Skip to main content

Product · Bare Metal Lifecycle

Stop provisioning racks by hand and hoping firmware is current.

One-off provisioning scripts mean every rack ends up configured slightly differently, and nobody's confident firmware is current until something fails. IronWolf brings racks, firmware, and maintenance for your bare-metal fleet — physical servers, not virtual machines — into the Kubernetes API, with remote power and reconfiguration (BMC) included and a dedicated-server portal for tenants in the same dashboard.

Kubernetes-nativeMulti-protocol BMCMetal3-alignedOps + tenant portalFirmware automationClick, don't script — full ops in the console

Product demo

See IronWolf in action

A walkthrough from a live IronWolf deployment — Ops dashboard (hosts, claims, pools, firmware, images, power, topology, cluster, observability). The same binary also ships Customer Portal mode for dedicated-server tenants.

How it works

From bare rack to production host

1

Discover the hardware

Metal3 BareMetalHost discovery and inventory pulls BMC details automatically via IPMI, Redfish, iLO, or iDRAC.

2

Build a golden image

ImageRecipe → ImageBuild → ImageArtifact produces a checksummed, approved OS image before it ever touches a host.

3

Provision from a hardware pool

Binpack, spread, or topology-aware scheduling places workloads on hosts grouped by capability or location.

4

Keep firmware and BIOS current

Declarative firmware profiles schedule BIOS, BMC, and NIC upgrades during maintenance windows, with pre/post validation.

5

React to hardware events in real time

BMCEventSubscription streams Redfish thermal, power, and fault events as they happen — no polling.

6

Back up and remediate automatically

Scheduled HardwareBackup snapshots BIOS/BMC/RAID config, and remediation policies handle failures with escalation and rollback.

Read the IronWolf docs

Why it exists

IronWolf

Bare-metal servers, provisioned through Kubernetes. One-off provisioning scripts mean every rack ends up configured slightly differently, and nobody's confident firmware is current until something fails. IronWolf brings racks, firmware, and maintenance into the Kubernetes API, with a dedicated-server portal for tenants in the same dashboard.

Feature pillars

What you get

Kubernetes-native bare metal

Pools, firmware, remediation, plus portal HostIP, monitors, and tickets — all tracked as Kubernetes resources.

Ops + Portal

One dashboard shell serves both your operations team and a tenant-scoped view for customers — no second app to run.

Multi-protocol BMC

Remote power and reconfiguration (IPMI, Redfish, iLO, iDRAC) without walking to the rack.

Metal3-aligned

Provision, wipe, firmware update, and decommission on BareMetalHost.

Differentiators

Built for production

The provisioning layer: bare-metal servers get brought under management before the Kubernetes and VM layers go on top.

Why teams choose us

  • Lays the physical groundwork other suite products build on — Kubernetes clusters, VMs and confidential-computing (TEE) prep via HyperCluster
  • Tenant Cart, Usage, Support, Monitoring, and IP management without a second app
  • Built on Metal3-aligned patterns with Zyvor enterprise hardening

When to choose

  • You want racks provisioned through Kubernetes, not legacy DCIM (data center infrastructure management) tools alone
  • You need an operator console and a customer-facing dedicated-server portal together
  • Kubernetes and confidential-computing workloads need verified, trustworthy hardware underneath them first
FAQ

IronWolf questions

How it flows

How it works

CLIvbmctl ironic nodes

Migrate from the platforms you already run

  • Enterprise Hypervisors
  • HCI Platforms
  • AWS
  • Azure
  • Google Cloud
  • Windows Hypervisor
  • Oracle Cloud
  • Machina fleet cloud
  • KubeVirt
  • KVM
  • KVM-based Platforms
SOC2-ready postureRBAC + audit logging99.9% SLA targetAir-gap programs

Key Capabilities

Full host lifecycle on Kubernetes

Every stage of a server's life — from first power-on to final decommission — managed the same way, as Kubernetes resources extending Metal3 Bare Metal Operator.

Hardware Discovery

Automatic bare metal host discovery and inventory management with BMC integration via Metal3.

Firmware Automation

Declarative firmware profiles for BIOS, BMC, and NIC firmware. Schedule upgrades during maintenance windows.

Power Policies

Kubernetes-native power management with scheduled power states, idle detection, and energy-aware scheduling.

Hardware Pools

Group hosts by capability, location, or purpose. Three scheduling strategies: binpack, spread, and topology-aware.

Maintenance Windows

Scheduled maintenance with automatic workload evacuation, cordoning, and post-maintenance validation.

