# Giant Swarm Documentation ## overview - [Developer portal introduction](https://docs.giantswarm.io/overview/developer-portal/introduction/): Our Backstage-based developer portal is your engineer's front end to the platform. We provide our self-service user interface as plugins for Backstage, so engineers using your platform find all the information they need in the right place. - [Introduction to observability configuration](https://docs.giantswarm.io/overview/observability/configuration/introduction/): Learn how to configure and customize the Giant Swarm observability platform for your organization's needs. - [Accessing the developer portal](https://docs.giantswarm.io/overview/developer-portal/access/): How to find your Giant Swarm developer portal URL and how to log in. - [Alert rules](https://docs.giantswarm.io/overview/observability/alert-management/alert-rules/): Learn how to create and manage alerting and recording rules in the Giant Swarm observability platform. - [Cluster configuration](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/cluster-configuration/): Explanation of how cluster configuration works in Cluster API and how you can customize it. - [Cluster naming](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/cluster-naming/): The specifications for naming workload clusters in the Giant Swarm platform. - [Clusters list](https://docs.giantswarm.io/overview/developer-portal/clusters/list/): How to access a list of clusters, select the ones you are interested in, and navigate to cluster details. - [Dashboard creation](https://docs.giantswarm.io/overview/observability/dashboard-management/dashboard-creation/): Learn how to create custom Grafana dashboards using GitOps workflows or the interactive UI in the Giant Swarm platform. - [Dashboard exploration](https://docs.giantswarm.io/overview/observability/dashboard-management/dashboard-exploration/): Learn how to discover, navigate, and use the pre-built dashboards in the Giant Swarm Observability Platform, plus tips for searching and organizing your own dashboards. - [Import data into the observability platform](https://docs.giantswarm.io/overview/observability/data-management/data-import-export/import/): Send metrics, logs, and traces from external sources into the Giant Swarm observability platform using Grafana Alloy or the platform's HTTP APIs. - [Introduction to Muster](https://docs.giantswarm.io/overview/ai-agents/introduction/): What Muster is, the MCP-server-sprawl problem it solves, and how intelligent tool aggregation makes AI assistants on the platform cheaper and more capable. - [Introduction to Giant Swarm and the Giant Swarm platform](https://docs.giantswarm.io/overview/introduction/): Giant Swarm gives platform engineering teams the ability to build cloud-native developer platforms and operate them without much hassle. - [Introduction to Cluster API](https://docs.giantswarm.io/overview/fleet-management/cluster-management/introduction-cluster-api/): How the Giant Swarm platform leverages the Cluster API standard for managing Kubernetes clusters across infrastructure providers. - [Multi-account clusters](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/multi-account/): Learn the advantages of using multi-account clusters in the Giant Swarm platform. - [Multi-tenancy](https://docs.giantswarm.io/overview/observability/configuration/multi-tenancy/): Learn how to set up and manage multi-tenancy in the Giant Swarm observability platform. - [Giant Swarm operational layers](https://docs.giantswarm.io/overview/architecture/operational-layers/): Here you learn how the operational layers of Giant Swarm are defined and what the intended operational model is. - [Organizations](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/organizations/): Organizations in the Giant Swarm platform allow isolation and logical separation of clusters and apps. - [Platform Security](https://docs.giantswarm.io/overview/security/platform-security/): Architecture and configuration information for the collection of security-related platform features. - [Private clusters](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/private-clusters/): Definition of what do we mean by private clusters in the Giant Swarm platform. - [Using your own URL for the developer portal](https://docs.giantswarm.io/overview/developer-portal/customizing/url/): How to set up a custom URL for your Giant Swarm developer portal. - [Alert routing](https://docs.giantswarm.io/overview/observability/alert-management/alert-routing/): Learn how to configure alert routing and notification policies in the Giant Swarm observability platform. - [App deployments](https://docs.giantswarm.io/overview/developer-portal/deployments/): The developer portal provides an overview of all app deployments in your clusters, even throughout installations. - [Muster architecture](https://docs.giantswarm.io/overview/ai-agents/architecture/): How the central Muster aggregator exposes one OAuth-protected MCP endpoint, aggregates per-cluster mcp-kubernetes servers across a fleet, and why workflows cut agent token cost. - [Authentication](https://docs.giantswarm.io/overview/architecture/authentication/): Authentication and authorization mechanisms in the Giant Swarm platform. - [Cluster details](https://docs.giantswarm.io/overview/developer-portal/clusters/details/): About the cluster details page in the Giant Swarm developer portal. - [Container network interface](https://docs.giantswarm.io/overview/connectivity/cni/): An introduction to the container network interface used in Giant Swarm clusters. - [Export data from the observability platform](https://docs.giantswarm.io/overview/observability/data-management/data-import-export/export/): Read metrics, logs, and traces out of the Giant Swarm observability platform from external Grafana or custom tools through the Observability Platform API. - [Enabling GitOps links](https://docs.giantswarm.io/overview/developer-portal/customizing/gitops-links/): How to configure the developer portal to show GitOps links for resources managed by Flux, so that users can jump directly to the source code. - [LogQL query reference](https://docs.giantswarm.io/overview/observability/data-management/data-exploration/logql/): Reference catalog of LogQL query patterns for analyzing logs on the Giant Swarm observability platform, with worked examples, parsers, and best practices. - [Pre-built dashboards](https://docs.giantswarm.io/overview/observability/dashboard-management/prebuilt-dashboards/): Catalog