Skip to main content
osinfra.io

A team-first, vendor-light, open source reference implementation for cloud infrastructure.

Platform docs, written for the people who use and build it.

๐Ÿš€

Building on the platform

You own a service and want to run it here. One interface, the Nomos Agent, onboards your team and requests everything the platform provides.

Get started โ†’
๐Ÿ› ๏ธ

Building the platform

You own a technical area. Find what each team owns, its interfaces, and the decisions behind them.

See the teams โ†’
๐ŸŒ

Learning from the stack

These docs are the reference implementation: every page describes the live platform, open source end to end.

See the stack โ†’

Start with one clear request

The Nomos Agent turns team requirements into validated, reviewable pull requests. Use the prompt builder to provide the information needed by Logos and any downstream platform services.

Build your agent prompt โ†’
Onboard a new team โ€” Fides. Team key: st-fides. Maintainers: joesmith. Admin email: joe@osinfra.io.

๐Ÿ‘‹ Hi! I'm the Nomos Agent โ€” your self-serve interface to the osinfra.io platform. Give me just a moment while I look you upโ€ฆ

โœ“ get_me โ†’ joesmith ยท joe@osinfra.io ยท osinfra-io member

โœ“ lookup_user โ†’ no existing team memberships

Team key st-fides is a stream-aligned team. Suggested display name: Fides. Confirm, and share a one or two sentence team description โ€” or I can suggest one.

Fides is right. Suggest a description.

Suggested description: "Fides โ€” the platform's trust and verification service." Keep it or rewrite it?

Keep it.

Next, Datadog: should I use joe@osinfra.io as the admin? Then I'll collect GitHub maintainers and Google Cloud groups, one group at a time.

โ€ฆ required fields, then an optional menu: GitHub Actions + GCP OIDC, repositories, GKE, Cloud SQL, projects

Yes. Enable workflows and add repo st-fides-api.

โœ“ open_team_pr โ†’ PR opened on pt-logos

โœ“ open_team_docs_pr โ†’ PR opened on pt-ekklesia-docs

Done. Once the pt-logos PR merges, your team structure and access foundations are created. Cloud and Kubernetes capabilities follow through Corpus and Pneuma.

๐Ÿ”

Guardrails by default

Platform-managed projects include established security controls, encrypted state, audit logging, and policy enforcement. Your team owns its workload while the platform owns the shared guardrails.

๐Ÿ“ฆ

Built on open standards

Infrastructure automation and runtime tooling are built on CNCF and Linux Foundation open-source projects โ€” Kubernetes, Istio, cert-manager, OPA Gatekeeper, OpenTofu, OpenBao. No proprietary abstractions, no lock-in, no black boxes.

๐Ÿค

Innersource, not a bottleneck

Arche, Ekklesia, and Techne run as innersource repositories โ€” any engineer can open a pull request, and platform engineers from staffed teams review. Stream-aligned teams unblock themselves by contributing fixes and new capabilities directly to the platform.

Everything your team needs, out of the box.

From source code management to production support โ€” already in place.

๐Ÿญ
Continuous delivery enablement
GitHub teams and repositories, keyless GCP authentication, Artifact Registry, and reusable deployment workflows.
๐Ÿ—๏ธ
Cloud foundation
CIS-compliant GCP projects across sandbox, non-production, and production, with KMS-encrypted state, shared networking, DNS, and Kubernetes namespaces.
๐Ÿ”’
Security
OpenBao secrets, Istio mTLS, OPA Gatekeeper admission control, Cloud Armor WAF, hardened GKE clusters, and Datadog security monitoring.
๐Ÿถ
Observability and incident response
Platform-managed Datadog integrations provide cluster telemetry and can enable logs, APM, security features, and cloud-cost visibility where configured.