutes, most of it waiting for images to pull.
Prerequisites
| You need | Detail |
|---|---|
| Kubernetes | 1.30 or newer (1.33+ is the tested target) |
| Helm | 3.x |
| Access | cluster-admin for the install: the chart registers CRDs, ClusterRoles and admission policies |
| Storage | A ReadWriteMany StorageClass (efs-sc on EKS). On a single-node cluster, use --set app.singleNode=true instead and any class works |
kubectl | Pointed at the cluster |
Full list: System requirements.
1. Install the chart
Replace <rwx-class> with your StorageClass and you@example.com with your email:
helm install telark oci://ghcr.io/telark/charts/telark -n telark --create-namespace \
--set app.persistence.storageClass=<rwx-class> \
--set 'app.auth.bootstrap.admins={you@example.com}'On a single-node cluster (kind, minikube, k3d), replace the first --set with --set app.singleNode=true.
The admin email is required. Passkey self-registration is off by default, so without a bootstrap admin nobody could sign in and the chart refuses to render.
2. Check that it is running
kubectl get pods -n telark
helm test telark -n telarkYou should see every pod Running and READY, and helm test should end with Phase: Succeeded. The test calls each service's readiness route and checks that the telark.io API group is served.
3. Enrol the first admin
Create your account and a one-time enrolment token:
kubectl exec -n telark deploy/telark-auth-service -- ./main break-glass --email you@example.com --enrollYou should see a line like enrollment token for you@example.com (expires …): <token>. The token is valid for 10 minutes.
4. Open the dashboard and register a passkey
kubectl port-forward -n telark svc/telark-ui-service 3000:8080Open http://localhost:3000/register?enroll=<token> and register a passkey. Passkeys need a secure origin; http://localhost counts as one.
You should land on the dashboard signed in with the Admin role.
5. Deploy a demo application
kubectl create namespace demo
kubectl create deployment web --image=nginx -n demoOpen Applications. Within a minute you should see an application named web in the demo namespace. Telark grouped the Deployment by its app label.
6. Create a protection plan in audit mode
- Open Protection plans and choose Create Plan.
- Details: name it
quickstart. Leave the environment empty (not Production) and execution on Automatic. - Scope: choose Applications and select
web. - Policies: keep the mode on Audit and add the
block-replica-scalingtemplate. - Schedule: choose Permanent.
- Choose Create Plan.
You should see the plan in phase active. Open it: within about 30 seconds the Health panel reads Healthy, which means Telark found the Kyverno policy it expected in the cluster.
7. Make a change the plan would block
kubectl scale deployment web -n demo --replicas=3In audit mode the change goes through. Refresh the plan's Violations section: you should see one row for web reading Replica scaling would be blocked by protection plan "<plan-id>". In enforce mode the same command fails at admission with Replica scaling is blocked by protection plan "<plan-id>".
Open the web application: its history shows the scaling change and a snapshot you can roll back to.
Clean up
Cancel the plan from its detail page, then kubectl delete namespace demo. To remove Telark, see Uninstall Telark.
Next
- Roll back an application to the snapshot you just created.
- Create a protection plan for a real window, with approval.
- Install for production: sizing, an HTTPS hostname, and Google sign-in.