IaC Adoption

Turn unmanaged cloud into reviewed code.

Discover what exists, create the first reviewable code from reality, and move into policy, review, and deployment without waiting for a perfect greenfield reset.

No blank repo to start
First fix from live state
Policy and approval from day one
Git review, not a rewrite

ops0 brings your clouds, runtime, infrastructure code, and workflows into one operating context. IaC adoption starts from live cloud discovery, codifies brownfield resources into Terraform, OpenTofu, or Oxid, and routes the first fix through policy, cost, and approval before it becomes an incident.

ops0.ai/use-cases/iac-adoption
ops0 reviewed IaC: generated Terraform for a discovered resource with policy checks, cost change, and a plan summary before apply

Most estates were built by hand, one console click at a time. You can bring them under code without starting over. 

Brownfield firstOne service at a timeReviewed pull requestsTerraform, OpenTofu, Oxid
The adoption journey
01 / 04 · Unmanaged

Start with what exists.

The estate is discovered as it is: services, databases, networks, none of it in code.

checkout-svcpayments-ledgerbilling-servicenotificationsreporting-apiauth-svc0%UNDER CODE0 of 6 services
0%under code
Going deeper

From discovered to governed, one service at a time.

Start from reality

Adoption begins with what is already running.

Discovery-first beats writing code against guesses.
Works for brownfield infrastructure and undocumented estates.
Resources
248
discovered
Unmanaged
181
not in any state file
Engine
OpenTofu
selected target
First fix
1
ready to generate
Codify toTerraformOpenTofuOxid
Under the hood

No blank repo. Just the estate you already run.

Brownfield first
Start from what is running, not a template.
Discovered
rds-payments-ledger-prodRDSunmanaged
billing-serviceECSunmanaged
notifications-workerLambdaunmanaged
checkout-albALBin Terraform

248 resources discovered, 181 not yet in any state file. Adoption starts from that list, not a clean-room rewrite.

Codified
Generated from live state, not a guess.
resource "aws_db_instance" {
  publicly_accessible = false
}
Reviewed
Every step is a pull request.
PR #851in review

Git review is the handoff, not a rewrite to reconcile.

Move at your pace
No big-bang cutover.
3 of 12 services25%

One PR at a time. Cutover required: none.

Ask Kiwi
Describe it, get reviewed code back.
@ops0 codify the billing-service database
Generated from its live config and opened as PR #851. Policy and cost checks are attached.

Common questions

ops0 discovers existing resources first, then helps generate reviewable IaC that reflects live infrastructure instead of starting from blank templates. Engineers can also describe what they need to Kiwi and get reviewed code back.

Start from the estate.
End with reviewed code.

IaC adoption does not need a blank repository. The first reviewed pull request comes from the infrastructure you already run.

Explore IaC