Skip to main content
Restate Cloud BYOC is designed around three principles: least privilege, no standing access to your cloud account, and customer ownership of infrastructure. Restate never holds your cloud provider credentials; management access is limited to your managed Kubernetes API endpoint via a scoped, revocable token.

Control channel

The BYOC deployment has three network connections, all initiated from within your account: The deployment agent uses an egress-only polling model — it reaches out to Restate’s control plane to check for work. Restate’s control plane never initiates connections into your account for provisioning or management operations. Restate’s control plane connects to your Kubernetes API to manage Restate environments. This connection uses a bearer token scoped to a limited Kubernetes RBAC role. You can restrict access to the Kubernetes API endpoint by IP allowlisting.
The token can manage RestateCluster resources and namespaces, and write the in-cluster signing-key Secrets it provisions — but it cannot read existing Secrets in your cluster. Revoking the token disables management while leaving running environments untouched.

What crosses the control channel

Sent to your cluster: Received from your cluster: What does NOT cross the control channel:
  • Customer application data or invocation payloads
  • State stored in Restate
  • Customer secrets or credentials
  • Application logs (retained in your account)

Bootstrap security

The foundation template is a standard CloudFormation stack (AWS) or ARM template (Azure) that you deploy yourself. It creates scoped roles for the deployment agent.
The CloudFormation template creates an IAM role for the deployment agent with the following permissions, scoped to the install’s resources:All IAM roles follow least-privilege principles and are scoped to the resources created by the stack.

Infrastructure security

Compute

Kubernetes clusters run on dedicated cloud-managed virtual machines: Instance security features include IMDSv2 enforcement (AWS), encrypted storage at rest (AES-256), and no local ephemeral storage (all data on network-attached volumes).

Patching

Vulnerabilities are triaged and prioritized by severity, with critical issues fast-tracked ahead of routine maintenance.

Network isolation

Each BYOC deployment runs in its own VPC with private subnets across multiple availability zones. Restate environments are isolated via Kubernetes NetworkPolicies:
  • Ingress: only the ingress proxy and metrics collector can reach environment pods
  • Egress: DNS, peer nodes in the same namespace, allowlisted VPC endpoints, tunnel, and the public internet
  • Cross-namespace: blocked by default
All in-cluster traffic between components is encrypted with mTLS via a service mesh.

Service connectivity

Restate environments invoke your service handlers over HTTP. Supported connectivity patterns:

Data sovereignty

All customer data remains in your cloud account:
  • Invocation payloads, stored state, and snapshots never leave your account
  • Application logs are retained in-cluster and accessible to you
  • Restate collects only operational metadata (health, resource utilization, environment configuration) for monitoring and management

Audit

Customer controls