Skip to main content
Reference

BYOC architecture

Your cloud runs the control plane. The operator receives deployment instructions over an outbound connection.

How deployments work

Rivet Cloud and your BYOC deployment 1: Request a deployment from Rivet Cloud. 2: Your operator pulls commands from Rivet Cloud. 3: The operator updates and maintains the Rivet control plane and FoundationDB, grouped as managed by operator. 4: The operator reports status to Rivet Cloud. All three components run in your Kubernetes cluster, inside your VPC. Your workers connect to the control plane. YOUR VPC KUBERNETES · EKS / GKE Request deployment 1 Rivet Cloud Command queue Rivet operator 2 Pull commands 4 Report status 3 Apply update Rivet control plane FoundationDB Managed by operator Your workers Connect

The Rivet operator runs inside your Kubernetes cluster and connects to Rivet Cloud to receive deployment instructions. It manages updates to the Rivet control plane and FoundationDB inside your VPC. No inbound management connection from Rivet Cloud is required.

  1. Request a deployment or update through Enterprise Support
  2. The operator receives instructions from Rivet Cloud
  3. The operator applies the update inside your cluster
  4. The operator reports status back to Rivet Cloud

What gets provisioned

Terraform provisions networking, a Kubernetes cluster, container registry, object storage, secrets, and the Rivet operator. Rivet then deploys the control plane and FoundationDB.

AWS

AWS BYOC resources Your cloud account contains a VPC with load balancers and a Kubernetes cluster. The cluster runs the Rivet operator, Rivet control plane and FoundationDB. Cloud services provide container images, object storage and secrets. Networking and IAM connect these resources. YOUR AWS ACCOUNT REGIONAL VPC Application Load Balancers AMAZON EKS Rivet operator Rivet control plane FoundationDB CLOUD SERVICES Amazon ECR Container images Amazon S3 Object storage AWS Secrets Manager Credentials Subnets · outbound NAT · private DNS · storage volumes · IAM

Google Cloud

Google Cloud BYOC resources Your cloud account contains a VPC with load balancers and a Kubernetes cluster. The cluster runs the Rivet operator, Rivet control plane and FoundationDB. Cloud services provide container images, object storage and secrets. Networking and IAM connect these resources. YOUR GOOGLE CLOUD PROJECT REGIONAL VPC Cloud Load Balancing GOOGLE KUBERNETES ENGINE Rivet operator Rivet control plane FoundationDB CLOUD SERVICES Artifact Registry Container images Cloud Storage S3-compatible object storage Secret Manager Credentials Subnets · outbound NAT · private DNS · storage volumes · IAM

Permissions and data

You do not need to allow inbound network access from Rivet Cloud or provide it with a service account or your admin token.

The Rivet operator runs inside your Kubernetes cluster, pulls deployment instructions from Rivet Cloud, and applies them locally. Your VPC needs no inbound management rules, and your admin token stays in your cloud secret manager.

Outbound access

Private deployments still need outbound routes for:

  • Rivet Cloud command polling and status reporting.
  • Release downloads and deployment-log uploads.
  • Cloud APIs, image registries, and prerequisite downloads used during installation and deployment.

If your organization restricts outbound access, allowlist these destinations.

For a fully air-gapped deployment, contact us.

Accessing Rivet

From your backend

Use the private_endpoint in your Terraform deployment outputs from your VPC or a connected network. Inside the same Kubernetes cluster, you can also use http://rivet-engine.rivet.svc.cluster.local:6420 (replace rivet if you changed kubernetes_namespace).

Authenticate with your admin token. See Credentials & dashboard to retrieve it.

From a public endpoint

When rivet_endpoint_access is public, use your configured hostname, such as https://rivet.mycompany.com. HTTPS is configured automatically after DNS setup.

Authenticate with your admin token, or create a public token using ACL.

Multi-region

BYOC across regions Two regional VPCs connect over a private network. Each region has a Kubernetes cluster running a Rivet operator, Rivet control plane and FoundationDB. REGION A · VPC KUBERNETES Rivet operator Rivet control plane FoundationDB REGION B · VPC KUBERNETES Rivet operator Rivet control plane FoundationDB Private connectivity

Each region has its own VPC, Kubernetes cluster, operator, and Rivet deployment. Regions communicate over private connectivity and share a container registry. Workers connect to the regional endpoints provided by Rivet.

Next steps