“We were essentially able to reduce the cost of that cluster by about 75%. On AWS, DevZero demonstrated they could achieve significantly higher savings than we initially thought possible.”

Mihir Nair
Head of Architecture, Databahn
Automatically rightsize CPU and memory on OpenShift. No pod disruption, no SCC conflicts, no dropped connections.
Companies who slashed their Kubernetes
spend using DevZero
Most OpenShift clusters run at 15–30% utilization. Teams over-provision, SCC policies block VPA tooling, and there's no clear view of what's costing money.
CPU and memory requests are defined in manifests and never revisited. Most OpenShift pods run at a fraction of what they request. You pay for the full allocation regardless of actual usage.
MachineSets are sized for peak load and stay fixed. Underutilized nodes keep running with no visibility into wasted capacity and no automated path to consolidate or right-size them.
OpenShift Security Context Constraints prevent VPA from evicting pods to apply resource changes. Teams fall back to manual tuning or accept permanently inflated requests across namespaces.
Lightweight operators observe usage, generate recommendations, and apply changes on your schedule. No SCC conflicts. No refactoring.
Rightsize requests to real usage, live
The write operator (dakr-op) applies new CPU and memory limits in place using CRIU checkpoint-restore. Pods are never restarted, SCC policies are preserved, and you only approve changes you trust.
Provision the right instance, automatically
DevZero's node operator consolidates idle nodes and provisions cost-optimal instance types per workload class. Works alongside OpenShift MachineAPI with no cluster-wide changes required.
See egress and cross-zone cost per workload
An eBPF DaemonSet (compatible with CRI-O) traces pod-level flows and attributes every cross-zone and egress charge to the workload that generated it. Visibility your cloud console cannot give you.
See the difference DevZero makes across workload resources, node capacity, and egress costs, with the same cluster, the same workloads.
First scan complete · No changes applied yet
Read-only · Open-source at github.com/devzero-inc/zxporter · No cluster changes until you enable automation
Deploy the open-source, read-only zxporter via Helm. See cost recommendations in your DevZero dashboard with no cluster changes and no SCC modifications needed.
Objects created
Nodes provisioned
MachineAPI integration active · Spot interruptions handled automatically · No static MachineSet changes needed
Install the DevZero node operator via Helm. It integrates with OpenShift MachineAPI to provision cost-optimal instance types and handle Spot interruptions automatically.
Scope
Workload types
Migration type
Aggressiveness
Automation enabled · SCC constraints respected · Savings begin immediately
Review recommendations, create workload and node policies in the DevZero dashboard, and scale down static MachineSets to hand off to the node operator.
CRIU applies new CPU and memory limits without restarting the pod. Connections stay open, SCC policies are preserved, and each recommendation is labelled live or restart before you approve.
View write operator →DevZero's node operator provisions the right instance type per workload, consolidates idle nodes, and handles Spot interruptions automatically. Integrated with OpenShift MachineAPI, managed by policy.
Node operator docs →An eBPF DaemonSet (Netfilter or eBPF mode, compatible with CRI-O) tracks pod-level flows and attributes every cross-zone and egress charge to the workload that generated it.
Network operator docs →Scans container images for CVEs, checks clusters against CIS Kubernetes Benchmark and NSA hardening guidelines, and flags RBAC and SCC misconfigurations, all in one dashboard.
Security operator →Manage clusters and policies as code using the official Terraform provider or Pulumi SDKs for TypeScript and Python. Fits existing GitOps and OpenShift GitOps (ArgoCD) workflows.
IaC providers →dz-scheduler runs as a secondary scheduler alongside the default OpenShift scheduler. Pods opt in via schedulerName and are placed on the cheapest viable nodes based on real-time pricing and CRIU compatibility.
Scheduler docs →“We were essentially able to reduce the cost of that cluster by about 75%. On AWS, DevZero demonstrated they could achieve significantly higher savings than we initially thought possible.”

Mihir Nair
Head of Architecture, Databahn
Technical questions from platform engineers who've evaluated DevZero on OpenShift.
Run a free assessment to identify overprovisioned workloads, idle capacity, and your potential savings, in minutes.
Optimize now