How ClusterValidator works offline
One of the first questions people ask: does ClusterValidator need to call home?
No. Not at install, not at startup, not during a run.
Why that is the requirement
The common licensing model starts with a call to a license server, and if the server does not answer, the tool does not start. That model is fine for an online service. It is wrong for infrastructure validation, because the moment you most need to check a cluster is the moment your network is misbehaving, and that is precisely when a license server is unreachable.
What happens instead
When you buy:
1. Pay through Stripe or a cloud marketplace
2. Our license service generates and signs a small license file
3. The file arrives by email (about 2 KB)
When you run:
1. Put the file where the product runs
2. ClusterValidator checks the signature locally,
against a public key that ships with the product
3. Valid signature, valid license. No network call.
The license file is cryptographically signed. The private key stays with us; the public key is on your machine, so the check needs nothing beyond the file itself. Cancel later and the file you already hold still runs to its own end date plus a short grace period, which the terms say out loud rather than leaving you to discover.
The free tier is simpler still: 2 clusters a calendar month needs no license file at all.
What this gets you
For operations, the validator works during a network outage, which is the entire point of having one.
For an auditor, there is no black box. The signature can be verified locally, the product makes no outbound calls at run time, and nothing about your cluster leaves your network.