of the pre-built Grafana dashboards that ship out of the box with the Giant Swarm observability platform, grouped by category. - [Understanding trace-derived metrics](https://docs.giantswarm.io/overview/observability/data-management/data-transformation/understanding-trace-derived-metrics/): Why the Giant Swarm observability platform derives metrics from trace data, what RED metrics are, and the monitoring patterns they enable. - [Understanding alert silences](https://docs.giantswarm.io/overview/observability/alert-management/understanding-silences/): How alert silences work on the Giant Swarm observability platform, when to use them, the two management approaches, and how they fit into the alerting pipeline. - [AWS architecture](https://docs.giantswarm.io/overview/architecture/aws/): How architecture and cluster setup look like with the AWS cloud provider specifically. - [Friendly display of labels](https://docs.giantswarm.io/overview/developer-portal/customizing/labels/): You can customize which labels get displayed in the developer portal, and how they appear in the portal user interface. - [Meta-tools and tool discovery](https://docs.giantswarm.io/overview/ai-agents/meta-tools/): The small set of meta-tools Muster exposes to AI agents, how lazy discovery keeps the context window lean, and the prefixes that group external, core, and workflow tools. - [Observability Platform API reference](https://docs.giantswarm.io/overview/observability/data-management/data-import-export/observability-platform-api/): Reference for the Giant Swarm Observability Platform API, covering import and export endpoints, authentication headers, tenant values, and OIDC provider settings. - [OTLP ingestion reference](https://docs.giantswarm.io/overview/observability/data-management/data-ingestion/otlp-reference/): Reference for OpenTelemetry Protocol (OTLP) ingestion on the Giant Swarm observability platform, covering gateway endpoints, ports, SDK environment variables, and tenant routing. - [PromQL query reference](https://docs.giantswarm.io/overview/observability/data-management/data-exploration/promql/): Reference catalog of PromQL query patterns for metrics analysis on the Giant Swarm observability platform, covering resource, application, and Kubernetes monitoring. - [Secure access to clusters](https://docs.giantswarm.io/overview/security/secure-access/): Our team needs access to your clusters for management purposes. Here's how we make sure this access is secure and responsible. - [Silences](https://docs.giantswarm.io/overview/observability/alert-management/silences/): Learn how to manage alert silences in the Giant Swarm observability platform. - [Trace-derived metrics reference](https://docs.giantswarm.io/overview/observability/data-management/data-transformation/trace-derived-metrics/): Catalog of the metrics Tempo's metrics-generator derives from trace data on the Giant Swarm observability platform, with the PromQL patterns for querying them. - [Workload cluster releases](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/releases/): Learn about workload cluster releases offered by Giant Swarm and how to find more details. - [Metrics monitoring concepts](https://docs.giantswarm.io/overview/observability/data-management/data-exploration/metrics-monitoring-concepts/): The concepts behind metrics monitoring on the Giant Swarm observability platform, including how to approach PromQL query construction, the label model, and service level indicators. - [AI chat in the developer portal](https://docs.giantswarm.io/overview/developer-portal/ai-chat/): Ask plain-language questions about your clusters and platform directly in the developer portal, answered by an AI assistant powered by Muster. - [Alert on trace-derived metrics](https://docs.giantswarm.io/overview/observability/data-management/data-transformation/alert-on-trace-derived-metrics/): How to create alert rules from the trace-derived metrics generated by Tempo on the Giant Swarm observability platform. - [Friendly display of annotations](https://docs.giantswarm.io/overview/developer-portal/customizing/annotations/): You can customize which annotations get displayed in the developer portal, and how they appear in the portal user interface. - [Adding your own catalog](https://docs.giantswarm.io/overview/developer-portal/customizing/catalog/): How to add your own catalog entities to the developer portal provided by Giant Swarm, for your own users, groups, components, and more. - [Creating a Grafana organization](https://docs.giantswarm.io/overview/observability/configuration/creating-grafana-organization/): Step-by-step guide to create and configure Grafana organizations for multi-tenant observability. - [Domain allowlist](https://docs.giantswarm.io/overview/security/domain-allowlist/): A list of all external domains Giant Swarm clusters need access to in order to function. - [Multi-tenancy](https://docs.giantswarm.io/overview/fleet-management/multi-tenancy/): Manage cluster and application resources across multiple organizations and teams. - [AI agent security and SSO](https://docs.giantswarm.io/overview/ai-agents/security/): How Muster secures AI agent access with OAuth 2.1, per-user tool visibility keyed on identity, and single sign-on across clusters via token forwarding and exchange. - [Service graphs](https://docs.giantswarm.io/overview/observability/data-management/data-exploration/service-graphs/): Visualize and analyze service topology and communication patterns using Tempo's service graph feature. - [ServiceMonitor and PodMonitor reference](https://docs.giantswarm.io/overview/observability/data-management/data-ingestion/servicemonitor-reference/): Reference for the Prometheus ServiceMonitor and PodMonitor resources used to collect metrics on the Giant Swarm observability platform, including the required tenant label and their key fields. - [Authentication deep dive: from your MCP client to the Kubernetes API](https://docs.giantswarm.io/overview/ai-agents/authentication/): A token-by-token walkthrough of how user identity flows from an MCP client through Muster and mcp-kubernetes to the Kubernetes API, covering login, validation, token forwarding, exchange, and impersonation. - [Migrate Grafana organizations to v1alpha2](https://docs.giantswarm.io/overview/observability/configuration/migrate-grafana-organizations/): How to migrate GrafanaOrganization resources from the v1alpha1 to the v1alpha2 API version