Integrations

Connect the tools your cloud already runs on.

ops0 plugs into your clouds, IaC engines, clusters, repositories, and vaults, so cloud risk becomes reviewed fixes with audit evidence, inside the workflow you already use.

AWS, GCP, Azure, and OCI
Terraform, OpenTofu, and Oxid
GitHub and GitLab pull requests
External secret vaults

ops0 integrations connect AWS, GCP, Azure, and OCI, Terraform, OpenTofu, and Oxid, Ansible and Kubernetes, GitHub and GitLab, and external secret vaults, so cloud risk becomes reviewed fixes with audit evidence.

4
Clouds
AWS · GCP · Azure · OCI
230+
Resource types
across four clouds
3
IaC engines
Terraform · OpenTofu · Oxid
2
Git platforms
GitHub and GitLab
Read-only
Access
no write path
Clouds

Connect every cloud, read-only first.

AWS

Scan live state across accounts and regions, with least-privilege read-only access.

Google Cloud

Discover and govern Google Cloud resources inside the same reviewed workflow.

Microsoft Azure

Bring Azure subscriptions under continuous discovery, policy, and cost checks.

Oracle Cloud (OCI)

Extend the same discovery and governance model to Oracle Cloud Infrastructure.

Infrastructure as code

Generate and manage code in your engine.

Terraform

Generate, import, plan, and apply Terraform, with policy and cost checked before apply.

OpenTofu

Full OpenTofu support with the same reviewed generate, import, and apply flow.

Oxid

The database-backed IaC engine by ops0, with queryable, SQL-style state.

Configuration

Govern configuration, not just provisioning.

Ansible

Author and check playbooks through the same policy and approval path.

Kubernetes manifests

Validate manifests with dry-run previews before they reach a cluster.

Helm, kubectl, kustomize

Work with the tooling your platform team already uses to ship configuration.

Kubernetes

Link cluster risk back to the change.

EKS, GKE, AKS, OKE

Connect managed clusters across AWS, Google Cloud, Azure, and Oracle Cloud.

Self-managed clusters

Bring your own clusters into the same posture, cost, and incident view.

Incidents to code

Every incident links back to the deploy and the IaC that owns the resource.

Version control and pull requests

Keep your repository the source of truth.

GitHub

Reviewed fixes arrive as pull requests, with branches, commits, and sync status tracked.

GitLab

The same pull-request workflow and merge-based governance on GitLab.

Secrets and vaults

Reference secrets without exposing them.

AWS Secrets Manager

Reference values at apply time, never stored in code and never sent to the AI.

GCP Secret Manager

Pull secrets by reference and inject them only when a change is applied.

Azure Key Vault

Bind Key Vault secrets to variables that resolve server-side at apply.

Oracle Vault and external vaults

Use Oracle Vault or an external vault, with the same inject-at-apply model.

Compliance frameworks

Check against the standards you report on.

SOC 2 and CIS

One policy engine gates deploys and scans live state against these standards.

ISO 27001 and ISO 27002

Evidence carries over where controls are cross-mapped between frameworks.

HIPAA and GDPR

Frameworks ops0 evaluates your cloud against, not certifications held by ops0.

How it fits together

Every connection feeds one governed path.

01
Connect

Attach clouds, clusters, repos, and vaults with least-privilege, read-only access.

02
Check

Policy, cost, and compliance run against live state and the proposed change.

03
Approve

A reviewer sees plan, policy results, cost, and dependencies before anything applies.

04
Ship and record

The fix lands as a pull request, applies on approval, and captures audit evidence.

Common questions

ops0 connects to AWS, Google Cloud, Microsoft Azure, and Oracle Cloud Infrastructure, covering more than 230 resource types across the four clouds. Every connection is read-only by default, with least-privilege access and no write path, so discovery never changes anything in your cloud.

Connect your stack,
turn risk into reviewed fixes.

Start with read-only access to one cloud account. Every connection feeds the same governed path.

See pricing