Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,36 @@ Kumoss is an orchestration platform: a FastAPI core, a React web application, an

https://github.com/user-attachments/assets/9613c8b4-f0f3-487f-9fdd-8a38c17c730a

## Key capabilities

**What Kumoss does for you**

- **Compliant infrastructure from plain language.** A developer-friendly assistant needs only your request and the project you are working on.
- **A validated plan, every time.** Kumoss reads your IaC code and the infrastructure actually deployed in the cloud, then proposes a change that fulfills the request. It treats what is deployed as the source of truth and transparently corrects existing and impacted drift, including day-2 changes. The result is a successful Terraform/OpenTofu plan that complies with the architecture, security, and governance rules your organization defines.
- **Human review where it matters.** Any request detected as high impact or non-compliant locks the session until your administrator team reviews it.
- **A report people can read.** Every session ends with a summary of the proposal, its impact, and a cost estimate.
- **Several modes of operation.** Generate new infrastructure, remediate drift, or import existing resources, for part of a project or all of it.

**Built to fit your organization**

- **Works with what you already have.** Use your existing IaC repositories, Terraform state, and Git provider (GitHub, Azure DevOps, or GitLab).
- **Multicloud.** AWS, Azure, Google Cloud, Oracle Cloud Infrastructure, and Kubernetes.
- **Your rules, your definition of critical.** You decide what is allowed, what is high risk, and which compliance checks apply. Critical can mean special projects, every production environment, changes above a cost threshold, or any rule you write.
- **Full traceability.** An admin panel shows users, sessions, and roles, all stored in a database.
- **Observability built in.** Every agent and every system prompt read at runtime is traced with OpenTelemetry and Arize Phoenix.

**Bring your own**

- **Model.** Any [LiteLLM](https://docs.litellm.ai/)-supported model.
- **Identity provider.** Any OIDC provider for sign-in.
- **Authorization logic.** You decide who may request infrastructure, and where, by implementing the authorization OpenAPI contract.
- **IaC executor.** Keep your own Terraform or OpenTofu runtime, version, and execution environment by implementing the IaC OpenAPI contract.

Each integration point is a sidecar service behind an [OpenAPI contract](contracts/openapi/), so you can replace the bundled reference implementation with your own.

> [!NOTE]
> Kumoss exposes everything through a FastAPI API, so support for the Model Context Protocol (MCP) and the Agent2Agent (A2A) protocol is in progress, letting other agents consume Kumoss directly.

## Documentation

The full documentation is published at **[inditextech.github.io/kumoss](https://inditextech.github.io/kumoss/stable/)**.
Expand Down
91 changes: 79 additions & 12 deletions docs/src/modules/ROOT/pages/index.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -46,28 +46,95 @@ merging and applying the result.

== Key capabilities

[cards,columns="1 s:2 m:2"]
=== What Kumoss does for you

[cards,columns="1 s:2 m:3"]
====
[card]
.xref:main:guides/make-a-request.adoc[Describe what you need, in plain language]
Open a session and phrase a request; Kumoss fills in naming conventions,
resource defaults, and the placement it finds in your repository.
.xref:main:guides/make-a-request.adoc[Ask in plain language]
Describe what you need and pick the project you are working on. The
assistant takes it from there.

[card]
.xref:main:guides/generate-infrastructure.adoc[Get a validated, compliant plan]
Kumoss reads your code and the infrastructure deployed in the cloud,
treats what is deployed as the source of truth, corrects impacted drift,
and delivers a successful Terraform or OpenTofu plan that meets your
organization's standards.
Comment on lines +59 to +63

[card]
.xref:main:guides/merge-and-apply.adoc#session-locked[Review what is risky]
A high-impact or non-compliant request locks the session until your
administrator team reviews it.

[card]
.xref:main:guides/generate-infrastructure.adoc[Get back validated Terraform code]
Kumoss writes Terraform-compatible HCL on a new branch and runs it through
the engine's own `init`, `validate`, and `plan` until it passes.
.xref:main:guides/follow-a-session.adoc[Read a clear report]
Every session ends with a human-readable summary of the proposal, its
impact, and a cost estimate.

[card]
.xref:main:guides/merge-and-apply.adoc#session-locked[Catch compliance issues before they ship]
An LLM auditor reviews every generated plan against your organization's
rules; a failing finding or a high-impact change locks the session until
a reviewer clears it.
.xref:main:reference/operating-modes.adoc[Generate, remediate, or import]
Create new infrastructure, remediate drift, or import existing resources,
for part of a project or all of it.

[card]
.xref:main:guides/merge-and-apply.adoc[Apply only when a developer says so]
Kumoss opens a pull request from the reviewed plan and applies it only
after an explicit apply request — never on its own.
after an explicit apply request, never on its own.
====

=== Built to fit your organization

[cards,columns="1 s:2 m:3"]
====
[card]
.xref:main:guides/customize-prompts.adoc[Enforce your own rules]
You define what is allowed, what is high risk, and which compliance
checks apply, from special projects to all of production.