on the Giant Swarm observability platform. - [TraceQL query reference](https://docs.giantswarm.io/overview/observability/data-management/data-exploration/traceql/): Reference for TraceQL, Grafana Tempo's query language, on the Giant Swarm observability platform, covering syntax, query patterns, and best practices. - [Continuous deployment](https://docs.giantswarm.io/overview/continuous-deployment/): Continuous deployment and GitOps capabilities for deploying and upgrading your applications and clusters efficiently. - [Sharing secrets with our team](https://docs.giantswarm.io/overview/security/sharing-secrets/): When getting started with Giant Swarm, some secrets and credentials need to be shared. Learn how to do it securely. - [Troubleshoot traces with TraceQL](https://docs.giantswarm.io/overview/observability/data-management/data-exploration/troubleshoot-traces-with-traceql/): Task-oriented workflows for debugging distributed traces with TraceQL on the Giant Swarm observability platform, from failed requests to performance regressions. - [Cluster upgrades](https://docs.giantswarm.io/overview/fleet-management/cluster-management/cluster-concepts/cluster-upgrades/): Learn how to upgrade your workload clusters and how to keep them ready for upgrades. - [App Platform deprecation and migration to Flux HelmRelease](https://docs.giantswarm.io/overview/fleet-management/app-management/app-platform-deprecation/): Timeline, reasoning, and migration path for moving from the Giant Swarm App Platform to Flux HelmRelease. - [Picking an installation name](https://docs.giantswarm.io/overview/fleet-management/cluster-management/installation-name/): Every Giant Swarm installation has a unique name. Learn the rules to select a proper name for a new installation. - [Kernel settings](https://docs.giantswarm.io/overview/security/kernel-settings/): Here's a complete list of the kernel settings we apply to all cluster nodes, be it control plane or worker. ## getting-started - [Prepare your AWS account](https://docs.giantswarm.io/getting-started/prepare-your-provider-infrastructure/aws/): Prepare your AWS account to start building your cloud-native developer platform with Giant Swarm. - [Access to the platform API](https://docs.giantswarm.io/getting-started/access-to-platform-api/): How engineers can access the platform API to provision new workload clusters or deploy applications. - [Prepare your provider account for Azure](https://docs.giantswarm.io/getting-started/prepare-your-provider-infrastructure/azure/): Prepare your Azure account to start building your cloud-native developer platform with Giant Swarm. - [Create a first workload cluster](https://docs.giantswarm.io/getting-started/provision-your-first-workload-cluster/): Experience configuring and provisioning your first workload cluster using the platform API. - [Prepare your provider environment for VMware Cloud Director](https://docs.giantswarm.io/getting-started/prepare-your-provider-infrastructure/vmware-cloud-director/): Prepare your VMware Cloud Director (VCD) setup to start building your cloud-native developer platform with Giant Swarm. - [Install an application using the app platform](https://docs.giantswarm.io/getting-started/install-an-application/): Deploy applications to your workload cluster using Flux HelmRelease and expose them with Envoy Gateway. - [Prepare your provider environment for Proxmox VE](https://docs.giantswarm.io/getting-started/prepare-your-provider-infrastructure/proxmox/): Prepare your Proxmox VE environment to start building your cloud-native developer platform with Giant Swarm. - [Prepare your provider environment for VMware vSphere](https://docs.giantswarm.io/getting-started/prepare-your-provider-infrastructure/vmware-vsphere/): Prepare your VMware vSphere setup to start building your cloud-native developer platform with Giant Swarm. - [Control the application connectivity](https://docs.giantswarm.io/getting-started/understand-connectivity/): Understand how basic connectivity works in the platform and which options are available for exposing your app. - [Observe your clusters and apps](https://docs.giantswarm.io/getting-started/observe-your-clusters-and-apps/): Start monitoring your clusters and applications with Giant Swarm's observability platform - from basic metrics and logs to distributed tracing, custom dashboards and alerts. - [Set up your AI agent for Kubernetes operations](https://docs.giantswarm.io/getting-started/ai-agent-setup/): Learn how to use Muster and mcp-kubernetes to interact with your Giant Swarm management clusters through AI assistants like Claude Code, Cursor, or GitHub Copilot. ## tutorials - [Add a HelmRelease to a workload cluster](https://docs.giantswarm.io/tutorials/continuous-deployment/helm-releases/add-helmrelease/): Deploy and configure an application into a workload cluster using a Flux HelmRelease and OCIRepository, managed through GitOps. - [Authentication for the platform API as a user](https://docs.giantswarm.io/tutorials/access-management/authentication/user/): Here you learn how to log in to the platform API as a user, using single sign-on (SSO), to use tools like kubectl. - [Author a Muster workflow](https://docs.giantswarm.io/tutorials/ai-agents/authoring-workflows/): Write a Muster Workflow resource that packages a multi-step operation into one named tool an AI agent can discover and call, grounded in the fields the engine actually implements. - [Separate the pod network on AWS using Cilium ENI IPAM mode](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/aws-cilium-eni-mode/): Allocate pod IPs directly on the AWS network using a second VPC CIDR with separate security group and subnets. - [Cluster access control with RBAC and Pod Security Standards](https://docs.giantswarm.io/tutorials/security/rbac/): Introduction to using role-based access control (RBAC) to secure access to cluster resources. - [Cluster upgrades](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/cluster-upgrades/): How workload cluster release work and how they relate to Kubernetes versions and breaking changes. Safety and automation considerations for upgrades. - [Deploying an application via a Flux HelmRelease](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/deploy-app-helmrelease/): Full tutorial on deploying an application that is published as a Helm chart in an OCI registry to a workload cluster, via Flux OCIRepository and HelmRelease resources. - [Exposing