Open components for the cloud-edge continuum
Apeiro Reference Architecture is built from proven open-source components spanning the full stack — from physical data center infrastructure and bare metal hardware management, through cloud operating system and workload orchestration, to data integration, security, and AI-driven autonomous operations. The projects listed here are the ones where Apeiro makes significant source code contributions; they sit within a broader architecture that also draws on established open-source projects from the wider ecosystem. Each project addresses a specific layer, and together they form a neutral, standards-based baseline that works across providers, environments, and organizational boundaries.
Apeiro Cloud-Edge Infrastructure (CEI)
Building and operating infrastructure that spans centralized data centers and distributed edge locations requires far more than selecting hardware. Facility teams face fragmented tooling, no shared reference architecture across site types and sizes, limited visibility into physical conditions at rack level, and growing regulatory requirements around energy efficiency — all of which must be managed across sites that may be geographically dispersed and independently operated. The Cloud-Edge Infrastructure layer provides the physical foundation of the cloud-edge continuum. Open-source blueprints guide the design of facilities from layout and power distribution to networking and environmental sensing, with rack-level telemetry collected via embedded monitoring units giving operators unified visibility across hardware, power, and environmental signals. A digital twin approach treats the data center as a continuously updated managed system, enabling immersive visualization and AI-driven forecasting for smarter operational decisions. Compliance reporting for EU energy efficiency regulations is integrated directly into the platform, reducing the manual effort of demonstrating regulatory compliance across distributed sites.
Immersive Data Center Management
We leverage the power of Digital Twins by treating the data center like a manufacturing environment. All relevant data flows into that Digital Twin, allowing immersive visualization and smart decision-making through forecasts and AI.
- Digital Twin with Asset Administration Shell: Creates a Digital Twin of the data center using the Asset Administration Shell standard, providing a structured and interoperable representation of all physical assets.
- Immersive Data Center Access: Provides immersive VR and desktop access to the data center, enabling better monitoring, planning, and decision-making for infrastructure operations.
- Operational & Environmental Data Ingestion: Ingests real-time operational and environmental data into the Digital Twin, ensuring an up-to-date and accurate representation of data center state.
- Energy-Workload Transparency: Links compute workloads to their energy consumption, enabling data-driven sustainability management and capacity planning.
- Sustainability & Transparency: Increases transparency across the data center footprint and improves sustainability through AI-powered forecasts and actionable insights.
- Improved Interoperability: Built on open standards to ensure interoperability across heterogeneous data center environments and vendor ecosystems.
- Modular Open-Source Components: Open-source application with modular components applicable beyond data center management, enabling reuse across other infrastructure domains.
GitHub
Apeiro Baremetal Operating System (BOS)
The cloud-edge continuum requires physical hardware which can be housed in centralized, secure data centers or in more compact form factor at near edges, all with appropriate energy supply (preferably renewable) and cooling. Alongside the physical setup of cloud and edge locations, a software system is essential for managing this hardware - the Baremetal Operating System (BOS). The BOS is designed to create a stable and robust foundation that seamlessly integrates with the Cloud Operating System (COS). As spending on cloud infrastructure services continues to grow, BOS aims to facilitate an easily reproducible, fully automated, and end-to-end lifecycle for compute, storage, and network hardware from build to decommissioning. In addition to documentation, BOS will provide a reference implementation on qualified hardware, allowing companies to join the continuum. BOS extends the traditional definition of machine-centric Infrastructure-as-a-service (IaaS) by operationalizing and combining cloud-native concepts with robust and known open-source components. CobaltCore is an OpenStack distribution providing an IaaS API suited for non-cloud-native and heritage workloads. IronCore exposes a cloud-native IaaS API tailored for ephemeral, Kubernetes-native workloads. Both can optionally build on a shared foundation of Bare Metal Management and Network Automation, which are part of the IronCore product family. Other projects assist with production-grade monitoring and operations.
CobaltCore
CobaltCore is a cloud-native IaaS platform combining Kubernetes-native orchestration with OpenStack-influenced services to deliver a modern cloud distribution for cloud-native and traditional workloads alike. It ensures backward compatibility for stateful VMs and traditional network configurations. Compute, storage, and networking lifecycles are fully managed through Kubernetes APIs and wired together by feature-rich services covering every operational concern of a modern data center, enabling production-grade deployments at any scale within weeks, from bare metal up.
