Cosmonic Control runs the same deny-by-default sandbox as Cosmonic Desktop across your Kubernetes clusters: thousands of workloads per node, scaling to zero when idle, on infrastructure you run.
Runs on any Kubernetes · Helm install in minutes · Free to start
Kubernetes-native
Control is a distributed control plane for Wasm sandboxes. Platform teams deploy and manage workloads with the tools they already use like Helm, kubectl, and GitOps. Developers just build and publish components.
Operator and developer concerns stay separate.
Use cases
Whether you're deploying agent code, untrusted plugins, or high-density services, Cosmonic Control provides sandboxing that works everywhere from the cloud to highly regulated environments.
Run the agents, MCP servers, and AI-generated code your teams build at cluster scale, each one capability-bounded and packed thousands to a node.
Execute customer plugins, partner logic, and other code from outside your trust boundary deny-by-default, with no shared escape surface between tenants.
Replace idle-heavy containers and microVMs with sandboxes that scale to zero: denser and cheaper on the Kubernetes you already run.
Run in classified, sovereign, or offline environments. Mirror every image to your registry and keep code and data inside the cluster.
Density that changes the math
A container or microVM carries its own OS and idle cost for every workload. A Cosmonic sandbox starts in a fraction of a millisecond, uses a fraction of the memory, and costs nothing while it waits. So one node runs what used to take a fleet.
Sandbox workloads are WebAssembly components running on CNCF wasmCloud, the open source runtime Control embeds. Open standards and an open source runtime mean no lock-in.
Your infrastructure
Control installs on any Kubernetes cluster with Helm. Your code and data never leave the cluster: designed from the ground up for regulated, sovereign, and classified environments.
Managed cloud (EKS, GKE, AKS) or your own distribution. If it runs Kubernetes, it runs Control.
Run in your own data center, including a documented path for VMware vSphere / VKS.
Mirror every chart and image to your internal registry and install with no connection to the public internet.
Runs on any Kubernetes








Platform engineering
Control gives a platform team the governance and visibility to run everyone's workloads on shared infrastructure, safely. It's the secure-compute layer your internal developer platform runs on: dense, sandboxed Wasm workloads behind the golden paths your teams already use.
Integrates with your stack







Desktop to cluster
Develop and sandbox agents, MCP servers, and AI-generated code locally with Cosmonic Desktop, then run the exact same capability-bounded workloads at cluster scale with Control. Same model, same manifest, no rewrite between your laptop and production.
Open standards, no lock-in
Cosmonic Control is a supported distribution of open technology, not a proprietary runtime you're stuck with. Workloads are standard WebAssembly components, the host that runs and sandboxes them is open source, and it all plugs into the Kubernetes stack you already operate.
The host that runs and sandboxes your workloads is wasmCloud, a Cloud Native Computing Foundation project. The code that enforces every capability boundary is open to audit and free to run yourself.
Workloads are WebAssembly components built to the W3C Component Model and WASI, shipped as ordinary OCI artifacts. They run on any conformant host, so nothing you build is trapped in Cosmonic.
Kubernetes-native CRDs and an operator, standard OCI registries, and your own CI/CD, RBAC, and observability. No parallel platform to buy into, and no bespoke format to migrate off later.
Pricing
Install the full control plane on any cluster for free. Enterprise adds the controls and support that production platforms require.
FAQ
Yes. Cosmonic Control installs on any Kubernetes cluster with Helm and runs WebAssembly components as first-class workloads through Kubernetes operators and CRDs, alongside your existing containers.
A WebAssembly component starts in sub-millisecond per-call instantiation and runs deny-by-default (no file, network, or host access until granted), so Control packs thousands to tens of thousands per host, depending on component size, and scales them to zero when idle.
Yes. Mirror every chart and image to your internal registry and install with no connection to the public internet. Your code and data never leave the cluster.
Idle WebAssembly workloads cost nothing; Control scales them to zero and starts them on demand in sub-millisecond per-call instantiation, so you reclaim the idle capacity a per-pod container footprint would hold.
Yes. Teams are isolated by namespace and tenant with per-tenant RBAC, so a platform team can run many teams' workloads on shared infrastructure safely.
Workloads are CRDs and OCI artifacts, so your existing GitOps tooling (Argo CD, Helm, GitHub Actions) manages them like any other Kubernetes resource.
No. Control is the secure-compute layer an internal developer platform runs on. It exposes workloads as CRDs and OCI artifacts behind your existing tooling (Backstage, Argo CD, Helm), so platform teams add dense, sandboxed Wasm compute without swapping their portal.
Get started
Install Cosmonic Control free on any Kubernetes cluster, or talk to us about enterprise and air-gapped deployments.
Any Kubernetes · Cloud, on-prem, or air-gapped