Skip to main content
osinfra.io

A team-first, vendor-light, open source reference implementation for cloud infrastructure.

πŸ”

Guardrails by default

Platform-managed projects include established security controls, encrypted state, audit logging, and policy enforcement. Your team owns its workload while the platform owns the shared guardrails.

πŸ“¦

Built on open standards

Infrastructure automation and runtime tooling are built on CNCF and Linux Foundation open-source projects β€” Kubernetes, Istio, cert-manager, OPA Gatekeeper, OpenTofu, OpenBao. No proprietary abstractions, no lock-in, no black boxes.

πŸ€–

A self-service entry point

The Nomos Agent collects team requirements, validates them, and proposes reviewed infrastructure changes through pull requests.

🀝

Innersource, not a bottleneck

Arche, Ekklesia, and Techne run as innersource repositories β€” any engineer can open a pull request, and platform engineers from staffed teams review. Stream-aligned teams unblock themselves by contributing fixes and new capabilities directly to the platform.

Start with one clear request

The Nomos Agent turns team requirements into validated, reviewable pull requests. Use the prompt builder to provide the information needed by Logos and any downstream platform services.

Build your agent prompt β†’
Onboard a new team β€” Fides. Team key: st-fides. Maintainers: joesmith. Admin email: joe@osinfra.io.

πŸ‘‹ Hi! I'm the Nomos Agent β€” onboarding a new team for you now.

Give me just a moment while I look you up…

βœ“ get_me β†’ joesmith Β· joe@osinfra.io Β· osinfra-io member

βœ“ lookup_user β†’ no existing team memberships found

Welcome! I have everything I need from your prompt. Here's what I'll create for st-fides:

  • πŸ“ GCP folder β€” Fides with Sandbox / Non-Production / Production sub-folders
  • πŸ‘₯ Google Identity groups β€” admin, reader, writer per environment
  • πŸ™ GitHub parent team st-fides + 4 standard child teams
  • 🐢 Datadog team β€” Fides, admin: joe@osinfra.io

Any optional features to enable β€” Google Cloud project, OpenTofu state management, or additional GitHub repositories?

Enable google project and workflows. Add repo st-fides-api.

βœ“ open_team_pr β†’ PR #142 opened on pt-logos

Done β€” PR #142 is open on pt-logos. Once it merges, your team structure and access foundations will be created.

Optional cloud and Kubernetes capabilities are proposed through the owning platform repositories and follow their sandbox, non-production, and production workflows.

Everything your team needs, out of the box.

From source code management to production support β€” already in place.

🏭
Continuous delivery enablement
GitHub team structure with branch protection, Workload Identity and OIDC federation for keyless GCP auth, Artifact Registry, encrypted state buckets, reusable GitHub Actions called workflows, and Datadog CI Visibility and Test Optimization.
πŸ—οΈ
Cloud foundation
CIS-compliant GCP projects with audit logging, billing budgets, and KMS-encrypted state across sandbox, non-production, and production β€” with Shared VPC networking, per-team DNS subdomain zones, Cloud NAT, managed data services (Cloud SQL, Private Services Access), and namespace provisioning with Workload Identity bindings.
πŸ”’
Security
OpenBao for dynamic credentials, KV2 paths, and a Kubernetes secrets operator β€” plus Cloud Armor WAF, Istio mTLS with automated certificate rotation, OPA Gatekeeper admission control, CIS-hardened GKE clusters, GitHub secret scanning and Dependabot, and Datadog Application Security Management, SIEM, Cloud Security Posture Management, and Code Security.
🐢
Observability and incident response
Platform-managed Datadog integrations provide cluster telemetry and can enable logs, APM, security features, and cloud-cost visibility where configured.
πŸš€

Onboard your team

Use the Nomos Agent to describe your team, required repositories, and optional infrastructure capabilities.

Get started β†’
πŸ—ΊοΈ

Explore the Platform

Understand the team topology β€” how the platform is organized, what each team owns, and how the layers fit together.

See the teams β†’
🌐

Explore the Ecosystem

The open-source tools and infrastructure that power the platform β€” GCP, OpenTofu, GKE, Istio, Datadog, OpenBao, GitHub Actions, and more.

See the stack β†’