workloads](https://docs.giantswarm.io/tutorials/connectivity/ingress/exposing-workloads/): Expose your workloads to the public internet using an ingress controller. - [GitOps at Giant Swarm](https://docs.giantswarm.io/tutorials/continuous-deployment/gitops-at-giantswarm/): A brief explanation of how Giant Swarm supports the GitOps journey for our customers. - [Deploying Ray clusters with KubeRay on Giant Swarm](https://docs.giantswarm.io/tutorials/fleet-management/job-management/kuberay/): Learn how to deploy and manage distributed Ray clusters using KubeRay operator on Giant Swarm clusters. - [Reduce cloud costs with network traffic monitoring](https://docs.giantswarm.io/tutorials/observability/network-monitoring/): Learn how to enable network traffic monitoring to identify costly cross-AZ traffic and optimize your infrastructure spending. - [Persistent volumes](https://docs.giantswarm.io/tutorials/storage/persistent-volumes/): Storage classes, creation and mounting of persistent volumes. - [Installing Gateway API with Envoy Gateway](https://docs.giantswarm.io/tutorials/connectivity/gateway-api/installation/): Learn how to install and configure the Kubernetes Gateway API with Envoy Gateway in Giant Swarm workload clusters. - [Scaling workloads based on custom GPU metrics](https://docs.giantswarm.io/tutorials/fleet-management/scaling-workloads/scaling-based-on-custom-metrics/): Learn how to configure Horizontal Pod Autoscaling with Prometheus adapter to scale workloads based on custom GPU metrics in Giant Swarm clusters. - [Migrating to release charts](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/release-chart-migration/): How to migrate existing clusters from cluster-provider to release-provider charts for automated upgrades via Flux. - [Multiple VPC CIDRs for AWS clusters](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/aws-multiple-cidrs/): Allocate multiple CIDRs in order to scale the cluster or align a cluster with your existing network rules. - [Save agent tokens with workflows](https://docs.giantswarm.io/tutorials/ai-agents/saving-tokens-with-workflows/): Why a Muster workflow makes an AI agent dramatically cheaper, with the measured before-and-after numbers and the design rules that maximize the saving. - [Advanced ingress configuration](https://docs.giantswarm.io/tutorials/connectivity/ingress/configuration/): Here we describe how you can customize and enable specific features for the ingress-nginx controller. - [Access your workload cluster API via automation](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/workload-cluster-api-access-for-automation/): Access your cluster API from an automation requires a hands-free way to provide credentials to kubectl or any Kubernetes client. This article explains how to obtain a service account token to use in such a scenario. - [AWS Cluster scaling](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/aws-cluster-scaling/): How to configure and manage the scaling of your AWS workload clusters on Giant Swarm. - [External Secrets Operator](https://docs.giantswarm.io/tutorials/security/external-secrets-operator/): External Secrets Operator is a managed application within our platform and this is what you need to know. - [Authentication for the platform API in automation](https://docs.giantswarm.io/tutorials/access-management/authentication/automation/): Using the platform API from an automation requires a hands-free way to provide credentials to kubectl or any `kubernetes` client. This article explains how to obtain a service account token to use in such a scenario. - [Manage MCP servers in Muster](https://docs.giantswarm.io/tutorials/ai-agents/managing-mcp-servers/): Add and configure downstream MCP servers behind Muster with MCPServer resources, covering stdio and remote transports, tool prefixes, server families, startup control, and authentication. - [Clusters over multiple availability zones](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/multi-az/): Using multiple availability zones both for worker and control plane nodes increases the resilience of the cluster. Here you will see some details regarding support on different cloud providers and releases, plus how to configure workloads to leverage multiple availability zones. - [Running multiple ingress-nginx controllers](https://docs.giantswarm.io/tutorials/connectivity/ingress/multi-nginx-ic/): Deploy multiple ingress-nginx controllers in a Kubernetes cluster to separate different ingress traffic classes. - [Security policy enforcement](https://docs.giantswarm.io/tutorials/security/policy-enforcement/): This article describes the security policies enforced in a cluster and how to resolve failing resources. - [Update an existing HelmRelease](https://docs.giantswarm.io/tutorials/continuous-deployment/helm-releases/update-helmrelease/): Update the chart version, configuration, or install behavior of a HelmRelease already deployed in a workload cluster via GitOps. - [Using Gateway API with Envoy Gateway](https://docs.giantswarm.io/tutorials/connectivity/gateway-api/usage/): Learn how to use the Kubernetes Gateway API with Envoy Gateway for traffic routing and management. - [Post-migration guide for clusters migrated from vintage to Cluster API](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/migration-to-cluster-api/): This only applies to clusters migrated from vintage to Cluster API, not to any newly created clusters. We explain cleanup and migration away from cloud resources previously used in the "vintage" product generation. - [What is GitOps](https://docs.giantswarm.io/tutorials/continuous-deployment/what-is-gitops/): Learn how to continuous deploy all your workloads thanks to GitOps and Kubernetes. - [Additional details on authentication for the platform API](https://docs.giantswarm.io/tutorials/access-management/authentication/additional-details/): Here we provide additional information about single sign-on with the platform API. - [App configuration reference](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/app-configuration/): Documentation on the various levels of App configuration and how they get merged into a final values object. - [Authorization in the platform API](https://docs.giantswarm.io/tutorials/access-management/authorization/): Granting users specific permission to certain resources is what authorization is all about. The Platform API uses Kubernetes' role based access control (RBAC) primitives and provides automation on top of it to make authorization easy for