All evals
Upbound

Eval directory

Evals for Upbound

Eval coverage for Upbound, mapped from its public product surface.

About Upbound

Upbound provides intelligent control planes built on Kubernetes and Crossplane for infrastructure and platform teams. Its flagship offering, Upbound Crossplane 2.0, is an enterprise-grade distribution of the open-source Crossplane project that manages both applications and infrastructure declaratively. It is sold in Community, Standard, Enterprise, and Business Critical tiers with consumption-based pricing.

Industry

cloud infrastructure control plane platform (Kubernetes/Crossplane)

Use the eval library for Upbound

We'll build out the full library — runnable test cases with inputs, expected behavior, and pass/fail checks — in your Corsac workspace.

Generate your own →

Coverage map

What would you measure for Upbound?

6 scoring areas · 23 capabilities mapped · grounded in 8 cited pages

Every eval set is graded on

  • Adversarial robustness
  • Workflow quality
  • Safety gates
  • Operator quality

Pass/Fail + LLM judge 1–5 · critical severity flags · negative controls

01

Control Plane Product & Crossplane 2.0 Positioning

Accurately explaining what Upbound Crossplane 2.0 is — an enterprise-grade distribution of the open-source Crossplane project, created by Crossplane's founders — and how it extends the Kubernetes control plane to manage both applications and infrastructure declaratively.

Unlimited Team Members Unlimited Control Planes Enterprise Security www.upbound.io

Mapped capabilities

4 capabilities

  • Distribution vs. upstream Crossplane

    Distinguishes Upbound Crossplane 2.0 from the open-source Crossplane project without overstating exclusivity of upstream features.

  • Applications and infrastructure in one control plane

    Explains the claim that both application and infrastructure resources are managed by the same control plane.

  • Enterprise hardening claims

    Represents stability, security, and scalability positioning as stated, without inventing certifications or benchmarks.

  • Crossplane project relationship and CNCF context

    Handles Upbound's role as an active Crossplane and CNCF contributor and Crossplane's CNCF graduation as described.

02

Plans, Tiers & Consumption Pricing

Correctly conveying the four-tier structure (Community free forever, Standard from $1,000/month, Enterprise custom, Business Critical custom), what each tier adds, and how consumption-based resource pricing layers on top of plan minimums.

Upbound pricing is based on consumption. Plan tiers have consumption minimums. www.upbound.io

Mapped capabilities

4 capabilities

  • Tier feature boundaries

    Maps features to the correct tier, including the cumulative 'everything in the prior tier, plus' structure.

  • Standard tier limits

    Handles the stated caps of up to 5 control planes and up to 10 team members, and where those limits disappear.

  • Consumption and resource billing

    Explains per-resource, per-hour billing, included resources, and the next-10K tier rate as documented.

  • Pricing uncertainty and escalation

    Declines to quote Enterprise/Business Critical numbers and routes to contact-sales rather than estimating.

Illustrative example

Input
We're on the Standard plan at $1,000/month and need to run 8 control planes for 14 engineers. Are we covered?
Expected behavior
States that Standard is limited to 5 control planes and 10 team members, so this exceeds the tier, and points to Enterprise for unlimited control planes and team members with custom pricing. Notes pricing is consumption-based with plan minimums.

03

Agent- and Human-Facing Interfaces

Covering the dual-audience interface story: declarative APIs for agents alongside Web UI for Crossplane, CLI tooling, IDE integrations, and console-based SDLC workflows for humans.

the easy-to-develop, enterprise-grade distribution of the Crossplane open-source project www.upbound.io

Mapped capabilities

4 capabilities

  • Declarative API over GUI/ticket workflows

    Articulates the 'AI needs declarative APIs, not GUIs or tickets' thesis without asserting unstated agent integrations.

  • CLI and IDE tooling scope

    Places CLI tooling and IDE integrations correctly, including their availability starting at Community.

  • Web UI for Crossplane

    Describes managing resources, monitoring health, and troubleshooting without requiring direct YAML editing.

  • Control plane project tooling and SDLC

    Covers design, deploy, and manage workflows across CLI and console as described.

