Evidence tier Source Confirmed · 3 captures on record
What the publisher says
As described on AWS Marketplace.
Clu is an agentic AI-powered operations platform for Kubernetes, built for platform engineers and SREs who run production clusters. Unlike SaaS observability tools, Clu runs entirely inside your cluster - telemetry, chat context, and generated artifacts never leave your AWS account. Inference runs on your own Amazon Bedrock, so your data and your model stay under your IAM boundary.
Three modules stack to fit your team's scope. Cluster Agent (always on) handles Kubernetes troubleshooting, automatic knowledge-graph scanning, scheduled health reports, convention detection, and Prometheus + CloudWatch integration. Cloud Agent adds IAM and IRSA mapping, managed-service discovery (RDS, ElastiCache, S3, ECR), VPC topology, cost analysis, and Terraform generation for AWS resources. IDP Platform adds application scaffolding, manifest generation, Helm golden paths, and safe write operations - every change dry-runs first and requires explicit operator approval before it lands.
Show the rest of the publisher’s description (2 more lines)
Safety is a first-class invariant: protected namespaces (kube-system, kube-public, and any flagged by policy) are hardcoded and cannot be overridden by configuration. Writes go through a two-step gate - the agent produces a dry-run and diff, parks the request in an approval queue visible in the in-cluster UI, and only executes after an operator explicitly clicks Approve. Every approved action is logged with the operator's identity for audit review.
Deployed as a single pod with a browser UI reachable via kubectl port-forward or your own ingress, Clu runs on both AMD64 and Graviton (ARM64) from day one, connects to Bedrock via IRSA or EKS Pod Identity, and requires no outbound network beyond Bedrock itself - air-gap friendly for regulated environments.
Highlights
Highlighted by the publisher on AWS Marketplace.
Your cluster telemetry and chat context never leave your AWS account. Inference runs on your own Amazon Bedrock, scoped by IAM. No SaaS control plane, no third-party data collection, no outbound dependency beyond Bedrock itself. Air-gap friendly for regulated and FedRAMP environments.
Every write produces a dry-run and diff, lands in an approval queue, and only executes after an explicit operator click. Protected namespaces are hardcoded - no config can override them. Every approved action is logged with operator identity, so you always know who applied what and when.
Start with Cluster Agent for Kubernetes troubleshooting on any conformant cluster. Add Cloud Agent for AWS inventory, IRSA mapping, and cost analysis. Add IDP Platform for scaffolding, golden paths, and gated write operations. Each module is independently licensable - pay for what you actually use.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
1 listed- UnitHrs
Refund terms
As stated by the publisher on AWS Marketplace.
Clu offers a 30-day free trial to evaluate functionality prior to paid usage. Refunds for paid hourly charges are considered case-by-case for: (1) sustained product defects preventing core functionality, or (2) documented service unavailability exceeding 24 hours in a billing period. Refund requests must be submitted within 30 days of the charge. Contact: support@cloudology.cloud
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