most real-life use cases. Here we explain them in detail. - [External DNS with AWS Route 53 and static credentials](https://docs.giantswarm.io/tutorials/connectivity/external-dns/aws-route53-static-creds/): How to configure the External DNS service to use AWS Route 53 with static credentials. - [Connect custom MCP servers](https://docs.giantswarm.io/tutorials/ai-agents/connecting-custom-mcp-servers/): Bring third-party and internal MCP servers behind Muster, including servers that don't publish RFC 9728 metadata, using the authorizationServer override. - [Enable automatic updates for HelmRelease](https://docs.giantswarm.io/tutorials/continuous-deployment/helm-releases/automatic-updates-helmrelease/): Configure Flux to pull and apply new chart versions for a HelmRelease, either via a SemVer range on the OCIRepository or via image automation committing version bumps to Git. - [What is FluxCD](https://docs.giantswarm.io/tutorials/continuous-deployment/flux/): An explanation of the GitOps principles and a guide to managing Giant Swarm platform resources with FluxCD. - [Installing Gateway API Inference Extension](https://docs.giantswarm.io/tutorials/connectivity/gateway-api/ai-gateway/): Learn how to install the Kubernetes Gateway API Inference Extension in Giant Swarm workload clusters. - [Ingress nginx to Gateway API migration guide](https://docs.giantswarm.io/tutorials/connectivity/gateway-api/ingress-nginx-migration/): Learn how to migrate from ingress-nginx to Gateway API with Envoy Gateway on Giant Swarm. - [Services of type LoadBalancer](https://docs.giantswarm.io/tutorials/connectivity/ingress/service-type-loadbalancer/): Learn how to expose services directly on cloud providers through services of type LoadBalancer. - [Configure OIDC authentication for workload clusters with structured authentication](https://docs.giantswarm.io/tutorials/security/structured-authentication/): Use Kubernetes structured authentication configuration to connect one or more OIDC providers to the API server of a workload cluster. - [Advanced CoreDNS configuration](https://docs.giantswarm.io/tutorials/connectivity/coredns/): Here we describe how you can customize the configuration of the managed CoreDNS service in your clusters. - [Creating a base template for your workload cluster](https://docs.giantswarm.io/tutorials/continuous-deployment/bases/): How to create a base templates for your workload clusters with different configurations. - [Defaulting and validation of App CRs](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/defaulting-validation/): How defaulting and validation of app CRs is implemented by app-admission-controller. - [Group multiple HelmReleases together](https://docs.giantswarm.io/tutorials/continuous-deployment/helm-releases/multiple-releases/): Patterns for deploying related HelmReleases as a unit. Covers Helm umbrella charts, Kustomize over multiple releases, and install ordering via `dependsOn`. - [Give agents multi-cluster access](https://docs.giantswarm.io/tutorials/ai-agents/multi-cluster-access/): Expose an entire fleet of management clusters through one central Muster, with the instance-selection argument contract and RFC 8693 token exchange for cross-cluster single sign-on. - [Configure OIDC using Dex to access your clusters](https://docs.giantswarm.io/tutorials/access-management/configure-dex-in-your-cluster/): How to install and configure Dex to work as an authenticator mechanism to provide OpenID tokens via OpenID Connect (OIDC). - [Node pools](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/node-pools/): A general description of node pools as a concept, its benefits, and some details you should be aware of. - [App bundle reference](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/app-bundle/): Overview of the app bundle concept, how it works, and how to configure it. - [Creating an app catalog](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/create-catalog/): How to create a custom app catalog for use with app platform and push helm charts to it. - [Creating and using App Sets](https://docs.giantswarm.io/tutorials/continuous-deployment/apps/app-sets/): Learn how to create and use App Sets for applications deployed with GitOps. - [Customizing default apps](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/configuring-default-apps/): How to customize default apps configuration using the cluster chart values. - [Enable automatic updates in Apps](https://docs.giantswarm.io/tutorials/continuous-deployment/apps/automatic-updates-appcr/): Learn how to enable and configure automatic updates in Apps deployed using GitOps. - [Job management with Kueue](https://docs.giantswarm.io/tutorials/fleet-management/job-management/kueue/): Learn how to use Kueue for Kubernetes-native job queueing and resource management in Giant Swarm workload clusters to manage batch workloads efficiently, AI and ML training jobs, or resource quotas. - [Map RBAC and single sign-on](https://docs.giantswarm.io/tutorials/ai-agents/access-control/): Connect identity-provider groups to Kubernetes RBAC so AI agents act with each user's own permissions, and handle large tokens and group limits. - [Obtaining TLS certificates for ingress traffic](https://docs.giantswarm.io/tutorials/security/tls-certificates/): Configure cert-manager to automatically obtain TLS certificates for ingress traffic. - [Managing workload clusters with GitOps](https://docs.giantswarm.io/tutorials/continuous-deployment/manage-workload-clusters/): A guide to create workload clusters in Giant Swarm platform with Flux. - [Configure Helm execution](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/installation-configuration/): Options for Helm execution that are currently supported by the App Platform. - [AWS IAM roles for service accounts (IRSA)](https://docs.giantswarm.io/tutorials/access-management/iam-roles-for-service-accounts/): This article describes how to use a new feature that allows binding of specific AWS IAM roles to a service account of a pod. - [Giant Swarm Policy API guide](https://docs.giantswarm.io/tutorials/security/policy-api/): An overview of how to use Giant Swarm `Policy` types to enforce cluster security and best practices. - [Configure an app's target namespace via its App CR](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/namespace-configuration/): How to configure metadata for the target namespace of an app via its app CR. So it can be used by other tools. - [Troubleshoot AI agent