Registered runtime clusters
GET /v1/clusters| Health | Cluster | Tenant | Cloud | Mode | Trust domain | Licence | Registered |
|---|---|---|---|---|---|---|---|
| healthy | hexr-runtime-aks-1 clu_971aac2644a01dd7827635c1 | globex-azure | aks | nested | globex-azure.agents.hexr.cloud | source · active · to 2027-05-22 | 2026-05-22 |
| healthy | hexr-runtime-eks-1 clu_d6e475d4df7966e2fbca13ef | acme-aws | eks | nested | agents.hexr.cloud | source · active · to 2027-05-22 | 2026-05-22 |
Healthtech tenant (AWS) — trust root
deployment/demos/verify-tenant-isolation.shAWS / EKS · healthcare denial review
# trust domain
agents.hexr.cloud
# root
Hexr Root CA 2026
E8:E6:77:6D:91:26:99:B5:CC:3A:73:C3:47:F3:AD:B1:7C:5F:73:62…
Globex People — trust root
deployment/demos/verify-tenant-isolation.shAzure / AKS · candidate screening (HR tech)
# trust domain
globex-azure.agents.hexr.cloud
# root
Hexr Root CA Globex 2026
74:C8:C4:CA:7B:AB:80:7E:36:D1:6C:3E:6A:1A:0A:E3:9D:75:CB:04…
What you install
helm upgrade hexr-runtime hexr/hexr-runtime -f values.yamlOne chart per cluster. It brings up the identity server (chained to the control plane), the policy engine, the credential injector and the evidence store, and registers the cluster with the licence you see above. No root is generated on your side; no signing key is held by your team.