Plans and Pricing

Free - $0

No credit card required.
Start for free
Highlights
  • 250+ OSS Projects & Add-ons
  • Providers: EKS, GKE, AKS, VMW Tanzu, OpenShift, Rancher, Nutanix, DIY, Self-Hosted
  • Classifiers: Deployment System, OSS Project, Package, Image
  • Risk Ledger: All Operational Risks
  • Artifact Register: Enriched inventory of Project Versions, Packages, Package Components, Deployment Systems, and Images
  • Upgrade Copilot: Upgrade Assessments
  • Up to 50 Nodes included

Business

Everything in Free, plus
Contact us
Highlights
  • Clusters: Unlimited
  • Users: Unlimited
  • Upgrade Copilot: Upgrade Templates & Plans
  • Risk Ledger: Risk API
  • PR Creator with Upgrade Context MCP Server
  • On-demand coverage of new OSS Projects
  • Integrations: Slack, Jira
  • Up to 3 Upgrade Cycles included
  • Up to 100 Nodes included (Additional nodes purchased separately)

Enterprise

Everything in Business, plus
Contact us
Highlights
  • API Access
  • SSO support
  • Custom Risk Signatures
  • Custom Deployment & Package Systems, Custom Built Images,  Additional Repositories
  • Custom Upgrade Blueprints
  • Risk Feed MCP Server
  • Integrations: GitHub, Custom
  • Custom contracts, Multi year contracts
  • Premium support response SLA
  • Dedicated account manager
  • Contractual uptime guarantee
  • Fleetwide Upgrade Templates & Upgrade Plans
  • Nodes Fleetwide nodes included
  • Volume discounts

