Security
Review Remote Operator as software that runs inside the customer’s Kubernetes cluster or AWS account, not as a dashboard feature.
Local permissions
The operator can only perform Kubernetes actions allowed by its ServiceAccount and RBAC. Cloud and private-service actions require separate identity and network access.
With no operation enabled, the operator can list Deployments, StatefulSets, DaemonSets, pods, events, and pod metrics, and manage its access-request resource. Each enabled operation adds the rules it declares. Log collection through the Kubernetes API and dynamic containers each add a separate Role, bound only when that feature is on. A debug session with kubectl runs as the operator and has the same limits. See Kubernetes permissions.
Keep the installation namespace-scoped unless a reviewed operation truly needs more. Compare every write permission to a specific operation.
# Inspect the installed namespaced permissions.
kubectl --context '<context>' get role,rolebinding,serviceaccount \
--namespace <installation-namespace> \
-o yamlInstallation secrets
On Kubernetes, setup shows the one-time registration token, encryption key, and collector token once. It creates a Secret with those values before Helm runs, so they never appear in Helm values or release history.
On Amazon ECS, the dashboard shows only the one-time registration token. The deploy command generates the encryption key locally and stores it with the token as syncToken in a Secrets Manager secret in the customer's account. The operator presents the registration token to Alien, stores the replacement connection key on its EFS identity volume, and uses that key to authenticate. The encryption key stays in the customer's account. Never reuse one customer's values for another.
Outbound data
Depending on what you enable, the operator can send deployment identity, workload inventory, health, operation inputs and results, and Kubernetes logs to Alien.
Logs and custom operation results are the easiest places to leak application data. Test with representative workloads and inspect what is returned before production rollout.
Removing access
Uninstalling Remote Operator stops that installation from connecting. Retiring its registration in Alien then deletes its deployment-scoped API key. Also revoke any cloud identity or external service credential that you created outside the release or stack. See Uninstall, and test the removal procedure the same way you test installation.
Do not claim that an action has approvals, an audit record, or a particular revocation guarantee unless you have verified that behavior in the exact Alien deployment and operator build you ship.