Skip to main content
osinfra.io

A team-first, vendor-light, open source reference implementation for cloud infrastructure.

πŸ”

Secure by default β€” not your problem to configure

Your infrastructure is CIS-compliant before you write a line of application code. Hardened GCP projects, KMS-encrypted state, and audit logging are built in β€” your team inherits a secure foundation without having to build or maintain it.

πŸ“¦

Built on open standards

Infrastructure automation and runtime tooling are built on CNCF and Linux Foundation open-source projects β€” Kubernetes, Istio, cert-manager, OPA Gatekeeper, OpenTofu, OpenBao. No proprietary abstractions, no lock-in, no black boxes.

πŸ€–

AI agents, not tickets

The platform is built around GitHub Copilot agents β€” the Nomos Agent handles team onboarding end-to-end. No YAML to write, no support ticket to file. Just describe what you need.

🀝

Innersource, not a bottleneck

Arche, Ekklesia, and Techne run as innersource repositories β€” any engineer can open a pull request, and platform engineers from staffed teams review. Stream-aligned teams unblock themselves by contributing fixes and new capabilities directly to the platform.

Your team, on the platform in minutes

The Nomos Agent asks the right questions and takes care of the platform details. Use the interactive prompt builder to describe what your team needs β€” the agent opens a pull request with every change.

Build your agent prompt β†’
Onboard a new team β€” Fides. Team key: st-fides. Maintainers: joesmith. Admin email: joe@osinfra.io.

πŸ‘‹ Hi! I'm the Nomos Agent β€” onboarding a new team for you now.

Give me just a moment while I look you up…

βœ“ get_me β†’ joesmith Β· joe@osinfra.io Β· osinfra-io member

βœ“ lookup_user β†’ no existing team memberships found

Welcome! I have everything I need from your prompt. Here's what I'll create for st-fides:

  • πŸ“ GCP folder β€” Fides with Sandbox / Non-Production / Production sub-folders
  • πŸ‘₯ Google Identity groups β€” admin, reader, writer per environment
  • πŸ™ GitHub parent team st-fides + 4 standard child teams
  • 🐢 Datadog team β€” Fides, admin: joe@osinfra.io

Any optional features to enable β€” Google Cloud project, OpenTofu state management, or additional GitHub repositories?

Enable google project and workflows. Add repo st-fides-api.

βœ“ open_team_pr β†’ PR #142 opened on pt-logos

Done β€” PR #142 is open on pt-logos. Once it merges, your GCP folder, identity groups, GitHub teams, and Datadog team will be created automatically.

Corpus and Pneuma deploy on their own schedules β€” your Google Cloud project and CI/CD service accounts will provision after the Corpus PR merges.

Everything your team needs, out of the box.

From source code management to production support β€” already in place.

🏭
Continuous delivery enablement
GitHub team structure with branch protection, Workload Identity and OIDC federation for keyless GCP auth, Artifact Registry, encrypted state buckets, reusable GitHub Actions called workflows, and Datadog CI Visibility and Test Optimization.
πŸ—οΈ
Cloud foundation
CIS-compliant GCP projects with audit logging, billing budgets, and KMS-encrypted state across sandbox, non-production, and production β€” with Shared VPC networking, per-team DNS subdomain zones, Cloud NAT, managed data services (Cloud SQL, Private Services Access), and namespace provisioning with Workload Identity bindings.
πŸ”’
Security
OpenBao for dynamic credentials, KV2 paths, and a Kubernetes secrets operator β€” plus Cloud Armor WAF, Istio mTLS with automated certificate rotation, OPA Gatekeeper admission control, CIS-hardened GKE clusters, GitHub secret scanning and Dependabot, and Datadog Application Security Management, SIEM, Cloud Security Posture Management, and Code Security.
🐢
Observability and incident response
Logs, metrics, Application Performance Monitoring, and Universal Service Monitoring in Datadog from day one β€” service catalog, API catalog, cloud cost management, and incident response included.
πŸš€

Onboard your team

New to the platform? The Nomos Agent guides you through onboarding step by step. No prior platform knowledge needed.

Get started β†’
πŸ—ΊοΈ

Explore the Platform

Understand the team topology β€” how the platform is organized, what each team owns, and how the layers fit together.

See the teams β†’
🌐

Explore the Ecosystem

The open-source tools and infrastructure that power the platform β€” GCP, OpenTofu, GKE, Istio, Datadog, OpenBao, GitHub Actions, and more.

See the stack β†’