Features

Free - $0
Start for free
Business
Book a demo
Enterprise
Book a demo
250+ Covered OSS Projects
Included
Included
Included
Networking & Connectivity
Istio, Contour, and more
Databases & Datastores
Postgres, MySQL, Elasticsearch, and more
Data Jobs
Apache Spark, Apache Stream, and more
Data Streams
Kafka, RabbitMQ, and more
Observability & Monitoring
Kube Prometheus Stack, Grafana Loki, and more
Security & IAM
Keycloak, Hashicorp Consul, and more
Node Lifecycle & AutoScaling
Karpenter, KEDA, and more
Platform Ops & Developer Tooling
ArgoCD, Argo Rollouts, Flux CD, and more
48hr SLA to Cover New OSS Projects
Covered Kubernetes Providers
Included
Included
Included
Amazon EKS, Google GKE, Azure AKS
VMW Tanzu, RedHat OpenShift, Rancher RKE, Nutanix NKP
DIY, Self-Hosted
Classifiers
Included
Included
Included
Deployment System Classifier
(i) Covers Terraform, ArgoCD, FluxCD, Helm, kubectl
Coverage for additional Deployment Systems can be requested
OSS Project Classifier
(i) Detects Image, Project Release, Project Components
Coverage for Custom Built Projects is available
Package Classifier
(i) Detects Package System (Helm, Kustomize, Kube, Terraform), Package Release, Package Components
Coverage for additional Package Systems can be requested
Image Classifier
(i) Detects OCI Registry, OCI Repository, OCI Tag, OCI Artifact
Coverage for additional repositories can be requested
Upgrade Copilot > Upgrade Assessments
  • Rapid, context-aware reports that surface all upgrade blockers, risks, and version recommendations for your cluster, add-ons and OSS projects.
K8s API Validator
Detects resources using deprecated / removed K8s APIs
PDB Validator
Flags resources using Misconfigured PDBs
Rapid Upgrade Recommender
Upgrade guardrails for EOL policies, compatibility maps, and release staleness
(i) Detects whether or not an OSS Project needs an upgrade
Recommends Rapid Source-grounded Next Versions
Tags Required vs Optional Upgrades
Action: Export Markdown
(i) Export the assessment for a Jira ticket, Wikis, Pull Requests or Coding Agents
Action: Export PDF
(i) Export the assessment as a PDF for attaching on tickets or sharing over emails
Actions: Leave Comments
Chat with Team Members
Leave Comment for Chkk
(i) Enables teams to collaborate within the context of a step in the workflow.
Actions: Customize Assessment
Add / Delete / Edit Steps
(i) Allows inclusion of steps in the workflow containing logic that is custom to your upgrade process
Action: Archive Assessment
Archive older Assessments that are not needed anymore
Activity Log
(i) Logs all actions taken on steps of an Assessment.
Artifact Register
  • Curated, Classified and Enriched Inventory For Your Fleet. Covers 100s of Open Source Software Project Versions, Packages, Package Components, Deployment Systems, and Images.
Included
Included
Included
Cluster Inventory
Version-first Inventory of Clusters & Nodes
(i) Includes all Covered Cloud & K8s Distributions.
Shows cluster Version, Environment, Region and Provider.
Overlays EOL and Extended Support / LTS information for each cluster
Project Inventory
Version-first inventory of all OSS Projects running as add-ons, application services, or operators
(i) Shows versions of Images, Project Releases, Project Components
Package Inventory
Shows inventory of Helm charts, Kustomize Overlay Directories, Kube Manifests, Terraform Packages
(i) Shows Package System (Helm, Kustomize, Kube, Terraform), Package Releases, Package Components
Cloud Account Register
Shows inventory of Cloud Accounts hosting clusters
(i) A minimal-permission, read-only IAM role reads cloud account metadata to enable cross-layer risk detection and automated pre/postflight checks
EOL Watchdog
Notifies 90d before any OSS Project hits EOL. Overlays EOL information on each Project version.
(i) Flags components approaching end-of-life or running known-bad versions the moment upstream publishes them
Compatibility Watchdog
Notifies instantly if a Project or Node is incompatible with K8s.
(i) Flags any Project that is incompatible with the running K8s version.
Flags version skew for Nodes and kubelets.
Flags incompatibilities across Projects--e.g. Istio<>Envoy, Containerd<>CNI, etc
Cost Spike Monitor
Notifies of upcoming 6x cost spike for clusters approaching EKS/GKE Extended Support or AKS Long Term Support (LTS)
(i) Notifies 90d earlier that clusters coming close to EKS/GKE Extended Support or AKS LTS will incur 500% more surcharges. Also reminds 1wk before the deadline.
Froced Upgrade Risk Notifier
(i) Detects OCI Registry, OCI Repository, OCI Tag, OCI Artifact
Custom Package Classifier
(i) Detects OCI Registry, OCI Repository, OCI Tag, OCI Artifact
Custom Image Classifier
(i) Detects OCI Registry, OCI Repository, OCI Tag, OCI Artifact
Request Project Coverage
(i) Detects OCI Registry, OCI Repository, OCI Tag, OCI Artifact
Request Cloud / K8s Distribution Coverage
(i) Detects OCI Registry, OCI Repository, OCI Tag, OCI Artifact
Compliance Reports
Share inventory summaries with compliance teams
(i) Share near-real-time reports with compliance teams that the platform software isn't running any EOL software
Proxy Filter
Redacts any configuration line from processing
(i) Fine-granular control over your entire configuration tree so you can redact any part of the tree that should not be processed by Chkk
Risk Ledger
  • Scans the Kubernetes configuration for at-risk components
  • Proactively surfaces hidden misconfigurations, version incompatibilities, end-of-life risks, and known defects.
  • Risk Signatures scan your infrastructure, identify issues that need attention, and prescribe mitigation and remediation workflows.
Included
Included
Included
Defects
Detects Opertional Risks that have caused breakages or disruptions for other teams
(i) Scans the Kubernetes configuration for at-risk components.
All Defects have an associated KBA which provides:
Affected Resources
Severity (Critical, High, Medium, Low)
Impact assessment
Trigger conditions that activate the risk
Mitigation (or short-term workaround)
Remediation (or long-term fix)
Code snippets for remediations and mitigations, when applicable
EOL Versions
Shows EOL Watchdog's output in a component-first view
(i) All EOL risks have an associated KBA with external sources and affected resources
Incompatibilities
Shows Compatibility Watchdog's output in a component-first view
(i) All Compatibility risks have an associated KBA with external sources and affected resources
Misconfigurations
Shows misconfigurations that can cause breakages or block upgrades.
(i) All Misconfigurations have an associated KBA which provides:
Affected Resources
Severity (Critical, High, Medium, Low)
Impact assessment
Trigger conditions that activate the risk
Mitigation (or short-term workaround)
Remediation (or long-term fix)
Code snippets for remediations and mitigations, when applicable
Deprecations
Shows output of K8s API Validator and deprecated CRDs and operator-specific APIs in OSS Projects.
(i) All Deprecations have an associated KBA which provides:
Affected Resources
Severity (Critical, High, Medium, Low)
Impact assessment
Trigger conditions that activate the risk
Mitigation (or short-term workaround)
Remediation (or long-term fix)