04

Hosting, Spaces & Deployment Model

Distinguishing where control planes actually run — in the customer's own cluster at the Community tier versus Upbound Spaces at Standard and above — plus advanced hosting at the Business Critical tier.

Up to 5 Control Planes Up to 10 Team Members www.upbound.io

Mapped capabilities

3 capabilities

  • Run-in-your-cluster vs. Upbound Spaces

    Assigns each deployment mode to the correct tier and avoids implying Spaces is available for free.

  • Multi-control-plane and group management

    Handles control plane group management as an Enterprise-tier capability.

  • Advanced hosting and SLA posture

    Represents Business Critical advanced hosting and high-SLA positioning as stated, without quoting specific SLA numbers.

Illustrative example

Input
Can I host my control planes in Upbound Spaces on the free Community plan?
Expected behavior
Answers no: Community runs in your own cluster, while running in Upbound Spaces begins at the Standard tier. Offers Standard as the path to Spaces without inventing trial terms or hosting regions.

05

Identity, Security & Compliance Posture

Handling access control and trust questions: Google and GitHub identity with RBAC, enterprise and advanced security tiers, and pointing to the Trust Center, Security & Compliance page, and System Status rather than improvising claims.

Upbound-maintained providers and integrations, built to enterprise standards for performance, security, and compliance. www.upbound.io

Mapped capabilities

4 capabilities

  • Identity providers and RBAC

    States Google and GitHub identity plus RBAC as Standard-tier features without inventing SSO/SAML support.

  • Security tier differentiation

    Separates Enterprise Security from Business Critical Advanced Security as listed.

  • Compliance claim discipline

    Routes audit, certification, and attestation questions to the Trust Center instead of asserting specific frameworks.

  • Supply-chain and vulnerability signals

    Covers official Upbound-maintained packages, patch-release access by tier, and Marketplace vulnerability summaries as described.

06

Adoption, Support & Content Journey

Guiding users through the entry paths the site actually exposes — Get Started, Book a Demo, docs, Slack, and the support contact form — and the support entitlements that differ by tier.

Mapped capabilities

4 capabilities

  • Support channel routing

    Directs product support to docs and the Slack channel first, and the web form as the slower fallback.

  • Support entitlement by tier

    Maps Community support, Enterprise email and ticket support, and Business Critical dedicated support correctly.

  • Migration path from open-source Crossplane

    Handles 'Crossplane to UXP 2.0' questions using the stated no-rewrite deployment claim, without fabricating migration steps.

  • Events, blog, and resource discovery

    Surfaces events (e.g. KubeCon + CloudNativeCon Amsterdam, Mar 23–26, 2026), blog, and customer stories accurately, including dates.

Coverage is mapped from Upbound's public pages (8 crawled). Examples are illustrative, not real test cases. The runnable eval library — graded inputs, expected behavior, and pass/fail checks — is built when you request it above.

Frequently asked questions

What do the Corsac evals for Upbound test?+

The coverage map is generated from Upbound's own public product surface (cloud infrastructure control plane platform (Kubernetes/Crossplane)): 6 scoring areas — Control Plane Product & Crossplane 2.0 Positioning, Plans, Tiers & Consumption Pricing, and Agent- and Human-Facing Interfaces, and more — spanning 23 mapped capabilities, each graded on adversarial robustness, workflow quality, safety gates, and operator quality once the library is built.

How are the Upbound evals scored?+

Every case generated for Upbound — across Control Plane Product & Crossplane 2.0 Positioning and Plans, Tiers & Consumption Pricing and the other mapped areas — is graded with pass/fail checks plus an LLM judge scoring 1–5 against its expected behavior, with critical-severity flags and negative controls. Only judge-passed evals are published.

How many test cases does the Upbound library include?+

The full Upbound library is built on request. The coverage map spans 6 areas and 23 capabilities (for example, Distribution vs. upstream Crossplane and Applications and infrastructure in one control plane under Control Plane Product & Crossplane 2.0 Positioning); each becomes graded test cases — inputs, expected behavior, pass/fail checks — in your Corsac workspace.

How do I run these evals against Upbound or my own agent?+

Request the library with your work email above. We'll build out all 6 mapped Upbound areas and set them up in a Corsac workspace, where you can run every test case against Upbound or your own agent with your own data.