Use the inputs you already have
Collect change, identity, ownership, and runtime context from CI/CD, cloud audit, Kubernetes, OpenTelemetry, catalogs, and security tools.
Vartio reconciles production changes with normalized runtime behavior, preserving the evidence behind each conclusion and refusing to guess when the evidence is insufficient.
Git, CI, cloud APIs, and Kubernetes record what changed. Runtime sensors and observability systems record what happened next. Neither side normally explains the other.
Vartio does not compare everything that changed. It explains which changes caused production to behave differently.
As automation becomes more autonomous, a human-authored deployment trail is no longer enough to describe production. We need a searchable memory of what existed, how it behaved, which automation patterns changed it, and how those patterns changed over time. That memory must preserve history rather than overwrite it with the latest snapshot.
Vartio is the product. False Agent, Kide, Ruuma, and Ahti are the systems inside it; external tools provide evidence and context.
Collect change, identity, ownership, and runtime context from CI/CD, cloud audit, Kubernetes, OpenTelemetry, catalogs, and security tools.
False Agent adds independent process lifecycle, ancestry, workload identity, network relationships, and observer-state evidence.
Coverage, capture loss, missing or withheld evidence, attribution degradation, and ordering limits travel with everything Vartio claims.
The mirror contains both the state of production and the epistemic state of what Vartio knows about it.
The footprint depends on the questions and coverage you need. Vartio can begin outside your workloads and make the resulting runtime gaps explicit.
Use webhooks, audit feeds, APIs, and existing OpenTelemetry exports. SaaS and control-plane use can begin without installing an application agent or sidecar.
For independent Linux runtime evidence, deploy False Agent at the node level. On Kubernetes, the intended footprint is one privileged DaemonSet instance per covered worker—not one sidecar per pod.
eBPF is a runtime-capture implementation choice, not a Vartio platform requirement. Vartio consumes selected operational evidence; it does not require every log, metric, trace, or application payload.
A smaller footprint means less coverage—not permission to turn missing evidence into absence.
Preserve source truth and derive small typed claims, recording whether each relationship was carried, witnessed, derived, or inferred.
Normalize causally meaningful runtime structure and establish same, changed, or indeterminate only when observation integrity allows it.
Turn claims and comparison witnesses into status, diff, why, blame, bisect, and explicit acceptance—while Ahti preserves the history.
A healthy collector does not prove a trustworthy observation interval. Capture loss, ordering degradation, attribution failure, or an unsupported dimension may prevent comparison.
Uncertainty is data. The epistemic state of the observer is data.
Vartio does not convert those conditions into a lower confidence percentage merely to force an answer.
The semantic system is deep so the user workflow can remain small: status, diff, why, blame, bisect, and accept.
| Before Vartio | With Vartio |
|---|---|
| Change records and runtime telemetry searched separately. | status and diff show what can be compared and what changed. |
| Engineers manually guess which deployment caused a symptom. | why, blame, and bisect preserve the evidence behind attribution. |
| Historically common behavior silently becomes normal. | accept records an explicit trust decision. |
Vartio does not replace observability, OpenTelemetry, security products, service catalogs, runtime enforcement, application logs, or a SIEM. Those systems make Vartio stronger by supplying evidence and context.
The mirror is useful only when a technical reader can distinguish production state from the quality of Vartio’s knowledge about it.
Kide preserves how shared meaning was established. Ruuma defines when two executions are behaviorally equivalent. Vartio gives both operational meaning and preserves observations and versioned interpretations in Ahti. Ahti stores structure; Vartio interprets behavior.
Show us the change record, the runtime evidence, and the question engineers still had to answer by hand. We will map what a trustworthy comparison would require.
Discuss the change →