Get started

Quickstart

Install Telark, sign in as the first admin, and watch a protection plan record a change. About ten minutes.

You install Telark with one Helm command, enrol yourself as the first admin, and run a protection plan in audit mode against a demo application.

Time: about 10 minutes, most of it waiting for images to pull.

Prerequisites

You needDetail
Kubernetes1.30 or newer (1.33+ is the tested target)
Helm3.x
Accesscluster-admin for the install: the chart registers CRDs, ClusterRoles and admission policies
StorageA ReadWriteMany StorageClass (efs-sc on EKS). On a single-node cluster, use --set app.singleNode=true instead and any class works
kubectlPointed at the cluster

Full list: System requirements.

1. Install the chart

Replace <rwx-class> with your StorageClass and you@example.com with your email:

helm install telark oci://ghcr.io/telark/charts/telark -n telark --create-namespace \
  --set app.persistence.storageClass=<rwx-class> \
  --set 'app.auth.bootstrap.admins={you@example.com}'

On a single-node cluster (kind, minikube, k3d), replace the first --set with --set app.singleNode=true.

The admin email is required. Passkey self-registration is off by default, so without a bootstrap admin nobody could sign in and the chart refuses to render.

2. Check that it is running

kubectl get pods -n telark
helm test telark -n telark

You should see every pod Running and READY, and helm test should end with Phase: Succeeded. The test calls each service's readiness route and checks that the telark.io API group is served.

3. Enrol the first admin

Create your account and a one-time enrolment token:

kubectl exec -n telark deploy/telark-auth-service -- ./main break-glass --email you@example.com --enroll

You should see a line like enrollment token for you@example.com (expires …): <token>. The token is valid for 10 minutes.

4. Open the dashboard and register a passkey

kubectl port-forward -n telark svc/telark-ui-service 3000:8080

Open http://localhost:3000/register?enroll=<token> and register a passkey. Passkeys need a secure origin; http://localhost counts as one.

You should land on the dashboard signed in with the Admin role.

5. Deploy a demo application

kubectl create namespace demo
kubectl create deployment web --image=nginx -n demo

Open Applications. Within a minute you should see an application named web in the demo namespace. Telark grouped the Deployment by its app label.

6. Create a protection plan in audit mode

  1. Open Protection plans and choose Create Plan.
  2. Details: name it quickstart. Leave the environment empty (not Production) and execution on Automatic.
  3. Scope: choose Applications and select web.
  4. Policies: keep the mode on Audit and add the block-replica-scaling template.
  5. Schedule: choose Permanent.
  6. Choose Create Plan.

You should see the plan in phase active. Open it: within about 30 seconds the Health panel reads Healthy, which means Telark found the Kyverno policy it expected in the cluster.

7. Make a change the plan would block

kubectl scale deployment web -n demo --replicas=3

In audit mode the change goes through. Refresh the plan's Violations section: you should see one row for web reading Replica scaling would be blocked by protection plan "<plan-id>". In enforce mode the same command fails at admission with Replica scaling is blocked by protection plan "<plan-id>".

Open the web application: its history shows the scaling change and a snapshot you can roll back to.

Clean up

Cancel the plan from its detail page, then kubectl delete namespace demo. To remove Telark, see Uninstall Telark.

Next