Code snippets for remediations and mitigations, when applicable
Guardrails
Shows rules, policies and best practices from a cloud provider, add-on vendor, kubernetes distribution, or the open source community.
(i) All Guardrails have an associated KBA which provides:
Affected Resources
Severity (Critical, High, Medium, Low)
Impact assessment
Trigger conditions that activate the risk
Mitigation (or short-term workaround)
Remediation (or long-term fix)
Code snippets for remediations and mitigations, when applicable
Action: Ignore Risk
Stops detection and notification of acceptable risks
(i) Risks can be ignored on a per-cluster or per-resource level, from the KBA page or through IaC annotations
Action: Mark Risk
Marks risks with additional context--comments for team, won't fix (by design, dev/test clusters, etc.)
Action: Create Ticket
Opens Jira tickets from an Operational Risk's KBA page
Risk API
Vends Operational Risks on an API see more   
(i) Allows filtering by risks, clusters and resources. Enables risk routing to platform and application teams.
Upgrade Copilot > Upgrade Templates & Upgrade Plans
  • AI-curated workflows that encode the safest upgrade path for any cluster, add-on or OSS project.
As many as you need for 3 fleetwide Upgrade Cycles
Additional Upgrade Cycles can be purchased separately
  • Includes Cluster Upgrade Templates and Add-on Upgrade Templates
Read FAQ about what comprises an Upgrade Cycle
As many as you need for your fleet's upgrades
Deep Upgrade Analyzer
Provides Verified Next Version Recommendations, Change Reasoning, Safety Checks, and Upgrade Instructions
(i) Recommends and preverifies on a Digital Twin the safest next version on a Digital Twin
Detects whether an upgrade involves single or multiple hops
Tags required vs optional upgrades based on change reasoning
Links to authoritative upstream notes for every recommendation
Upgrade Blueprints
In-place, Blue-Green, Rolling
Custom Blueprints
Breaking Changes & Upgrade Considerations
For Control Planes, Worker Nodes, Images (AMIs, COS, Node Images), all Covered OSS Projects
(i) Curated from Changelogs, Upgrade Guides / Notes, and Official Blogs.
Contextualized for your environment
Upgrade Advisories
Issues and considerations discovered during Preverification
(i) AI agents find issues not mentioned in Changelogs via deep research and by executing the recommended upgrade path on a Digital Twin
Notable Features & Critical Bug Fixes
For the recommended upgrade path
Guardrails
Shows rules, policies and best practices from a cloud provider, add-on vendor, kubernetes distribution, or the open source community.
(i) All Guardrails have an associated KBA which provides:
Affected Resources
Severity (Critical, High, Medium, Low)
Impact assessment
Trigger conditions that activate the risk
Mitigation (or short-term workaround)
Remediation (or long-term fix)
Code snippets for remediations and mitigations, when applicable
K8s API Validator
Detects resources using deprecated / removed K8s APIs
PDB Validator
Flags resources using Misconfigured PDBs
Upgrade Readiness Insights
Pulls upgrade readiness insights from AWS Upgrade Insights, GKE Recommender, Azure Advisor / Diagnosis
(i) Shows information provided by cloud providers about deprecated/removed API usage, control plane EOL, version skew (nodes, kubelet, kube-proxy, etc.)
Helm, Kustomize, Manifest Diffs
Provides ready-to-apply IaC diffs for Terraform, Helm and Kustomize
(i) Inline, annotated diffs show exactly what will change in Helm values, Kustomize overlays, Argo-CD app-sets, or raw YAML, eliminating manual side-by-side reviews and silent drift
RBAC Diffs
Shows newly introduced privileges or deprecated fields across all environments
(i) Audits RBAC additions or removals so required permissions evolve with every upgrade.
CRD Diffs
Surfaces changes in CRDs and their associated CRs to prevent breaking API contracts
(i) Compares old vs. new CRD schemas and every stored Custom Resource, guiding safe migrations and avoiding validation errors.
Actions: Customize Template / Plan
Add / Delete / Edit Steps
(i) Allows inclusion of steps in the workflow containing logic that is custom to your upgrade process
Actions: Leave Comments
Chat with Team Members
Leave Comment for Chkk
(i) Enables teams to collaborate within the context of a step in the workflow.
Action: Mark Plan / Template
Mark a Template as Approved (for use in Plans), Cluster Completed, Environment Upgraded, Canceled
Activity Log
(i) Logs all actions taken on steps of an Assessment.
Guided Preflight, Inflight, Postflight Checks
Provides ready-to-execute safety, health and readiness checks for each Kubernetes and add-on version
(i) Covers smoke tests, API readiness checks, and end-to-end checks, streams results into the Template workflow.
Preview
SHARC: Automated Safety, Health & Readiness Checks
Provides contrainerized, end-to-end safety checks, reports results in Upgrade Plans
Action: Can be triggered from Upgrade Plans or from CI/CD jobs
(i) Containerized, contextualized checks that can be seamlessly integrated with Upgrade Plans or run in CI/CD jobs.
Preview
Change Management Artifacts
Provides context on what, why and how of every single change. Ready for use in Change Management Tickets, PRs, Slack threads.
(i) Markdown-formatted context on the rationale of what change is proposed, why the change is required, and how the change reduces blast radious and improves safety.
Used by QA and compliance teams with extended stability guarantees--e.g. financials, healthcare, etc.
Live Workflow
Assigns owners, tracks lifecycle of the upgrade, preserves a full audit trail
(i) Assigns owners, sets actions, tracks lifecycle of each workflow step (completed, in-progress, skipped), manages lifecycle of the upgrade across all clusters in an environment (% completed)
Upgrade System of Record
Stores all actions, customizations, and learnings.
(i) Eliminates any additional work required to log these aspects in wikis or docs post upgrades.
AI Capabilities
Risk Feed MCP Server
Vends Operational Risks on an MCP Server
(i) Allows filtering by risks, clusters and resources. Enables risk routing to platform and application teams
Preview
PR Creator with Upgrade Context MCP Server
Vends Environment-aware Upgrade Context for 100s of Open Source Projects to your AI coding agent
    Works with: Cursor, Claude Code, CodeX, Gemini CLI, GitHub Copilot
    Creates PRs for: Helm, Terraform, Kustomize, Libsonnet and more
Integrations
Slack
Notifies of risks and upgrade lifecycle events on Slack channels
Jira
Opens tickets for Operational Risk resolution or upgrade tasks
GitHub
Reads IaC code and enables Chkk Coding Assistant to open PRs
Custom Integrations
SSO
Okta, PingIdentity
Contracts
Custom contracts, Multi year contracts
Contractual uptime guarantee
Support
Basic
Business Hours: 0500-1700 Mon-Fri (GMT-8), 24x7 for P0
Response Time: P0: 1 hour, P1: 4 business hours, P2: 1 business day, P3: 2 business days
Channels: Community Slack, Docs, Knowledge Base
Premium Support can be purchased with Business
Premium
24x7
Response Time: P0: 30 minutes, P1: 1 hour, P2: 4 hours, P3: 1 day
Channels: Private Slack Channel, Phone, Video, Email, Docs, Knowledge Base
Dedicated Account Manager