- Automated Lifecycle: Compute, storage, networking, and AI hardware lifecycles are fully automated through IronCore Bare Metal Management and Kubernetes-native operators - from bare metal provisioning to day-2 operations.
- Gardener Extensions: Gardener and GardenLinux extensions provide coordinated control-plane maintenance for the KVM hypervisor and storage fleet, ensuring reliable and non-disruptive updates at any scale.
- Greenhouse Integration: Operational concerns are seamlessly integrated with the Greenhouse Operations Platform and Heureka Security Posture Management, giving operators a unified view across the entire data center.
Website
GitHub
Greenhouse
Greenhouse is a Kubernetes-based day-2 operations platform providing a set of opinionated tools and operational processes for managing cloud-native infrastructure at scale.
- Team & Access Management: Manages organizational groups as Teams with fine-grained access control to and ownership of resources.
- Unified Operations Dashboard: Provides a single dashboard for infrastructure, alerting, security, compliance, and organizational management across a fleet of Kubernetes clusters.
- Preconfigured Tool Suite: Ships a set of preconfigured and integrated tools auto-deployed across clusters, covering observability, security, and compliance out of the box.
- Plugin API: An extensible plugin API allows teams to integrate self-developed solutions on top of the Greenhouse platform machinery.
Website
GitHub
IronCore Bare Metal Management
The bare metal management and automation in IronCore is designed to provide a comprehensive solution for managing physical servers in a Kubernetes-native way. It leverages the power of Kubernetes Custom Resource Definitions (CRDs) to automate server lifecycle from discovery to day-2 operations.
- Discovery: Automatically detect and register bare metal servers, ensuring seamless integration into the infrastructure.
- Provisioning: Deploy and configure servers using Ignition, automating OS installation and server setup.
- Day-2 Operations: Manage BIOS, firmware, and hardware inventory declaratively, keeping the fleet compliant and up to date without manual intervention.
- 3rd Party Integrations: Seamlessly integrate with existing vendor-specific management tools.
- Kubernetes Support: Run Kubernetes on bare metal servers with support for Cluster API and Gardener.
Website
GitHub
IronCore IaaS
The IronCore IaaS layer exposes a unified, declarative API for managing compute, storage, and networking resources using modular, pluggable providers. It integrates natively with Gardener, CSI, CCM, and Cluster API for cloud-native workloads.
- Compute: Pluggable providers support diverse environments, with KVM via libvirt as the default compute backend.
- Storage: Block, shared, and object storage are backed by default with Ceph, a cloud-natively automated, vendor-neutral storage solution.
- Networking: Declarative networking resources are managed through the IronCore API.
Website
GitHub
IronCore Network Fabric Automation
Network Fabric Automation provides a Kubernetes-based framework for automating network device deployment, configuration, and monitoring for IronCore opinionated underlay network stack. It currently supports Sonic Edgecore switches via the sonic-operator.
- Device Discovery: Automatically discover network devices across the data center.
- Provisioning: Automate the provisioning of network devices at scale.
- Configuration Management: Manage and apply configurations across multiple devices consistently.
Website
GitHub
Perses
An open-source dashboard tool for visualizing observability data with an open specification designed for portability across various datasources such as Prometheus, OpenSearch, Jaeger, etc.
- Open Dashboard Specification: Provides an open specification for dashboards, ensuring portability and avoiding vendor lock-in across observability backends.
- Multi-Source Observability: Visualizes data from Prometheus, Tempo, Loki, and Pyroscope in a single platform, reducing the need for separate dashboarding tools.
- Dashboard-as-Code: SDK-driven dashboard-as-code capabilities enable version-controlled, reproducible dashboard definitions.
- Kubernetes Native: Kubernetes operator integration enables GitOps-based deployment and lifecycle management of dashboards alongside the applications they monitor.
Website
GitHub
Apeiro Cloud Operating System (COS)
Running workloads across multiple infrastructure providers - or across cloud and edge simultaneously - normally requires separate tooling, separate operations teams, and painful trade-offs about where to deploy. Switching providers means rebuilding. The Cloud Operating System layer provides the software that abstracts these differences: a consistent operational environment for deploying, managing, and moving workloads across the continuum, regardless of the underlying provider. Application teams work with one set of interfaces; the infrastructure underneath can change without requiring application changes.
