Skip to content

Security model

Hyperlake separates control-plane governance from customer-owned execution. The user identity, target authorization, OPA policy, and cluster-level controls determine what an operation may do.

  • Use least-privilege identities and narrowly scoped catalog grants.
  • Prefer credential references over raw values.
  • Keep private clusters behind the customer’s access boundary, such as Cloudflare Access.
  • Treat query results, logs, policy decisions, lineage, and presigned artifact URLs as sensitive data.
  • Pin CLI versions in automation and review changes before upgrading.

The CLI and MCP surfaces do not replace Kubernetes, cloud IAM, network policy, or OPA. They provide a governed user-facing route into those controls.