LogoLogo
Log in|Playground
  • Welcome
    • Introduction
    • FAQ
  • Capabilities
    • Log Management
    • Infrastructure Monitoring
    • Application Performance Monitoring (APM)
      • Application Metrics
      • Traces
      • Supported Technologies
    • Real User Monitoring (RUM)
  • Getting Started
    • Requirements
      • Kubernetes requirements
      • Kernel requirements for eBPF sensor
      • CPU architectures
      • ClickHouse resources
    • Installation & updating
    • Connect Linux hosts
    • Connect RUM
    • 5 quick steps to get you started
    • groundcover MCP
      • Configure groundcover's MCP Server
      • Getting-started Prompts
      • Real-world Use Cases
  • Use groundcover
    • Monitors
      • Create a new Monitor
      • Issues page
      • Monitor List page
      • Silences page
      • Monitor Catalog page
      • Monitor YAML structure
      • Embedded Grafana Alerts
        • Create a Grafana alert
    • Dashboards
      • Create a dashboard
      • Embedded Grafana Dashboards
        • Create a Grafana dashboard
        • Build alerts & dashboards with Grafana Terraform provider
        • Using groundcover datasources in a Self-hosted Grafana
    • Insights
    • Explore & Monitors query builder
    • Workflows
      • Create a new Workflow
      • Workflow Examples
      • Alert Structure
    • Search & Filter
    • Issues
    • Role-Based Access Control (RBAC)
    • Service Accounts
    • API Keys
    • APIs
    • Log Patterns
    • Drilldown
    • Scraping custom metrics
      • Operator based metrics
      • kube-state-metrics
      • cadvisor metrics
    • Backup & Restore Metrics
    • Metrics & Labels
    • Add custom environment labels
    • Configuring Pipelines
      • Writing Remap Transforms
      • Logs Pipeline Examples
      • Traces Pipeline Examples
      • Logs to Events Pipeline Examples
      • Logs/Traces Sensitive Data Obfuscation
      • Sensitive Data Obfuscation using OTTL
      • Log Filtering using OTTL
    • Querying your groundcover data
      • Query your logs
        • Example queries
        • Logs alerting
      • Query your metrics
      • Querying you data using an API
      • Using KEDA autoscaler with groundcover
  • Log Parsing with OpenTelemetry Pipelines
  • Log and Trace Correlation
  • RUM
  • Customization
    • Customize deployment
      • Agents in host network mode
      • API Key Secret
      • Argo CD
      • On-premise deployment
      • Quay.io registry
      • Configuring sensor deployment coverage
      • Enabling SSL Tracing in Java Applications
    • Customize usage
      • Filtering Kubernetes entities
      • Custom data retention
      • Sensitive data obfuscation
      • Custom storage
      • Custom logs collection
      • Custom labels and annotations
        • Enrich logs and traces with pod labels & annotations
        • Enrich metrics with node labels
      • Disable tracing for specific protocols
      • Tuning resources
      • Controlling the eBPF sampling mechanism
  • Integrations
    • Overview
    • Workflow Integrations
      • Slack Webhook Integration
      • Opsgenie Integration
      • Webhook Integration
        • Incident.io
      • PagerDuty Integration
      • Jira Webhook Integration
      • Send groundcover Alerts to Email via Zapier
    • Data sources
      • OpenTelemetry
        • Traces & Logs
        • Metrics
      • Istio
      • AWS
        • Ingest CloudWatch Metrics
        • Ingest CloudWatch Logs
        • Ingest Logs Stored on S3
        • Integrate CloudWatch Grafana Datasource
      • GCP
        • Ingest Google Cloud Monitoring Metrics
        • Stream Logs using Pub/Sub
        • Integrate Google Cloud Monitoring Grafana Datasource
      • Azure
        • Ingest Azure Monitor Metrics
      • DataDog
        • Traces
        • Metrics
      • FluentBit
      • Fluentd
      • JSON Logs
    • 3rd-party metrics
      • ActiveMQ
      • Aerospike
      • Cassandra
      • CloudFlare
      • Consul
      • CoreDNS
      • Etcd
      • HAProxy
      • Harbor
      • JMeter
      • K6
      • Loki
      • Nginx
      • Pi-hole
      • Postfix
      • RabbitMQ
      • Redpanda
      • SNMP
      • Solr
      • Tomcat
      • Traefik
      • Varnish
      • Vertica
      • Zabbix
    • Source control (Gitlab/Github)
  • Architecture
    • Overview
    • inCloud Managed
      • Setup inCloud Managed with AWS
        • AWS PrivateLink Setup
        • EKS add-on
      • Setup inCloud Managed with GCP
      • Setup inCloud Managed with Azure
      • High Availability
      • Disaster Recovery
      • Ingestion Endpoints
      • Deploying in Sensor-Only mode
    • Security considerations
      • Okta SSO - onboarding
    • Service endpoints inside the cluster
  • Product Updates
    • What's new?
    • Earlier updates
      • 2025
        • Mar 2025
        • Feb 2025
        • Jan 2025
      • 2024
        • Dec 2024
        • Nov 2024
        • Oct 2024
        • Sep 2024
        • Aug 2024
        • July 2024
        • May 2024
        • Apr 2024
        • Mar 2024
        • Feb 2024
        • Jan 2024
      • 2023
        • Dec 2023
        • Nov 2023
        • Oct 2023
Powered by GitBook
On this page
  • What is inCloud Managed?
  • How does it work?
  • Supports object storage as component of storage strategy
  • Security Principles
Export as PDF
  1. Architecture