Garden Linux
Garden Linux is a minimal, immutable, API-driven operating system layer for automated, Kubernetes-centric platforms. It is not a general-purpose Operating System targeting all possible use-cases & scenarios.
- Lightweight & Optimized Container OS: Minimal footprint container OS designed for Kubernetes nodes and container base images, with an easy-to-use build system.
- Advanced Security & Auditability: Features immutable root filesystems, a hardened LTS kernel, secure boot, remote attestation, and built-in security modules like SELinux and AppArmor.
- Compliance & Future-Ready: Meets industry standards including CIS and DISA STIG, and integrates emerging Post-Quantum Cryptography algorithms.
- Cross-Platform & Multi-Cloud: Provides ready-made images for major cloud providers and on-premises environments, reducing integration effort.
- State-of-the-Art Technology: Fully systemd-based architecture ensuring modern, robust system management and repeatable, auditable builds.
- Qualified Baseline: All ApeiroRA components will be streamlined and qualified on Garden Linux only, providing a single, fully supported OS baseline across the entire stack.
Website
GitHub
Gardener
Deliver fully-managed Kubernetes clusters at scale everywhere with your own Gardener installation. A robust, scalable, and production-hardened, certification-ready open-source system managing Kubernetes clusters across many infrastructure providers — embodying open standards and interoperability as a bootstrap building block in ApeiroRA.
- Homogeneous Multi-Cloud Experience: Gardener's extension mechanism and multi-region seed cluster deployment deliver a consistent, homogeneous and scalable Kubernetes setup across cloud providers. It abstracts infrastructure complexity, streamlining operations and boosting developer productivity.
- High Availability & Resource Efficiency: Gardener's hosted control planes pattern ensures resilient control planes with automatic recovery and live migration options for demanding scenarios. Its dynamic scaling algorithms optimize resource usage, reducing downtime and lowering TCO.
- Simplified Fleet Management: Gardener simplifies operations by enabling administrators to manage multiple shoot clusters from a single garden cluster, streamlining updates, scaling, and monitoring.
Website
GitHub
Konfidence
Konfidence is an open-source software delivery framework. It ensures that only tested and approved versions reach production, addressing a common challenge in complex IT landscapes.
- Streamlined Deployment Processes: Streamlines fragmented deployment processes for microservices-based SaaS applications into a single structured framework.
- Immutable Versioned Packages: Establishes immutable, versioned application packages via OCM, containing all necessary components for consistent and traceable deployments.
- Reduced Complexity & Predictable Releases: Reduces complexity, improves security, and facilitates predictable daily releases.
- Modern Deployment Practices: Supports progressive rollouts, ring deployments, and feature toggles for safer production deployments with enterprise-grade multi-tenancy.
- Engineering Excellence: Structurally improves engineering culture and enables development teams to excel in their DORA metrics.
Website
GitHub
Kubernetes Control Plane
KCP is a horizontally scalable, Kubernetes-native control plane for building massively multi-tenant platforms and SaaS services. It provides fully isolated workspaces — each functioning like a lightweight Kubernetes cluster — enabling API providers to serve thousands of tenants from a single control plane without forking Kubernetes.
- Massively Multi-Tenant Workspaces: Provides fully isolated workspaces, each functioning as an independent Kubernetes-like cluster with dedicated API endpoints, CRDs, and RBAC — at the speed of namespace provisioning.
- APIs as a Service: Extends Kubernetes' CRD model with an optimized API export mechanism, enabling SaaS providers to offer APIs securely to thousands of user workspaces.
- Compute-Agnostic Control Plane: Operates as a generic control plane by intentionally excluding pod scheduling, making it suitable for use cases beyond container orchestration.
- Kubernetes-Native, No Fork: Built on established Kubernetes API conventions and standards — complements rather than replaces Kubernetes, avoiding vendor lock-in.
Website
GitHub
Luigi
Luigi is a micro frontend JavaScript framework for building modular, scalable, and technology-agnostic web applications with a unified user experience across distributed UI modules.
