Kubernetes integration¶
The Pacto Kubernetes integration is a read-only operator that continuously checks
whether running workloads match their declared Pacto service
contracts. Teams declare operational intent in a contract -- workload type, state
and persistence, interfaces, capabilities, dependencies and configurations -- then
deploy separately through Helm or Kustomize. Nothing connects the two sides at
runtime, so contracts drift from reality silently. The operator closes that gap:
it watches Pacto custom resources, reads the referenced contract, observes the
live workload and reports whether they align. It never modifies your workloads.
Where it fits¶
Pacto is a service contract system with three components:
| Component | Role |
|---|---|
| CLI | Author, validate, diff and publish contracts to OCI registries |
| Operator | Continuously check runtime alignment between contracts and live workloads |
| Dashboard | Visualize the service graph, dependency tree and compliance status |
The CLI is the authoring tool. The operator is the runtime feedback loop. The dashboard makes the results visible. The operator can optionally deploy and manage the dashboard for you (see Operator configuration).
How a reconciliation works¶
Each reconciliation follows a fixed pipeline:
- Loader resolves the contract from an OCI registry (auto-selecting the
highest semver tag) or parses inline YAML, and snapshots each resolved version
as an immutable
PactoRevision. - Observer (the collector) reads runtime state from the Kubernetes API and produces typed Evidence. See Runtime observations.
- Validator is the engine's pure evaluator. It reasons over contract versus evidence and returns typed findings plus evaluation coverage. It is stateless: the operator owns evidence collection and status writes.
- Controller coordinates the pipeline, writes the
PactoRevisionsnapshots, and updates thePactoCR status with structured conditions, a contract compliance status and Prometheus metrics.
flowchart LR
CR[Pacto CR] --> Loader
Observer -- reads --> API[(K8s API)]
Loader --> Validator
Observer --> Validator
Validator --> Status[Status + Conditions]
Validator --> Metrics[Prometheus metrics]
What it reports¶
The operator sets status.contractStatus on each Pacto resource to one of seven
values (Compliant, Warning, NonCompliant, Reference, Unknown, Invalid,
NotEvaluated) derived from the typed findings. It is a measure of contract
fidelity, not runtime health. The full status ladder, finding codes and the
observation dimensions are documented in
Runtime observations.
Where to go next¶
- Installation -- install the operator with Helm.
- Contract bindings -- bind a contract to a workload.
- Runtime observations -- what the operator observes and how it reasons.
- Operator configuration -- flags and environment variables.
- CRD reference -- the
PactoandPactoRevisionschemas. - Helm reference -- chart values.
- RBAC -- the permissions the operator needs.
- Artifact Hub -- published artifact coordinates.
- Troubleshooting and Limitations.