Resource graph

See what breaks before it breaks.

ops0 maps dependencies and blast radius from live state, so you know what a change or a failure touches before it happens. Not sure? Ask Kiwi.

Live-state topology
Blast radius before a change
Drift-aware graph
Queryable infrastructure

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. Resource Graph maps infrastructure dependencies, ownership, and blast radius from live, drift-aware state, so teams see what a change or an incident touches before it happens.

ops0.ai/features/resource-graph
ops0 resource graph query console: a natural-language query returns production resources with active security findings and monthly spend, and the blast radius panel shows that changing aws_db_instance.main affects 6 downstream resources across 1 level

A diagram shows what someone drew. The graph shows what is actually connected. 

Live stateUpstream and downstreamDrift-awareQueryable
Blast radius, live
01 / 04 · Build

Built from live state.

ops0 reads what is running across your accounts and draws every real connection. Nobody maintains this diagram.

rds-payments-ledger-prodcheckout-svcECSledger-apiECSsettlement-jobBATCHfraud-workerLAMBDAcheckout-albALBpayouts-svcECSreconciliation-cronCRONanalytics-streamKINESISchargeback-queueSQSapp.asteron.ioROUTE 53partner-webhooksWEBHOOKauth-svcECSsession-cacheELASTICACHEmarketing-siteS3cdn-assetsCLOUDFRONT
0
dependents
0
teams
Going deeper

More than a picture of your cloud.

Variable impact

Trace one variable everywhere it lands.

Change a shared variable and see every folder, module, and project it reaches.
Outputs and references are followed across module boundaries.
Variable impact7 affected
private_subnet_count change in network-core
ECS Servicecheckout-service
VPCpayments-vpc
Lambdafraud-worker
Kinesis Streamanalytics-pipeline
Severity
High
Change type
Shared subnet variable
Consumers
4 downstream projects
Drift linked
2 resources
Under the hood

A graph you can query, not just look at.

Queryable
Ask the graph a real question.
Question
Which production resources depend on the payments ledger and are exposed to the internet?
Answer from live state
fraud-workerLambdapublic endpoint
checkout-albALBinternet-facing
partner-webhooksWebhookoutbound only

Plain language or SQL-style queries, answered from database-backed state.

Both directions
What it needs, and what needs it.
Import order
Brought into code in the right order.
  1. 1payments-vpc
  2. 2private-subnets
  3. 3sg-payments-db-admin-prod
  4. 4rds-payments-ledger-prod
Live, not drawn
Rebuilt from every discovery scan.

Nodes and edges come from what is running across accounts, including cross-account links. Nobody redraws it after a change.

Kiwi in Slack
Ask where the incident is already happening.
@ops0 what depends on the payments ledger?
11 services across 5 teams. fraud-worker is the only one that reaches it over the public endpoint.

Common questions

Resource Graph is a view of infrastructure relationships, dependencies, state files, drift, and blast radius across cloud and Kubernetes resources.

Know what it touches
before you touch it.

Every dependency, owner, and blast radius in one queryable graph. Ask Kiwi what a change will reach, then ship it through Workflows.

Explore Workflows