- Modular: Monolithic web applications decompose into consistent, clearly scoped UI modules that reflect the underlying backend modularity.
- Extensible: UI modules from external systems integrate seamlessly, and applications can be extended with additional functionality from third-party vendors in a secure way.
- Scalable: End-to-end feature development distributes across an arbitrary number of teams, each able to independently develop, deploy, maintain, and operate their solutions.
- Technology-Agnostic: Luigi is technology-agnostic, allowing teams to adopt new trends quickly and preventing technology lock-in as the landscape evolves.
Website
GitHub
Maestro
Maestro is an orchestration engine for cloud platform delivery.
It coordinates lifecycle managers across a tree of control planes, from a single global control plane down to local and air-gapped clusters.
By propagating desired state declaratively through the hierarchy, Maestro enables consistent and automated platform lifecycle management across sovereign cloud, edge, and disconnected environments.
- Air-Gap Resilience: Local and air-gapped clusters continue operating with the last known-good state even when the global control plane is unreachable.
- Hierarchical Multi-Cluster Orchestration: Coordinates lifecycle managers across a tree of control planes - from a single global root down to local clusters - without owning application provisioning itself.
Public links coming soon.
Open Component Model
The Open Component Model (OCM) is an open-source, technology-agnostic model and toolset for secure software delivery. OCM provides a standard way to describe, sign, ship and deploy software components across any environment - including air-gapped and sovereign clouds - ensuring a tamper-proof, verifiable supply chain from build to deployment.
- One standard for every artifact: Any artifact — images, Helm charts, binaries, configs — is described as a single, versioned component with a cryptographic packing list.
- Sign once, trust everywhere: Using established algorithms like RSA and X.509 - and keyless signing via Sigstore. Location-independent signatures stay valid across registries, organizations, and air gaps, providing a verifiable Software Bill of Delivery.
- Deliver to any environment: Software ships across public cloud, on-prem, and fully disconnected sovereign environments without breaking integrity or traceability.
- Fits any stack: An extensible plugin model integrates with existing registries, signing services, and GitOps tooling - and OCM components serve as a shared anchor for downstream compliance tooling like Open Delivery Gear.
Website
GitHub
Open Delivery Gear
Open Delivery Gear (ODG) is an open-source compliance automation platform that continuously scans OCM component versions for security and compliance issues. ODG tracks findings against configurable SLAs and provides a Delivery Dashboard for platform operators and application teams - enabling trust-but-verify assurance across public and sovereign cloud environments.
- Aggregated Component View: Provides an aggregated view of component versions and metadata from multiple sources, including vulnerabilities and licenses.
- Technology-Agnostic Rescoring: Tooling- and technology-agnostic (semi-automated) rescoring of compliance findings across different software supply chain tools.
- Compliance Issue Tracking: Compliance issue tracking with a fine-granular "rolling due-date barrier" for managing remediation timelines.
- Extensible via ODG Extension Model: Extensible through the ODG Extension Model, allowing organizations to add custom compliance checks and integrations.
- Correlated to Component IDs: All findings are correlated to OCM Component IDs, facilitating alignment of different processes and tools across software lifecycle stages.
Website
GitHub
Open Micro Frontend Platform
The Open Micro Frontend Platform (OpenMFP) provides an opinionated platform for building portals and complex web-based applications with enterprise qualities.
- Dynamic Micro Frontend Extension Model: Self-sufficient micro frontend applications run within other applications, with a shared, dynamic navigation layer (header, footer, menu).
- Central Shared Services: Provides central shared services for authentication, authorization, reducing redundancy across all integrated micro frontends.
- Seamless Multi-Team Integration: Enables seamless integration of UI capabilities from different teams and disparate organizations while maintaining team independence.
- Independent Release Cadence: Untangles monolithic frontend build and planning processes into independent releases, splitting applications into smaller, autonomously deployable chunks.
- Reuse of Shared Infrastructure: Supports the reuse of shared functionality and infrastructure, and is built on the Luigi micro frontend framework.
Website
GitHub
OpenControlPlane
OpenControlPlane is a managed Infrastructure-as-Data orchestration layer, designed to streamline and automate the management of cloud resources and corresponding services using the Kubernetes Resource Model.