access](https://docs.giantswarm.io/tutorials/ai-agents/troubleshooting/): Work through the common Muster failure modes for platform teams, from authentication loops and disconnected clusters to missing tools and workflows agents can't find. - [Update an existing App](https://docs.giantswarm.io/tutorials/continuous-deployment/apps/update-appcr/): Learn how to update an App already deployed in a workload cluster with GitOps. - [Add a new app template](https://docs.giantswarm.io/tutorials/continuous-deployment/apps/add-app-template/): Learn how to create application templates to deploy apps using GitOps. - [Azure Workload Identity](https://docs.giantswarm.io/tutorials/access-management/azure-workload-identity/): This article describes how to configure a Giant Swarm cluster to support Azure Workload Identity. - [Deploy Muster](https://docs.giantswarm.io/tutorials/ai-agents/self-hosting/deploy-muster/): Install the CRD and application Helm charts for Muster on a management cluster, and run the aggregator in custom-resource discovery mode. - [Creating environments for GitOps resources](https://docs.giantswarm.io/tutorials/continuous-deployment/environments/): How to deploy resources, with different configurations or versions across several environments. - [GPU workloads in Cluster API workload clusters](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/gpu/): Guides explaining how to configure and use GPU nodes in Cluster API (CAPI) workload clusters for running GPU-accelerated workloads. - [Set up Dynamic Resource Allocation (DRA) for GPU workloads](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/dynamic-resource-allocation/): Learn how to configure Dynamic Resource Allocation (DRA) in Giant Swarm Cluster API workload clusters to enable advanced GPU resource management with Kubernetes native scheduling. - [Labelling workload clusters](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/labelling-workload-clusters/): Guide on using labels with workload clusters for the purpose of grouping, categorization and selection. - [Set up OAuth for Muster](https://docs.giantswarm.io/tutorials/ai-agents/self-hosting/oauth-setup/): Protect the Muster endpoint with OAuth and Dex, configure the proxy that authenticates to downstream servers, and handle large enterprise tokens. - [Tools for your GitOps workflow](https://docs.giantswarm.io/tutorials/continuous-deployment/tools/): Helpful tools for your GitOps workflow and how to use them. - [Add a new App to a workload cluster](https://docs.giantswarm.io/tutorials/continuous-deployment/apps/add-appcr/): Learn how to deploy and configure applications into workload clusters using GitOps. - [Advanced cluster autoscaler configuration](https://docs.giantswarm.io/tutorials/fleet-management/cluster-management/cluster-autoscaler/): Here we describe how you can customize the configuration of the managed cluster autoscaler service in your workload clusters. - [Multi-cluster token exchange](https://docs.giantswarm.io/tutorials/ai-agents/self-hosting/multi-mc-token-exchange/): Compare the single-cluster and central deployment shapes, set up RFC 8693 token exchange to remote management clusters, and grant the kubeconfig access each needs. - [Getting started deploying an app with the App Platform](https://docs.giantswarm.io/tutorials/fleet-management/app-platform/deploy-app/): Guide to deploying apps using kubectl gs and the Giant Swarm platform API. - [Setting up a caching container registry within a cluster using Zot](https://docs.giantswarm.io/tutorials/registry/zot/): A registry cache within the cluster can provide benefits for availability, performance, and cost. Here we explain how to set up a registry, using the Zot app provided by Giant Swarm. - [Prevent accidental deletion of resources](https://docs.giantswarm.io/tutorials/fleet-management/deletion-prevention/): Avoid accidental deletion of clusters, apps or other resources in Giant Swarm platform. ## reference - [Chart metadata reference](https://docs.giantswarm.io/reference/platform-api/chart-metadata/): Helm charts maintained by Giant Swarm require certain chart metadata. This page explains which fields are requires and recommended, and for what purpose. We also show how chart metadata is represented in OCI registries. - [Installing the Muster CLI](https://docs.giantswarm.io/reference/muster/installation/): How to install the muster command-line interface and keep it up to date. - ['kubectl gs gitops init' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/init/): Reference documentation on how to initialize an empty GitOps repository, so that it can be used with the `kubectl-gs` plugin. - [Installing kubectl-gs](https://docs.giantswarm.io/reference/kubectl-gs/installation/): How to obtain kubectl gs, the Giant Swarm kubectl plugin, how to keep it up to date, and where to find the Docker image. - ['muster serve' command reference](https://docs.giantswarm.io/reference/muster/cli/serve/): Reference for the 'muster serve' command, which starts the Muster aggregator server that AI agents and other Muster commands connect to. - ['kubectl gs gitops add management-cluster' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-mc/): Reference documentation on how to add a new Management Cluster to the GitOps repository. - ['kubectl gs deploy chart' command reference](https://docs.giantswarm.io/reference/kubectl-gs/deploy-chart/): Reference documentation on how to deploy a Helm chart using 'kubectl gs'. - ['kubectl gs gitops add base' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-base/): Reference documentation on how to add a new base to create clusters in a GitOps repository. - ['kubectl gs gitops add organization' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-org/): Reference documentation on how to add a new organization to a GitOps repository. - ['kubectl gs get catalogs' command reference](https://docs.giantswarm.io/reference/kubectl-gs/get-catalogs/): Reference documentation on how to list catalogs and get details for a single catalog using 'kubectl gs'. - [Muster meta-tools reference](https://docs.giantswarm.io/reference/muster/meta-tools/): Reference for the meta-tools Muster exposes to AI agents, the filter_tools discovery arguments and response shape, and the catalog of built-in tools. - ['muster standalone' command reference](https://docs.giantswarm.io/reference/muster/cli/standalone/): Reference for the 'muster standalone' command, which runs the Muster aggregator and the agent together in