Configuration changes

Change configuration without bypassing control.

Unsafe Ansible and Kubernetes changes are how incidents start. ops0 routes them through the same reviewed fix path as IaC, with policy, dry-run, approval, and evidence before anything executes.

Ansible and Kubernetes
Policy checks injected
Dry-run before execute
Ships through Git

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. Ansible and Kubernetes configuration changes travel the same reviewed fix path as infrastructure as code, with policy checks, dry-run, approval, and evidence captured before execution, so unsafe changes are stopped before they cause an incident.

ops0.ai/features/configurations
ops0 configuration management: an AI-generated hardened Helm chart for the checkout service with a non-root security context, a NetworkPolicy, a secret-sourced database URL, and autoscaling, alongside validation, policy checks passed, Git sync, and a dry-run before deploy to the payments-prod namespace

A one-line config change can restart a whole fleet. So every change here dry-runs first. 

AnsibleHelmkubectlkustomizeGit review
Dry run first
01 / 04 · Describe

Describe the change.

Ask Kiwi to rotate the TLS certificate on the web tier. It writes the Ansible playbook.

ROTATE-TLS.YMLAWAITING APPROVALAPPROVED0 / 18 changedweb-01web-02web-03web-04web-05web-06web-07web-08web-09web-10web-11web-12web-13web-14web-15web-16web-17web-18web-19web-20web-21web-22web-23web-24
Going deeper

Configuration, through the same checks.

From intent

Generate configuration in the same fix path.

Describe the change to Kiwi and get Ansible or Kubernetes config back.
Policy checks are injected into what gets generated.
Generated from requestAnsible
app-config.yaml
- hosts: web
become: true
tasks:
- name: enforce firewall baseline
ufw:
rule: deny
port: "22"
src: 0.0.0.0/0
Policy checks: on
Kubernetes target: ready
Under the hood

Built for the tools you already run.

Ansible and Kubernetes
Generate for the tools you already run.
values.yaml
replicaCount: 3
image:
repository: checkout-svc
tag: 2.14.1
resources:
requests: { cpu: 250m }
Ansible
Helm
kubectl
kustomize

Playbooks for hosts, manifests for clusters, generated from one request and reviewed the same way.

Ships through Git
Every change is a pull request.
ops0/config/prod-web-group → main
PR #482 · synced
Policy on every change
Checked before it ships.
12 rulesPassed
Server groups and keys
Credentials never sit in the open.
web-tier-key
SHA256:9f2c...e14a

Keys are stored encrypted. Only the fingerprint is ever shown.

Server inventory
Linux and Windows, one inventory.
web-07ubuntu 22.04reachable
web-12ubuntu 22.04reachable
win-dc-02windows server 2022reachable
Kyverno for clusters
Policy installed on every connected cluster.
payments-prod
kyverno installed
checkout-staging
kyverno installed
data-prod
deploying

Common questions

ops0 helps generate, validate, and govern Ansible playbooks and Kubernetes manifests inside the same infrastructure operating model.

Ansible and Kubernetes,
through the same checks.

Every Ansible and Kubernetes change earns the same policy, dry-run, and approval path as your infrastructure code.

Explore Workflows