Integrations

Keep your tools. Connect what they know.

ops0 plugs into your clouds, IaC engines, clusters, repositories, vaults, and Slack, and brings what they know into one picture of your cloud, inside the workflow you already use.

AWS, GCP, Azure, and OCI
Terraform, OpenTofu, and Oxid
GitHub and GitLab pull requests
External secret vaults

ops0 integrations connect AWS, GCP, Azure, and OCI, Terraform, OpenTofu, and Oxid, Ansible and Kubernetes, GitHub and GitLab, and external secret vaults, so cloud risk becomes reviewed fixes with audit evidence.

4
Native clouds
plus any Terraform provider
4
IaC engines
Terraform · OpenTofu · Oxid · CFN
4
Secret vaults
AWS · GCP · Azure · Oracle
2
Git platforms
GitHub and GitLab
Read-only
Access
no write path
Clouds

Connect every cloud, read-only first.

AWS

Scan live state across accounts and regions, with least-privilege read-only access.

Google Cloud

Discover and govern Google Cloud resources inside the same reviewed workflow.

Microsoft Azure

Bring Azure subscriptions under continuous discovery, policy, and cost checks.

Oracle Cloud (OCI)

Extend the same discovery and governance model to Oracle Cloud Infrastructure.

Any Terraform provider

Generic Cloud projects run SaaS, identity, observability, and other providers through the same plan, policy, and approval path.

Infrastructure as code

Generate and manage code in your engine.

Terraform

Generate, import, plan, and apply Terraform, with policy and cost checked before apply.

OpenTofu

Full OpenTofu support with the same reviewed generate, import, and apply flow.

Oxid

The database-backed IaC engine by ops0, with queryable, SQL-style state.

CloudFormation

Run CloudFormation projects with parameter checks before apply, or convert stacks to Terraform or OpenTofu.

Configuration

Govern configuration, not just provisioning.

Ansible

Author and check playbooks through the same policy and approval path.

Kubernetes manifests

Validate manifests with dry-run previews before they reach a cluster.

Helm, kubectl, kustomize

Work with the tooling your platform team already uses to ship configuration.

Kubernetes

Link cluster risk back to the change.

EKS, GKE, AKS, OKE

Connect managed clusters across AWS, Google Cloud, Azure, and Oracle Cloud.

Self-managed clusters

Bring your own clusters into the same posture, cost, and incident view.

Incidents to code

Every incident links back to the deploy and the IaC that owns the resource.

Version control and pull requests

Keep your repository the source of truth.

GitHub

Reviewed fixes arrive as pull requests, with branches, commits, and sync status tracked.

GitLab

The same pull-request workflow and merge-based governance on GitLab.

Secrets and vaults

Reference secrets without exposing them.

AWS Secrets Manager

Reference values at apply time, never stored in code and never sent to the AI.

GCP Secret Manager

Pull secrets by reference and inject them only when a change is applied.

Azure Key Vault

Bind Key Vault secrets to variables that resolve server-side at apply.

Oracle Vault and external vaults

Use Oracle Vault or an external vault, with the same inject-at-apply model.

Compliance frameworks

Check against the standards you report on.

SOC 2 and CIS

One policy engine gates deploys and scans live state against these standards.

ISO 27001 and ISO 27002

Evidence carries over where controls are cross-mapped between frameworks.

HIPAA and GDPR

Frameworks ops0 checks your cloud against, with evidence ready for review.

ops0 is SOC 2 Type II

The platform you connect to is itself SOC 2 Type II audited.

Kiwi and your team

Ask Kiwi where your team already works.

Slack

Mention @ops0 or use /ops0 to ask Kiwi about projects, clusters, and cloud accounts, with answers kept in the thread.

Slack and webhook alerts

Route approvals, drift, and policy alerts to Slack or any HTTPS webhook, with every delivery logged.

OpenObserve

Send deployment events and product telemetry to your OpenObserve instance.

Security and cost engines

The scanners you trust, in one place.

Checkov, TFLint, Infracost

Security and lint findings shown on the exact line, plus a cost estimate on every plan.

Prowler, Nuclei, Cloud Custodian

Three engines scan live cloud in parallel, and findings are correlated so agreement raises confidence.

Trivy, Kyverno, OpenCost

Container scanning, cluster admission policy, and Kubernetes cost allocation, installed and managed from ops0.

How it fits together

Every connection adds to one picture.

01
Connect

Attach clouds, clusters, repos, and vaults with least-privilege, read-only access.

02
Check

Policy, cost, and compliance run against live state and the proposed change.

03
Approve

A reviewer sees plan, policy results, cost, and dependencies before anything applies.

04
Ship and record

The change lands as a pull request, applies on approval, and captures audit evidence.

Common questions

ops0 connects to AWS, Google Cloud, Microsoft Azure, and Oracle Cloud Infrastructure, covering more than 230 resource types across the four clouds. Every connection is read-only by default, with least-privilege access and no write path, so discovery never changes anything in your cloud. Beyond the four native clouds, Generic Cloud projects run any compatible Terraform or OpenTofu provider through the same plan, policy, and approval path.

Keep your tools.
See them as one picture.

Start with read-only access to one cloud account. Every connection adds to the same picture of your cloud.

See pricing