a single process. - ['kubectl gs gitops add workload-cluster' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-wc/): Reference documentation on how to add a new workload cluster to a GitOps repository. - ['kubectl gs gitops add app' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-app/): Reference documentation on how to add a new App to the GitOps repository. - ['muster agent' command reference](https://docs.giantswarm.io/reference/muster/cli/agent/): Reference for the 'muster agent' command, which connects to the Muster aggregator as a client or bridges it to a stdio-only IDE. - [Muster custom resource reference](https://docs.giantswarm.io/reference/muster/crds/): Field reference for the Muster MCPServer and Workflow custom resources, grounded in the API types shipped at version 0.10.0. - ['kubectl gs get apps' command reference](https://docs.giantswarm.io/reference/kubectl-gs/get-apps/): Reference documentation on how to list apps and get details for a single app using 'kubectl gs'. - ['kubectl gs gitops add automatic-update' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-update/): Reference documentation on how to configure automatic updates for an App to the GitOps repository. - ['kubectl gs gitops add encryption' command reference](https://docs.giantswarm.io/reference/kubectl-gs/gitops/add-enc/): Reference documentation on how to configure encryption for the GitOps repository. - ['muster context' command reference](https://docs.giantswarm.io/reference/muster/cli/context/): Reference for the 'muster context' command, which manages named contexts that each point at a Muster endpoint. - ['kubectl gs get clusters' command reference](https://docs.giantswarm.io/reference/kubectl-gs/get-clusters/): Reference documentation on how to list clusters and get details for a single cluster using 'kubectl gs'. - ['muster auth' command reference](https://docs.giantswarm.io/reference/muster/cli/auth/): Reference for the 'muster auth' command, which authenticates the Muster CLI to a remote OAuth-protected aggregator. - ['kubectl gs get nodepools' command reference](https://docs.giantswarm.io/reference/kubectl-gs/get-nodepools/): Reference documentation on how to list node pools and get details for a single node pool using 'kubectl gs'. - ['kubectl gs get organizations' command reference](https://docs.giantswarm.io/reference/kubectl-gs/get-organizations/): Reference documentation on how to list organizations and get details for a single organization using 'kubectl gs'. - ['kubectl gs get releases' command reference](https://docs.giantswarm.io/reference/kubectl-gs/get-releases/): Reference documentation on how to list releases and get details for a single release using 'kubectl gs'. - ['muster list' command reference](https://docs.giantswarm.io/reference/muster/cli/list/): Reference for the 'muster list' command, which lists Muster services, MCP servers, workflows, executions, and MCP primitives. - ['kubectl gs login' command reference](https://docs.giantswarm.io/reference/kubectl-gs/login/): Reference documentation on how to ensure an authenticated kubectl context for a Giant Swarm management or workload cluster, using 'kubectl gs'. - ['muster get' command reference](https://docs.giantswarm.io/reference/muster/cli/get/): Reference for the 'muster get' command, which retrieves details about a single Muster resource. - ['kubectl gs template app' command reference](https://docs.giantswarm.io/reference/kubectl-gs/template-app/): Reference documentation on how to create a manifest for an App using 'kubectl gs'. - ['muster create' command reference](https://docs.giantswarm.io/reference/muster/cli/create/): Reference for the 'muster create' command, which creates Muster Workflow and MCPServer definitions. - ['kubectl gs template catalog' command reference](https://docs.giantswarm.io/reference/kubectl-gs/template-catalog/): Reference documentation on how to create a manifest for a Catalog using 'kubectl gs'. - ['muster call' command reference](https://docs.giantswarm.io/reference/muster/cli/call/): Reference for the 'muster call' command, which invokes any MCP tool behind the Muster aggregator by name. - ['kubectl gs template cluster' command reference](https://docs.giantswarm.io/reference/kubectl-gs/template-cluster/): Reference documentation on how to create a manifest for a Cluster using 'kubectl gs'. - [App CRD schema reference (group application.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/apps.application.giantswarm.io/): App represents a managed app which a user intended to install. It is reconciled by app-operator. - [AppCatalog CRD schema reference (group application.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/appcatalogs.application.giantswarm.io/): Deprecated, use Catalog CRD instead. AppCatalog represents a catalog of managed apps. It stores general information for potential apps to install. It is reconciled by app-operator. - [AppCatalogEntry CRD schema reference (group application.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/appcatalogentries.application.giantswarm.io/): AppCatalogEntry represents an entry of an app in a catalog of managed apps. It stores metadata for specific versions and apps. It is generated by app-operator and consumed by app-admission-controller. - [Catalog CRD schema reference (group application.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/catalogs.application.giantswarm.io/): Catalog represents a catalog of managed apps. It stores general information for potential apps to install. It is reconciled by app-operator. - [Chart CRD schema reference (group application.