yeke.io · pricing
Two tiers: Community and Enterprise.
Community is free forever and its core capabilities are not trimmed — the limit is scale, not features. Enterprise adds enterprise items that have not been built yet, and is licensed per cluster. This page is not a brochure; it is a commitment: the limits published here are never tightened later.
Tiers
There is no middle "Pro" tier. Two tiers, two sentences.
Community
Free and permanent — this is not a trial. Nothing expires, no countdown runs, and no step of the install asks for a signup, an email address or a license key.
- The full write chain.
plan → guardrail → dry-run → approval → apply— not one link of it is reserved for the paid tier. That includes the 11 built-in CEL policies and your own policy directory. - Append-only audit trail. Reading it, filtering it, and the two identities on every record (the YEKE user and the Kubernetes identity) are all here.
- AI with your own key. You bring the provider key — and an in-house model endpoint (any OpenAI-compatible address) counts as your own key too.
- Both cluster connection modes. The agent tunnel and direct kubeconfig; neither is gated.
- Cluster provisioning. Creating VMs on Harvester and vSphere, standing up an HA control plane, adding and removing nodes.
- Exec/terminal and log streaming. Part of day-to-day operations, not a paid add-on.
- Backup and restore. We do not hold your data hostage: how to back up the database is documented for every tier.
Enterprise
Limits are set by contract, and the unit of pricing is the cluster — not the seat and not the node. We do not publish a price figure on this site: the unit and the structure are fixed, the number will be set with what we learn in the first enterprise conversations. Talk to sales for scope and price.
None of the items Enterprise will add exist in the product today. What they are, in which order they arrive and why that order — written out below, without dressing them up as shipped features.
An organization buying Enterprise today buys the product as it is now, with higher ceilings and SLA-backed support; roadmap items unlock as they are built.
Talk to salesCommunity limits
The free tier is limited by scale, not by cutting features: you run the real product, not a trimmed demonstration of it.
- 3 clusters and 5 active users. A cluster is a cluster record in your inventory; a user is a YEKE user who can sign in. Nothing counts nodes, vCPUs or pods.
- These limits apply today. There is no "free for now, restricted in some later release" period: the ceilings are in the product and behave exactly as published. Removing that surprise is the whole reason this page exists.
- Hitting a limit does not put the product into read-only. The only thing that stops is adding a new cluster or a new user. Every existing cluster stays fully manageable — reads, the write chain, approvals, rollbacks, the audit trail. The refusal is an explicit error; nothing is quietly throttled.
- It is keyless. Community has no license file, and no install screen asks for an email, an account or a key. The product makes no outbound call for licensing: no online activation, no periodic phone-home, no usage telemetry.
- An operator cannot lower the ceiling. The numbers are constants in the code; we deliberately did not add an environment variable that shrinks them — a ceiling that can be lowered would make the pledge below meaningless.
The direction of these numbers is settled: they can be raised, never lowered. 3 and 5 are a starting point and may grow with what we hear from the field.
The pledge: no retroactive tightening
This category has watched products narrow their free tier after the fact, and pay for it in trust. The cheapest tightening is the one never made: start narrow, announce it as permanent, and only ever widen.
Written commitment
- Published limits only move up. If 3 clusters / 5 users ever changes, it grows. Never the other way.
- No feature that is free today is moved behind payment later. Every Enterprise item is either newly written or built on top of an existing layer: reading the audit trail stays free and what is sold is the export; guardrails stay free and what is sold is central distribution of policies.
- Community stays keyless. We will not one day attach the free tier to a signup or a license key.
- The limit of this pledge is written down too: it is not a promise that "everything will be free forever". New capabilities written in the future may be born in the paid tier. What we promise is that what you have today will not be taken away — we are not making a broader promise here, precisely so we never have to break one.
This pledge was published in August 2026 and lives on this page.
Enterprise: what exists, what is planned
None of the items below are in the product today. This page does not present them as shipped features; it publishes their order and their scope so that you can make a buying decision against a plan rather than a slogan.