Remediation

Automatic hardware remediation with configurable strategies, escalation policies, and integration with alerting systems.

Observability

Full-stack bare metal visibility

See the health of the entire fleet at a glance, with alerts routed wherever your team already looks — one web dashboard, Grafana integration, and multi-channel alerting.

React Dashboard

Full-featured web UI for host lifecycle operations with real-time status updates — trigger firmware upgrades, power policies, and remediation with a click, no CLI required.

Prometheus Metrics

Built-in Prometheus metrics for hardware health, power consumption, firmware versions, and pool utilization.

Alerting

Slack, email, and webhook alerting for hardware failures, firmware drift, and maintenance schedule violations.

Integration

Fits your infrastructure stack

IronWolf is the provisioning layer: bare-metal servers get brought under management before the Kubernetes and VM layers go on top.

Metal3 Native

Extends the Metal3 Bare Metal Operator. Compatible with existing Metal3 deployments and Ironic integrations.

Terraform & Crossplane

Provision and manage bare metal hosts from Terraform or Crossplane alongside your cloud infrastructure.

Grafana Dashboards

Pre-built Grafana dashboards for hardware fleet health, power consumption trends, and capacity planning.

Security & Compliance

Harden the metal, attest the boot, prove the compliance

Set your hardware security baseline once and enforce it across the whole fleet — secure boot, TPM (a hardware chip that proves a machine hasn't been tampered with) checks, BMC hardening, compliance scanning, and intrusion detection all come from a single SecurityPolicy.

Secure Boot, TPM & BMC Hardening

Enforce secure boot, TPM requirements, and BMC hardening — HTTPS-only access, minimum TLS, allowed networks, password policy, and certificate rotation — from a single SecurityPolicy.

CIS / NIST / DISA STIG Scanning

Schedule compliance scans against CIS, NIST, and DISA STIG standards with optional auto-remediation and multi-format reports.

TPM Attestation & Intrusion Detection

Verify hosts against a PKIX-backed attestation server on a refresh interval, and watch for port scans, brute-force attempts, and hardware tampering with alert, lockdown, or IP-block actions.

Networking

Program the fabric alongside the hosts it connects

Manage the switches your servers plug into with the same tooling as the servers themselves — VLANs, BGP routing, and access rules (ACLs) across a mixed-vendor switch estate, via NetworkProfile and NetworkSwitchProfile.

Multi-Vendor Switch Control

Automate Arista, Cisco, Juniper, and Mellanox switches over eAPI, NETCONF, RESTCONF, or SSH via the NetworkSwitchProfile resource — one workflow for a mixed-vendor switch estate.

NetworkProfile

Declare VLANs, BGP peering, and ACLs and apply them to matching hosts and switches as one reconciled resource.

Interface Profiles & Bonding

Define host interface layouts including bonds (802.3ad, active-backup, balance-rr), MTU, and per-interface VLAN assignments.

BGP & ACL Policy

Configure BGP autonomous systems, peers, and advertised prefixes, plus permit/deny ACL rules with logging.

Customer Portal

A dedicated-server portal in the same dashboard

Toggle Ops | Portal in the menu bar — the same dashboard serves both your operations team and a tenant-scoped view for customers, so you're not running a second app just for customer self-service.

Bare Metal Host Tabs

Per-server Overview, Traffic, Power, Installation, Networking, and Remote Access (SSH config, Deploy SSH, OpenVPN profile) — tenant day-2 without exposing the full Ops nav.

IP Management

Addresses synced from BareMetalHost NIC inspection via the HostIPAddress CRD, with reverse DNS edit/publish, block/unblock, and family filters.

Availability Monitoring

HTTP/TCP/ICMP checks with probe status, pause/resume, rename, and clone — uptime monitoring without a separate product.

Support Desk

Create and reply to tickets via the SupportTicket CRD, with phase/priority filters and Slack/email/webhook notifications.

Cart, Usage & Storage

SKU-based quoting that opens a sales support ticket at checkout (no card charging), Prometheus-backed bandwidth and invoice views, and an object storage browser for tenant buckets.

Image Factory

Build golden OS images, not just provision them

Know exactly what OS image landed on every host, and rebuild it identically on demand — a GitOps image pipeline (ImageRecipe → ImageBuild → ImageArtifact) makes the image Metal3 writes to a host reproducible from source, not a one-off snapshot.