Marketplaces

Chkk

Sign up

AWS

Explore

Google Cloud

Explore

FAQs

What is the definition of a node?

What is the difference between Business and Enterprise?

What comprises an upgrade cycle?

Do you offer volume discounts?

What happens if my nodes auto-scale?

What if I exceed the nodes included in my subscription?

Don’t pay 500% surcharge for running outdated versions

Upgrade your outdated versions
Chkk helps you upgrade safely and quickly, saving you time and money
Upgrade Advisory

Upgrade Advisory: Missing External Service Metrics After Istio v1.22 → v1.23 Upgrade

by
Muneeb Ahmad
Read more
Spotlight

Spotlight: Simplifying Keycloak Upgrades with Chkk

by
Chkk Team
Read more
Operational Safety

A Practitioner's Taxonomy of Infrastructure‑as‑Code (IaC) Patterns in the Wild

by
Fawad Khaliq
Read more
News

EKS v1.27 EOL and v1.30 Extended Support: Upgrade Deadlines, Costs & Risks

by
Chkk Team
Read more
Hidden Toil

Why Upgrades Are Delayed: The Real, Human, Practical Reasons

by
Awais Nemat
Read more
Spotlight

Spotlight: Seamless Self-Managed Grafana Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: CoreDNS Upgrades with Chkk

by
Chkk Team
Read more
Technology

Karpenter vs. Cluster Autoscaler

by
Chkk Team
Read more
Spotlight

Spotlight: Simplifying Contour Upgrades with Chkk

by
Chkk Team
Read more
Hidden Toil

5 Reasons Why Delaying Open Source Software Upgrades Is a Bad Idea

by
Awais Nemat
Read more
Spotlight

Spotlight: Seamless cert-manager Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Argo Rollouts Upgrades with Chkk

