How ready are your agents for a bad day? Get your score

Image catalog

The set of images anyone can run is a list somebody approved.

WhereConsoleTerraform

Introduced Aug 4, 2026

workspace
Your devcontainer. Where work happens.
agent_runtime
Claude Code, Codex, agn, or yours.
mcp
One per tool, with its own secrets.
public / internaltag filtersregistry creds as secrets
Runnerscluster-scopedorg-scoped

How it works

Three slots.

Workspace, agent runtime, and MCP images register separately, with per-organization visibility and tag filters that keep release channels in front of people.

A list somebody approved.

Environments and agents choose from the catalog, not from arbitrary registry strings — and versions are discovered from the registry, not typed.

Credentials stay out of the cluster.

Registry credentials are stored write-only, and every pull goes through the platform's image proxy — they never reach the cluster that runs the workload.

See it on your own cluster.

Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.