- Full Cloud Landscape Orchestration: Equips teams with everything needed to orchestrate their cloud landscapes — from application to account and infrastructure management — using the control plane pattern.
- Declarative Resource API: All resources in the cloud-edge continuum are accessible and managed via a declarative API based on the Kubernetes Resource Model, with corresponding controllers and operators.
- Centralized Infra-as-Data Capabilities: Enables organizations to centrally offer Infrastructure-as-Data capabilities, leveraging open-source providers like Crossplane, Flux, External Secrets Operator, and OCM.
- GitOps at the Edge: Together with declarative deployment orchestrators, consumers implement automated, GitOps-driven deployment workflows at the edges.
- Release Train Subscription: Consumers subscribe to a product release-train from software producers, enabling continuous and controlled delivery across distributed environments.
- Custom Platform Builder: Allows larger organizations to pre-configure control planes tailored to their needs and grow their own internal developer platform.
- Managed Control Planes as a Service: Allows any company to offer managed control planes to their engineers, reducing platform complexity for individual teams.
Website
GitHub
Platform Mesh
Platform Mesh is the main Platform API for users and technical services to order and orchestrate capabilities attached to the environment. Its design principle is inherited from the Kubernetes Resource Model (KRM), enabling declarative management of services across distributed environments.
- Multi-tenant Control Planes: Supports complex multi-tenant scenarios without compromising security and provides a foundation for a scalable and regionally distributed service ecosystem.
- KRM-based API Management: KRM as the "lingua-franca" for declarative service management. Control Planes provide a declarative API layer between providers and consumers.
- Service Provider Integration: Seamless provider integration through combination points between control planes of service providers and service consumers.
- Decentralized Marketplace Support: Export and Binding interfaces that back decentralized marketplaces for consumers to browse available APIs and providers to publish services.
Website
GitHub
Apeiro Data Fabric (DF)
Applications deployed across cloud and edge environments often have no common way to discover each other, share data, or coordinate business processes. Each integration becomes a bespoke connection that must be built and maintained separately. Data Fabric defines the standardized interfaces - APIs, resource discovery protocols, and event formats - that allow distributed services to find each other and work together without central coordination or manual pre-wiring. The result is that applications can be composed into business processes automatically, based on shared metadata and open standards rather than point-to-point integrations.
Knowledge Graph
Knowledge Graph (KG) grounds AI to avoid hallucinations and provide accurate business context. AI agents enabled via KG can combine enterprise knowledge, business data, and AI for the best outcomes. Within Apeiro, KG moves from costly use-case-specific knowledge modeling to self-describing semantics (via ORD) and model-driven centralized access to metadata (via UMS).
- Business Context for Agentic AI: Extracts metadata sources aggregated via UMS and retrieved via ORD, making them accessible for AI-related processes and grounding AI to avoid hallucinations.
- Semantic Layering on Metadata: Generates a derived modeling layer based on metadata sources using automated KG modeling and AI methods, including link generation, graph clustering, and generative AI enrichment.
- AI-Driven Knowledge Modeling & Extension: Enables domain experts with methods for agentic knowledge modeling, scaling toward a decentralized approach of KG generation across enterprises.
Public links coming soon.
Open Resource Discovery
ORD is an open protocol for publishing and discovering application and service metadata. It defines a structured schema for APIs, events, data products, and AI agents, enabling consistent discovery and integration across systems and marketplaces. As the foundation of the Data Fabric, ORD metadata is collected by UMS and used by Knowledge Graph to map relationships across providers.
- Common Metadata Language: Defines a clear, machine-readable format for describing APIs, events, data products, and related resources, ensuring consistent structure across all producers.
- Improved Resource Discoverability: Standardizes key details like endpoints, capabilities, and ownership, making resources easier to find and understand across distributed landscapes.
- Cross-System Interoperability: One shared specification lets platforms and tools exchange and interpret resource descriptions without custom integrations.
- Extensible Schema: Supports safe extensions so organizations can add domain-specific fields without breaking compatibility, allowing flexibility for future needs.
Website
GitHub
Unified Metadata Service
UMS consolidates fragmented metadata - APIs, events, services, and tenant information - across complex landscapes into a unified, extensible, model-driven environment. It enables marketplaces with consistent, searchable service catalogs and allows AI systems to discover and orchestrate resources automatically. Together with ORD, UMS enables seamless integration between services without manual pre-design.