by
Chkk Team
Read more
Upgrade Advisory

Upgrade Advisory: Pods Stuck in Pending During Kubelet v1.30 → v1.31 Upgrade

by
Chkk Team
Read more
Spotlight

Spotlight: Simplifying Self-Managed Apache Kafka Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Seamless Calico Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: NGINX Ingress Controller Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: KEDA Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Streamlining Prometheus Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: RabbitMQ Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Seamless Kyverno Upgrades with Chkk

by
Chkk Team
Read more
News

Google Container Registry Deprecation 2025: How to Migrate to Artifact Registry

by
Chkk Team
Read more
Spotlight

Spotlight: HashiCorp Vault Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Streamlining Crossplane Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Seamless External DNS Upgrades with Chkk

by
Chkk Team
Read more
Case Study

How Dexcom Derisked GKE Upgrades and Sped Them Up by 5x using Chkk

by
Chkk Team
Read more
Case Study

Assuring Compliance and Availability for Yoti’s On-Prem Platform with Chkk

by
Chkk Team
Read more
Case Study

How a Fortune 500 Enterprise Avoided $500K in EKS Extended Support Fees, Achieved 80% Reduction in Prep Time, and Boosted Upgrade Productivity by 200%

by
Chkk Team
Read more
Case Study

How a Fortune 1000 Enterprise Standardized Multi-Cloud (EKS & GKE) Upgrades for 30+ Add-Ons, Avoided 6x Costs, and Achieved an 80% Reduction in Prep Time

by
Chkk Team
Read more
Spotlight

Spotlight: Upgrading Self-Managed Redis

by
Chkk Team
Read more
Spotlight

Spotlight: Simplifying Self-Managed Elasticsearch Upgrades with Chkk

by
Chkk Team
Read more
News

GKE & EKS Extended Support: Are 6x Fees for Supporting Older Kubernetes Versions Justified?

by
Ali Khayam
Read more
Spotlight

Spotlight: Seamless Karpenter Upgrades with Chkk

by
Chkk Team
Read more
Operational Safety

Forced EKS & GKE Upgrades: How to Manage Business Continuity Risks

by
Fawad Khaliq
Read more
Spotlight

Spotlight: How Chkk Streamlines & Safeguards Cilium Upgrades

by
Chkk Team
Read more
Technology

Kubernetes Admission Controllers and Webhooks Deep Dive

by
Chkk Team
Read more
Spotlight

Chkk Spotlight: Istio

by
Chkk Team
Read more
Technology

Pod Disruption Budgets: Pitfalls, Evictions & Kubernetes Upgrades

by
Chkk Team
Read more
Technology

cgroup v1 to v2 Migration in Kubernetes

by
Chkk Team
Read more
Operational Safety

OpenAI’s Outage: The Complexity and Fragility of Modern AI Infrastructure on Kubernetes

by
Fawad Khaliq
Read more
News

EKS launches Auto Mode… How can you adopt it?

by
Ali Khayam
Read more
Change Safety

CrowdStrike outage was the symptom; missing Operational Safety was the cause

by
Fawad Khaliq
Read more
News

GKE Follows EKS & AKS, Launches Extended Support with a 500% Surcharge for Delayed Upgrade

by
Ali Khayam
Read more
News

AKS Long Term Support and EKS Extended Support: Similarities & Differences

by
Ali Khayam
Read more
News

Amazon launches EKS extended support… How does it impact you?

by
Ali Khayam
Read more
Platform Engineering

Platform teams need a delightfully different approach, not one that sucks less

by
Fawad Khaliq
Read more
Technology

Kubernetes Enters Its Second Decade: Insights from KubeCon Chicago

by
Fawad Khaliq
Read more
Company

Launching Chkk Operational Safety Platform

by
Awais Nemat
Read more
Technology

What Makes Kubernetes Upgrades So Challenging?

by
Fawad Khaliq
Read more
Company

4 Lessons from our SOC2 Journey

by
Fawad Khaliq
Read more
Technology

Collective Learning: The Power of Not Repeating Others’ Mistakes

by
Ali Khayam
Read more
Technology

From Fighting Fires to Availability Assurance

by
Fawad Khaliq
Read more
Company

Welcome to Chkk

by
Awais Nemat
Read more