ImageRecipe Templates

Long-lived build templates pinning OS family, Kubernetes version, provider make-target, node profile, and an embedded security policy. Change the recipe, get a new image.

Pluggable Executors

ImageBuild runs on auto, lab, or kubernetes executors. Auto picks the right backend; Kubernetes runs the build as an in-cluster Job.

Checksummed Artifacts

Every ImageBuild records a checksum and a resolved manifest URI, so provisioning references a verifiable, immutable image.

Approval & Promotion

ImageArtifact catalogs each built golden image with an approval gate and promotion field — only approved images flow to production hosts.

Real-Time BMC Events

Redfish event streaming, not polling

Find out about a hardware problem the moment it happens, not on your next check-in cycle — BMCEventSubscription registers against a host's Redfish EventService so the BMC pushes hardware events in real time.

Native Redfish Subscriptions

Subscribe a BareMetalHost to its BMC EventService. Thermal, power, and hardware fault events arrive as they occur instead of on a poll interval.

Webhook Delivery

Events post to an HTTPS destination with a per-subscription context tag and optional custom headers loaded from a Kubernetes Secret.

Managed Lifecycle

The controller creates and reconciles the Redfish subscription ID and cleans it up via finalizer when the resource is deleted.

Hardware DR

Back up and restore BMC & BIOS config

If a BIOS or BMC misconfiguration takes a host down, roll it back instead of reconfiguring by hand — HardwareBackup and RestoreJob CRDs give scheduled capture and point-in-time restore of hardware configuration.

Scheduled Config Backups

HardwareBackup runs on a cron schedule across a host label selector, capturing BIOS, BMC, firmware, RAID, network, and partition config with a retention count.

Post-Backup Verification

Optional verification validates each backup after capture, so a stored backup is known-good before you ever need it.

Selective Restore

RestoreJob restores a chosen backup to a target host, component by component, with dry-run and force options.

Rollback on Failure

Restores can roll back automatically if a component fails mid-apply, avoiding a half-configured host.

30-Day Trial

Get full access — request your trial

Run IronWolf on your bare metal fleet with full lifecycle automation, BMC drivers, and a complete operator console. Onboarding included.

Request 30-Day Trial

Full Feature Access

Full bare-metal control plane, 4 BMC protocols (IPMI, Redfish, iLO, iDRAC), hardware pool scheduling, and the complete operator console — nothing gated.

Delivered via Helm

Deploy the operator and dashboard with a single Helm command into your Kubernetes cluster alongside Metal3.

Onboarding Session

A 45-minute walkthrough with the Zyvor team to configure BMC access, firmware profiles, and hardware pool policies.

After the Trial

Move to a commercial licence with no data loss. Hardware pools, firmware profiles, and policies carry forward.

Kubernetes 1.32+Metal3 BareMetalOperatorIPMI / Redfish / iLO / iDRACHelm 3.xGo 1.25+
Metal3 automation

Enterprise CRDs on top of BMO

Extends Metal3 Bare Metal Operator for fleet programs — policy, host lifecycle, BMO integration, and a Customer Portal for tenants.

Hardware pools & claims

Binpack, spread, and topology-aware scheduling with quotas and priorities.

Firmware & power

Declarative BIOS/BMC profiles, power policies, and energy-aware consolidation.

Maintenance & remediation

Draining maintenance windows and progressive auto-remediation strategies.

Customer Portal

Ops | Portal modes — Bare Metal tabs, Cart checkout, Usage & invoices, Support tickets, Monitoring, IP/rDNS, Storage, Account.

Network & security policies

NetworkProfile, SecurityPolicy (TPM/secure boot), bulletins/scans, and EnergyPolicy for carbon-aware bare metal.

BMC drivers & telemetry

IPMI, Redfish, iDRAC, iLO; TelemetryPolicy, HardwareBackup/RestoreJob, and Prometheus-backed traffic when configured.

Resources

Signature deck

Download the h2kvm-format PDF or open the HTML preview for stakeholder reviews.

Overview

A4 portrait · purple cover · orange accent (h2kvm style)

Browse all 11 IronWolf decks

Free trial

30-day guided trial — IronWolf

Bare-metal fleet provisioning with BMC and a tenant portal.

  • Scoped trial against your rack / lab
  • Ops + tenant portal walkthrough
  • Engineer support during evaluation

After the trial window, it is completely up to you whether to continue. There is absolutely no pressure or obligation from our side.

Ready to manage bare metal at scale?

See how IronWolf brings Kubernetes-native lifecycle management to your bare metal infrastructure.