- Centralized Metadata Access: Aggregates metadata from multiple sources and optionally federates queries to external systems, providing a single access point across the landscape.
- Real-Time Awareness for Automation: Subscriptions notify consumers on relevant changes (e.g., new tenants or APIs), enabling event-driven workflows in downstream products.
- Scalability and Governance: Model-driven approach allows organizations to extend and adapt metadata structures without losing control, ensuring sustainable growth and strong governance.
Public links coming soon.
Apeiro Security
Security is a key concern in cloud environments, where providers hold responsibility of customers’ data and have to adhere to amplified regulatory requirements. In a multilateral world, the control and limitation of integrated cryptography within cloud environments becomes increasingly important as the level of entrusted data confidentiality rises. Apeiro Security provides a powerful set of tools to manage cryptographic assets, protect sensitive data, and maintain a strong and adaptable security posture in the face of emerging threats and changing requirements. This includes Key Management (supporting BYOK and HYOK), Secrets Management and PKI, Crypto Agility, Software Supply Chain Security via OCM, and Audit Log standards and integration.
AI Trust
The AI Trust Platform enables organizations to register AI assets once and maintain continuous, automated EU AI Act compliance - centralizing transparency, monitoring, and documentation in one place, with automatic requirements updates, gap analysis, and mitigation proposals.
- Centralized Compliance Infrastructure: Provides shared, reusable compliance capabilities — transparency, monitoring, documentation, and oversight — across AI systems.
- Automated Regulatory Tracking: Continuously tracks EU AI Act requirements and proactively surfaces gaps and mitigation proposals, reducing the need for manual ex-post remediation.
- Compliance-by-Design: Embeds compliance mechanisms directly into the AI development lifecycle, enabling scalable and consistent implementation across all registered AI systems.
- Proactive Stakeholder Notifications: Automatically notifies responsible stakeholders whenever the compliance status of an AI system changes, ensuring accountability without manual follow-up.
Website
GitHub
Audit Logging
OpenTelemetry has evolved into a widely adopted standard for observability, but lacks support for audit logging purposes such as standardized semantic conventions and delivery guarantees. Together with the OpenTelemetry community, we are working on closing these gaps and making OpenTelemetry fit for audit logging.
- Audit Logging Standard for OpenTelemetry: Establishes a standard for audit logging as part of OpenTelemetry, enabling consistent audit event collection through the existing OTel ecosystem.
- Standardized Semantic Conventions: Standardizes semantic conventions for audit logging, ensuring a common vocabulary and structure across all audit-relevant events.
- Delivery Guarantees: Adds support for different delivery guarantees when processing audit-relevant events, addressing a core gap in OpenTelemetry's current capabilities.
GitHub
Confidential Computing Attestation
Confidential Computing Attestation provides hardware-rooted trust verification for cloud workloads running in Trusted Execution Environments (TEEs). The project delivers attestation services that cryptographically verify the integrity and confidentiality guarantees of compute environments, enabling workloads to prove they are running on genuine, uncompromised confidential computing hardware.
- Protection from Infrastructure Operators: Hardware-level encryption (Intel TDX, AMD SEV-SNP) keeps data inaccessible even to the cloud provider, unlocking regulated markets like public sector and healthcare.
- Provider-Independent Hardware Attestation: Open attestation against reference SBOMs proves workload integrity without relying on any single hyperscaler's proprietary mechanisms.
- Sovereignty-Grade Security at Native Performance: Unlike homomorphic encryption, hardware TEEs deliver data-in-use protection without meaningful performance overhead, making it viable for production workloads.
Public links coming soon.
Crypto Broker
The Open Crypto Broker moves cryptographic operations into a managed environment, enabling governance and policies over which algorithms are allowed. It provides a unified interface for crypto operations to help workloads become crypto-agile.
- Simplified Crypto Consumption: Simplifies consumption of cryptographic operations by providing a unified, profile-based interface to diverse underlying crypto implementations.
- Governance & Algorithm Control: Manages and controls allowed cryptographic operations, enabling organizations to enforce policies over which algorithms may be used.