inCloud Managed

Last updated 2 months ago

groundcover inCloud Managed is only available on our Enterprise plan. Learn more about our .

What is inCloud Managed?

groundcover inCloud Managed is a managed enterprise solution designed for installing groundcover’s observability backend infrastructure within your own cloud environment to enable the ultimate level of control, privacy, and customization.

How does it work?

Installed in a separate, isolated cloud provider account owned by your organization, it ensures the most secure and private environment for groundcover's infrastructure, separating it from other workloads and minimizing interference.

groundcover's control plane manages, configures, and maintains the necessary infrastructure and workloads within the cloud provider account. It leverages a variety of additional services by the cloud provider, including cloud storage, managed Kubernetes services, virtual private cloud networks, and load balancers, to create a robust and scalable environment.

Access to this account is securely managed through your cloud provider’s built-in access federation features, with specific roles and permissions set up to ensure that the groundcover control plane can manage resources effectively, while adhering to strict security principles. It also allows for secure telemetry data delivery, infrastructure monitoring, log management, and real-time data handling.

The entire setup, from infrastructure provisioning to ongoing maintenance, is managed by groundcover, providing an enterprise solution that minimizes the operational burdens of installing and maintaining your observability solution. In addition, security patching, health monitoring, and scaling are all automated.

groundcover Managed can be deployed using any cloud provider account. Follow our setup instructions in the following guides:

Supports object storage as component of storage strategy

groundcover inCloud Managed allows you to leverage object storage as an additional data storage option that lives together with the out-of-the-box ClickHouse integration. This allows you total flexibility on what data you need to have stored in a fast and powerful storage (ClickHouse), and what data you need in the most cost-effective longer term storage (Amazon S3, Google Cloud, Azure Blob, etc.). Perfect to support cold storage needs.

Security Principles

  • groundcover is denied access at the IP route level from sending traffic towards your production workloads.

  • inCloud instances are isolated from public traffic at the IP route level.

  • Kubernetes Public API is exposed to predefined IP addresses [3.86.137.43, 44.217.56.175]

    • These addresses are groundcover control plane addresses with limited access enforced via internal security measurements

subscription p
lans
Cover
Cover
Cover

Setup with AWS
Setup with GCP
Setup with Azure