What we run

Machines, not adjectives.

Packet Analysis is the lead. When the fault is the platform, the second machine is K3 / Kubernetes platform migration on demand — the RILEY Dashboard, already shipping. By Design is how a change proves itself before merge.

01 · Lead

Packet Analysis

What we run

Wireshark and tcpdump on the path. Kubeshark on in-cluster API and service traffic. eBPF on the Kubernetes stack: Cilium, Hubble, bpftrace, BCC, custom kprobes and tracepoints, socket filters, cgroup v2 watermarks. NetFlow and SNMP when flow and fabric fill the gap.

What you get

Cause across service · network · compute, sized to a fix. Not a PCAP left on a laptop, and not a dashboard that stopped at the symptom. Pedigree: 25+ years of national TELCO packet forensics.

02 · Shipped

K3 platform migration on demand

What we run

The RILEY Dashboard is the pane of glass for a Kubernetes fleet moving onto KRO. RileyApplication is the source of truth. Argo is the sync engine under that definition, not a pile of hand-written application YAML. Conductor is deprecated; orchestration moves to Temporal.

What you get

A runway in priority order. The Apps board is one row per product: health, containers, pods, restarts, cluster, namespace, and whether it is managed from the KRO source of truth or from legacy sync. Still-broken is not the same as open. A row opens its containers, then Start workspace runs the change and stops at a pull request.

The console below is a sanitized demonstration of that operating picture. Six fictional applications. No live cluster, no secrets, no internal host.

RILEY Dashboard

K3 / Kubernetes platform migration on demand.

Demonstration fleet · not a live cluster

One row per product. Health, restarts, and where the app is managed from — KRO source of truth or legacy sync — with priority on the left. Click a product to open its containers. This board is a demonstration, not a live cluster.

8 shown / 8 · demonstration

Scroll the board sideways.

ContainersPods R/P/FClusterNamespaceManaged fromIssues
P0Degraded41/0/226 active 18medgeingressLegacy sync1
gatewayDegraded22container · session-gateway
proxyHealthy4container · session-gateway
P1Degraded63/1/111 settling 2happsruntimeKRO SSOT1
P1Unknown20/0/00 edgeingressLegacy sync0
P1Progressing32/1/07 stable 1dcoredataLegacy sync1
P2N/A00/0/00 coreobserveKRO SSOT0
P2Healthy11/0/03 stable 9dappsruntimeKRO SSOT0
P2Healthy22/0/04 stable 9dcorepolicyKRO SSOT0
P2Healthy55/0/044 stable 9dappsruntimeKRO SSOT1

P0 · Still broken · managed from Legacy sync

The issue was closed. The same drift came back on the next collect.

03 · Gate

riley-pr-check and bverify

What we run

By-Design checks in CI. The 9-Layer Verification Engine dynamically selects what the diff needs, from physical through cognitive governance. The 4-Round Quadriad is R1 Expected-Red on main, R2 Expected-Green on the pull request, R3 zero-leak / 0→1→0, R4 sabotage caught.

What you get

A gate that fails closed. The agent that picked the tests does not edit them, mute them, or rewrite the raw result. It summarizes. Proof trail: revive_labs #932 and #959. Run it on bare metal, Docker, Kubernetes, and Cloud MicroVMs.

04 · Watch

Remote monitoring, sized to the application

What we run

Remote probes, log intelligence, and a health / reaper path customized to how your service actually runs. revive_labs #956.

What you get

A picture of launcher, serve, and Cloud that operators can act on. Closed-loop reaping for leaked PTYs and zombie trees, tied back to the True SRE ladder when the wire has to be read.

05 · Loop

Performance and benchmarking

What we run

A performance loop across any service or application: measure, diagnose on Service → Network → Compute, change config or code or architecture, re-measure. Agentic Development Workflows keep that loop repeatable.

What you get

The loop proved on bare metal between Calgary and Montreal, then extended to any cloud or enterprise network. No invented savings on this site.