[card]
.xref:main:guides/configure-state-backends.adoc[Keep your repositories and state]
Use your existing IaC repositories, Terraform state, and Git provider:
GitHub, Azure DevOps, or GitLab.

[card]
.xref:main:reference/operating-modes.adoc#session-inputs[Work on any major cloud]
AWS, Azure, Google Cloud, Oracle Cloud Infrastructure, and Kubernetes.

[card]
.xref:main:guides/administer-users-and-locks.adoc[Trace every session]
An admin panel shows users, sessions, and roles, all stored in a
database.

[card]
.xref:main:guides/monitor-with-phoenix.adoc[Observe every agent]
Every agent run and every system prompt read at runtime is traced with
OpenTelemetry and Arize Phoenix.
====

=== Bring your own

Each integration point is a sidecar behind an
xref:main:reference/api/index.adoc[OpenAPI contract]: implement the
contract and Kumoss uses your service instead of the bundled one.

[cards,columns="1 s:2 m:4"]
====
[card]
.xref:main:reference/llm-providers.adoc[Model]
Any LiteLLM-supported model.

[card]
.xref:main:guides/enable-authentication.adoc[Identity provider]
Any OIDC provider for sign-in.

[card]
.xref:main:reference/api/authz.adoc[Authorization logic]
Your rules for who may request infrastructure, and where.

[card]
.xref:main:reference/api/iac.adoc[IaC executor]
Your own Terraform or OpenTofu runtime, version, and environment.
====

== Free & open source
Expand Down
61 changes: 49 additions & 12 deletions docs/src/modules/main/pages/about.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -42,18 +42,55 @@ The React single-page application is the user-facing portal, served by the
`proxy`. The whole stack runs from one Docker Compose stack, with nginx as
the only public entry point.

== Key features

* *Layered orchestration core* — sessions run through filtering,
generation, validation, and reporting phases, computed by application
code, see xref:main:architecture.adoc[Architecture].
* *Four replaceable sidecars* — the IaC engine, repository mapping,
notifications, and authorization each implement an OpenAPI contract, so
an organization can swap in its own implementation.
* *Human-gated apply* — every blocking decision is computed by code, and
applying a reviewed plan is always an explicit human action.
* *OpenTofu by default* — the bundled `iac` sidecar runs OpenTofu, with
HashiCorp Terraform also bundled and selectable via `IAC_BINARY`.
== Key capabilities

*What Kumoss does for you*

* *Compliant infrastructure from plain language* — a developer-friendly
assistant needs only the request and the project you are working on.
* *A validated plan, every time* — Kumoss reads your IaC code and the
infrastructure deployed in the cloud, treats what is deployed as the
source of truth, and transparently corrects existing and impacted drift,
including day-2 changes. The result is a successful Terraform or OpenTofu
Comment on lines +51 to +54
plan that complies with your organization's architecture, security, and
governance standards, see
xref:main:guides/generate-infrastructure.adoc[Generate infrastructure].
* *Human review where it matters* — a high-impact or non-compliant request
locks the session until your administrator team reviews it, and applying
a plan is always an explicit human action.
* *A report people can read* — every session ends with a summary of the
proposal, its impact, and a cost estimate.
* *Several modes of operation* — generate, remediate drift, or import, for
part of a project or all of it, see
xref:main:reference/operating-modes.adoc[Operating modes].

*Built to fit your organization*

* *Works with what you already have* — your existing IaC repositories,
Terraform state, and Git provider (GitHub, Azure DevOps, or GitLab).
* *Multicloud* — AWS, Azure, Google Cloud, Oracle Cloud Infrastructure, and
Kubernetes.
* *Your rules, your definition of critical* — you decide what is allowed,
what is high risk, and which compliance checks apply, from special
projects to every production environment or a cost threshold, see
xref:main:guides/customize-prompts.adoc[Customize prompts].
* *Full traceability* — an admin panel over users, sessions, and roles, all
stored in a database.
* *Observability built in* — every agent and every system prompt read at
runtime is traced with OpenTelemetry and Arize Phoenix.

*Bring your own*

* *Model* — any LiteLLM-supported model, see
xref:main:reference/llm-providers.adoc[LLM providers and models].
* *Identity provider* — any OIDC provider for sign-in.
* *Authorization logic* — your own rules for who may request
infrastructure, and where, by implementing the authorization OpenAPI
contract.
* *IaC executor* — your own Terraform or OpenTofu runtime, version, and
environment, by implementing the IaC OpenAPI contract. The bundled `iac`
sidecar runs OpenTofu by default, with HashiCorp Terraform selectable via
`IAC_BINARY`.

Kumoss's runtime components, internal layering, and end-to-end request flow
are covered in xref:main:architecture.adoc[Architecture]. To run the bundled
Expand Down
Loading