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/charts.application.giantswarm.io/): Chart represents a Helm chart to be deployed as a Helm release. It is reconciled by chart-operator. - [cluster chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/cluster/): Giant Swarm cluster chart with provider-independent cluster resources; Check here the different properties of the chart. - [cluster-aws chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/cluster-aws/): A helm chart for creating Cluster API clusters with the AWS infrastructure provider (CAPA).; Check here the different properties of the chart. - [cluster-azure chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/cluster-azure/): A helm chart for creating Cluster API clusters with the Azure infrastructure provider (CAPZ).; Check here the different properties of the chart. - [cluster-cloud-director chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/cluster-cloud-director/): A helm chart for creating Cluster API clusters with the VMware Cloud Director (VCD) infrastructure provider (CAPVCD).; Check here the different properties of the chart. - [cluster-eks chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/cluster-eks/): A helm chart for creating Cluster API EKS clusters with the AWS infrastructure provider (CAPA).; Check here the different properties of the chart. - [cluster-vsphere chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/cluster-vsphere/): A helm chart for creating Cluster API clusters with the vSphere provider (CAPV).; Check here the different properties of the chart. - [default-apps-eks chart reference](https://docs.giantswarm.io/reference/platform-api/cluster-apps/default-apps-eks/): A Helm chart for default-apps-eks; Check here the different properties of the chart. - [GrafanaOrganization CRD schema reference (group observability.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/grafanaorganizations.observability.giantswarm.io/): GrafanaOrganization is the Schema describing a Grafana organization. Its lifecycle is managed by the observability-operator. - [Konfiguration CRD schema reference (group konfigure.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/konfigurations.konfigure.giantswarm.io/): Konfiguration is the Schema for the konfigurations API. - [KonfigurationSchema CRD schema reference (group konfigure.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/konfigurationschemas.konfigure.giantswarm.io/): KonfigurationSchema is the Schema for the konfigurationschemas API. - [MCPServer CRD schema reference (group muster.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/mcpservers.muster.giantswarm.io/): MCPServer is the Schema for the mcpservers API - [Organization CRD schema reference (group security.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/organizations.security.giantswarm.io/): Organization represents schema for managed Kubernetes namespace. Reconciled by organization-operator. - [PolicyException CRD schema reference (group policy.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/policyexceptions.policy.giantswarm.io/): PolicyException is the Schema for the policyexceptions API - [PolicyExceptionDraft CRD schema reference (group policy.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/policyexceptiondrafts.policy.giantswarm.io/): PolicyExceptionDraft is the Schema for the policyexceptiondrafts API - [Release CRD schema reference (group release.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/releases.release.giantswarm.io/): Release is a Kubernetes resource (CR) representing a Giant Swarm workload cluster release. - [RoleBindingTemplate CRD schema reference (group auth.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/rolebindingtemplates.auth.giantswarm.io/): RoleBindingTemplate is the Schema for the rolebindingtemplates API - [Silence CRD schema reference (group observability.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/silences.observability.giantswarm.io/): Silence is the Schema for the silences API. - ['muster start' command reference](https://docs.giantswarm.io/reference/muster/cli/start/): Reference for the 'muster start' command, which starts a Muster service or runs a workflow. - [Workflow CRD schema reference (group muster.giantswarm.io)](https://docs.giantswarm.io/reference/platform-api/crd/workflows.muster.giantswarm.io/): Workflow is the Schema for the workflows API - ['muster stop' command reference](https://docs.giantswarm.io/reference/muster/cli/stop/): Reference for the 'muster stop' command, which stops a running Muster service. - ['kubectl gs template organization' command reference](https://docs.giantswarm.io/reference/kubectl-gs/template-organization/): Reference documentation on how to create a manifest for an organization using 'kubectl gs'. - ['muster check' command reference](https://docs.giantswarm.io/reference/muster/cli/check/): Reference for the 'muster check' command, which checks whether a Muster MCP server or workflow is available. - ['kubectl gs update app' command reference](https://docs.giantswarm.io/reference/kubectl-gs/update-app/): Reference documentation on how to update an App CR using 'kubectl gs'. - ['muster events' command reference](https://docs.giantswarm.io/reference/muster/cli/events/): Reference for the 'muster events' command, which lists and filters events for Muster resources. - ['kubectl gs update cluster' command reference (cluster upgrades)](https://docs.giantswarm.io/reference/kubectl-gs/update-cluster/): Reference documentation on how to upgrade a workload cluster using kubectl-gs. - [Questions and answers on kubectl-gs](https://docs.giantswarm.io/reference/kubectl-gs/faq/): Frequently asked questions and answers and help for troubleshooting around `kubectl-gs`. - ['muster version' command reference](https://docs.giantswarm.io/reference/muster/cli/version/): Reference for the 'muster version' command, which prints the Muster CLI and server version. - ['muster self-update' command reference](https://docs.giantswarm.io/reference/muster/cli/self-update/): Reference for the 'muster self-update' command, which updates the Muster CLI to the latest GitHub release. - [Kubernetes resource annotation reference](https://docs.giantswarm.io/reference/platform-api/annotations/): Overview of Kubernetes resource annotations used by Giant Swarm, and their meaning. - [Kubernetes resource labels reference](https://docs.giantswarm.io/reference/platform-api/labels/): Overview of Kubernetes resource labels used by Giant Swarm, and their meaning. - [Usage data collection in 'kubectl gs'](https://docs.giantswarm.io/reference/kubectl-gs/telemetry/): kubectl-gs collects anonymous usage data, which helps us to prioritize our further development on the tool. ## support - [Customer support](https://docs.giantswarm.io/support/overview/): The support we provide is an essential part of our offering. Here we explain various support service processes and workflows. - [Giant Swarm training catalog](https://docs.giantswarm.io/support/training-catalog/): Overview of the trainings and workshops offered to customers in order to share our knowledge and best practices with them and answer possible follow-up questions. - [Incident process](https://docs.giantswarm.io/support/incident-process/): The process used by the Giant Swarm support team when a priority one incident is called.