- We give no dates. The order of the phases is binding — which set arrives before which is decided. A calendar is not binding, and we do not print one here.
- The order follows what unlocks a sale, not what is easiest to build: each phase carries its reason in one sentence.
- No item is an existing free feature moved behind payment. That is the roadmap's share of the pledge above.
E1 Identity and compliance
LDAP/AD binding · OIDC SSO · group → Kubernetes identity mapping · audit trail export to a SIEM
The first two questions in an enterprise review are "does it bind to our directory" and "do the logs reach our SIEM"; no enterprise PoC starts before this phase.
E2 Scale and continuity
PostgreSQL backend · zero-downtime core deployment (HA) · air-gapped install bundle · long retention and archiving
Two questions decide whether a PoC goes to production: the database, and whether a deploy causes downtime.
E3 Governance
dual approval (four eyes) · maintenance windows / change freeze · central policy management · terminal session recording · compliance reports
The set that justifies the price difference: it is built on top of the approval chain that already exists, and it is the hardest to copy.
E4 GitOps and fleet
GitOps mode (a chain that opens a PR instead of applying) · drift visibility · staged fleet waves · ITSM integration
The expansion phase, aimed at platform teams already mature on ArgoCD or Flux.
E5 Managed AI and the demand-driven tail
managed AI (we hold the key and the contract) · AI usage policies · AI audit reporting · SCIM · SAML
AI rarely triggers the purchase on its own, but it grows the contract; SCIM and SAML take their shape from the first customer who asks.
SLA-backed support in Turkish is part of Enterprise in every phase. It is a commercial item rather than a code item; its scope and response times are defined in the contract.
Deliberately staying free
What will not be charged for is written down as firmly as what will be. The items below are not candidates waiting to be moved into Enterprise — the decision to keep them in Community has been made.
| Item | Why it stays in Community |
|---|---|
| Cluster provisioning | It is the core experience of the fleet story, and the 3-cluster limit is already a natural ceiling on it. |
| In-house model endpoints | An honest reading of "bring your own key and model" includes the model running on your own servers. The value of Enterprise AI is the managed key, the policies and the reporting — not a monopoly on the endpoint URL. |
| Guardrails and your own policy directory | The chain is the identity of the product. What is Enterprise is central distribution of policies, not the protection itself. |
| Reading the audit trail | Part of the trust claim. Only the export and reporting layer is paid. |
| Exec/terminal and log streaming | Part of daily operations. Only session recording is paid. |
| Backup and restore | Data is never held hostage: the backup path is documented for every tier. |
Licensing and buying
An Enterprise license is a signed block of text you load into the product. The mechanism works in the product today; the items it will unlock are not written yet.
- Verified entirely offline. There is no license server to reach, no online activation and no periodic check — it behaves identically in an air-gapped install.
- Not locked to hardware, no anti-tamper layer. A license is issued to a legal entity, not to a machine. Enterprise buyers buy invoices, support and compliance; we are not entering a DRM arms race.
- A license can only raise limits. A loaded license can never drop you below the Community ceilings: the effective ceiling is always the larger of the two. "I loaded my license and got less" is not a state this product can reach.
- When it expires, the product does not shut down. The core never refuses to start, in any license state. A banner appears before and after expiry, and everything keeps working through the grace period written into the contract. Once that ends, only growth stops: no new clusters or users, and no changes to enterprise configuration. Every existing cluster stays fully manageable — reads, the write chain, approvals and rollbacks are never cut, and local administrator login is always available.
- Why it works this way: the write chain is how you intervene in a production incident. Holding it hostage to a commercial state burns every bit of earned trust in a single bad night. The penalty is "you cannot grow", never "you lose what you had".
Enterprise scope, limits and price are settled in a conversation. You need no license to try the product yourself: the deployment guide is Community from beginning to end.
yeke.io
Install first, talk later.
You need nobody's permission to run Community: no account, no key, no sales call. Having the Enterprise conversation after you have seen the product on your own clusters works better for both of us.