- Crypto-Agility: Helps cryptographic workloads become crypto-agile, making it straightforward to swap algorithms in response to new standards or Post-Quantum Cryptography requirements.
GitHub
OpenBao
OpenBao is an identity-based secrets and encryption management system. In addition to storing key/value data such as passwords or tokens, it can host public key infrastructures (PKIs) for issuing certificates.
- Secure Secrets Storage: Provides secure, identity-based storage for secrets, credentials, tokens, and certificates with strong access controls.
- HSM-Backed Encryption at Rest: Protects secrets at-rest through different seal/unseal mechanisms including HSM-backed protection for high-security environments.
- Multi-Tenancy via Namespaces: Supports multi-tenancy through namespaces, enabling isolated secret management for different teams, applications, or customers.
Website
GitHub
OpenKCM
OpenKCM is an open source central key chain manager for customer-owned encryption keys. It gives organizations full governance over their key hierarchy — from root keys down to data encryption keys — across cloud-native and on-premise deployments. Customers retain exclusive control over their key material, with immediate revocation across all governed workloads.
- Customer-Owned Key Governance: Puts the customer in control of the full key hierarchy — from root keys to data encryption keys — without handing key material to any platform or vendor.
- Unified Keystore Control Plane: Manages encryption keys across several platforms and heterogeneous infrastructure providers from a single control layer.
- BYOK & HYOK Support: Supports Bring-Your-Own-Key and Hold-Your-Own-Key scenarios so customers retain full control over their cryptographic keys and can revoke access at any time.
- Keychain Composition & Lifecycle Control: Composes data encryption keys into keychains and controls the key lifecycle of different keychains individually.
- Pluggable Keystore Backends: Connects to OpenBao, AWS KMS, Azure Key Vault, GCP KMS, and HSMs — key material never leaves the customer's own keystore.
- Compliance Ready: Ensures compliance with stringent security and privacy standards across multi-tenant cloud-native and enterprise platforms.
Website
GitHub
Zero Trust Workload Identities
Zero trust workload identities bring verifiable identity documents to the Cloud operating system based on the SPIFFE standard.
- SPIFFE-Based Identities: Provides verifiable identity documents based on the SPIFFE standard, ensuring cryptographically provable workload identities across the Cloud operating system.
- Mutual Authentication: Enables workloads to mutually authenticate each other in distributed Cloud systems, eliminating implicit trust between services.
- Zero-Trust Made Easy: Makes zero-trust security practices easily accessible without requiring deep security expertise from platform operators.
Public links coming soon.
Apeiro Artificial Intelligence
Running cloud and edge infrastructure at scale creates two distinct operational demands. The complexity and volume of signals across distributed sites outpaces what any operations team can handle manually — incidents are slow to detect and root causes are buried in noise. At the same time, the rapid proliferation of AI models, datasets, and inference endpoints across an organization creates its own governance challenge: capabilities accumulate faster than any team can track them, creating shadow AI and operational blind spots. The Artificial Intelligence layer addresses both dimensions with equal weight. For infrastructure operations, a continuously updated knowledge graph correlates data from across the stack to support autonomous reasoning, self-healing, and proactive incident response — while a purpose-built framework captures and applies expert operational knowledge automatically, enabling distributed and air-gapped data centers to run with minimal personnel. For AI services and governance, a sovereign AI-as-a-Service platform lets organizations deploy and consume AI securely and compliantly without depending on hyperscale providers — and an AI engineering hub makes models, datasets, inference endpoints, and observability signals discoverable, connected, and governable across the organization.
Autonomous Operations
Autonomous Operations is a framework that keeps data centers running with minimal personnel across routine and adverse conditions. It captures expert knowledge and applies it automatically across sites, drastically increasing automation and autonomy. Distributed as open-source, it enables efficient operations of distributed cloud-edge environments and decentralized or air-gapped data centers.
- Minimal-Personnel Operations: A small team can run a full data center across the entire operational spectrum - routine maintenance, configuration management, compliance, and incident response - without requiring specialist availability for covered scenarios.
- Automated Incident Remediation: Known issues are identified and resolved automatically, dramatically reducing Mean Time to Resolution and eliminating the dependency on individual operator expertise during adverse conditions.
- AI Without Operational Risk: AI-driven root cause analysis and automation generation are applied during the safe, supervised development phase - not on the critical path - delivering the analytical benefits of AI while preserving the determinism, bounded latency, and auditability that mission-critical operations require.
- Air-Gapped Readiness: The system operates with complete isolation from external networks, making it viable for regulated, sensitive, or physically isolated environments without architectural compromises.
- Regulatory Compliance Built In: The AI components are fully specified as a high-risk AI system under the EU AI Act, with risk management, transparency, human oversight, and post-market monitoring obligations addressed by design rather than retrofitted.
Website
GitHub
Naira
Naira is an open-source AI Engineering Hub for discovering, governing and operating AI assets and services. It connects context across models, datasets, inference endpoints, gateways, applications, documentation and observability signals. Rather than replacing specialized systems, it makes the relationships between them visible and actionable - helping teams understand what AI capabilities exist, who owns them and how they can be used safely.
- Unified AI Engineering Context: Connects models, datasets, endpoints, gateways, applications, documentation, observability and ownership information into one understandable hub.
- Stand Up Against Shadow AI: Helps organizations gain visibility into AI assets and services that are otherwise spread across disconnected tools, teams and platforms.
- Relationships, Not Just Lists: Shows how AI assets are connected, for example which model is served by which endpoint, exposed through which route and consumed by which application.
- Governance Built Into Discovery: Makes ownership, lifecycle state, approval status, access constraints, documentation and operational signals visible close to the AI asset or service.
- Reduce Cognitive Load: Rather than having dozens of tools handy, Naira is a single-entry point providing minimal signals and transparency across workflows and deep links where it matters.
- Extensible and Tool-Neutral: Integrates with existing AI engineering tools through plugins instead of forcing teams into one monolithic platform.
- From Visibility to Safe Action: Starts by making the AI landscape visible and understandable, then grows toward guided onboarding, golden paths, policy-aware access and safe operational workflows.
Website
GitHub
Operational Context Graph
The Operational Context Graph provides a unified, continuously updated knowledge graph of the operational state of data centers. By correlating infrastructure, workload, and event data into a structured graph, it enables autonomous reasoning and decision-making for self-healing and proactive operations.
- Single Source of Operational Truth: Consolidates telemetry, topology, runbooks, recorded actions, and AI-generated insights into a unified, versioned repository - giving every consuming system a consistent, authoritative view of the data center.
- Living Knowledge Graph: Continuously builds and maintains a semantic graph that links infrastructure, services, incidents, runbooks, and actions into a connected, queryable model.
- Implicit Knowledge Made Explicit: Topology relationships, configuration baselines, historical incident patterns, and approved procedures are captured and made accessible to both AI systems and human operators through standardized interfaces.
- Temporal Awareness: Versions graph state over time, enabling point-in-time reconstruction and comparison to support trend analysis, incident investigation, and change tracking.
- Semantic Interoperability Across Vendors: Adopts the Asset Administration Shell standard and unified data models to enable consistent interpretation of telemetry from heterogeneous, multi-vendor infrastructure.
Website
GitHub
Thalamus
Thalamus is an open-source AI-as-a-Service platform that transforms any AI infrastructure into scalable, consumable AI services. Built for sovereign AI environments, it enables organizations to deploy, operate, and consume AI securely, compliantly, and independently of hyperscale cloud providers.
- Sovereign & Regulatory-Compliant AI: Designed for sovereign AI ecosystems requiring restricted, confidential, and controlled deployments. Complies with regulatory requirements for the public sector and highly regulated industries.
- Infrastructure Freedom: Runs on any AI infrastructure with out-of-the-box support for bare-metal AI hardware. Built for GenAI inference, machine learning, and emerging AI applications. Delivers Model-as-a-Service capabilities for both open-weight and proprietary models.
- Confidential AI by Design: Enables confidential computing to protect model weights, intellectual property, and sensitive data.
- Optimized AI Operations: Advanced routing, scheduling, and caching maximize performance, utilization, and cost efficiency for AI inference. Built-in observability, monitoring, metrics, lifecycle management, and model provisioning.
- Open Standards, No Vendor Lock-In: Built on open, standardized Kubernetes APIs in collaboration with the open-source community. Vendor-specific inference blueprints are contributed back to open source and the Linux Foundation.
Website
GitHub