env0
env0 is the best way to deploy and manage your IaC, including Terraform, Terragrunt, CloudFormation, Pulumi, Kubernetes, and others. The env0 platform enables users and teams to collaborate and provide self-service cloud deployments, all with advanced policies to meet governance and compliance. With env0, every engineer, from development, operations, and DevOps can deploy infrastructure simply, quickly and safely. Maximum productivity, minimum friction.
Learn more
Massdriver
Massdriver is an internal developer platform and platform orchestrator. Platform teams publish the Terraform, OpenTofu, and Helm they already write to a catalog; developers and AI agents provision from it with policy enforced before every deploy. Self-hosted or managed.
Platform and operations teams encode their security, compliance, and cost requirements into pre-approved modules using the IaC tools they already use. Developers and AI agents discover and provision those modules from a central catalog, and policy is checked before anything is created. Built-in secrets management, monitoring, and attribute-based access control cover AWS, Azure, GCP, and Kubernetes.
Massdriver generates an ephemeral pipeline per deploy from each module's own tooling, so there are no standing CI/CD pipelines to maintain. Run it self-hosted, on-prem, or in your cloud, or let Massdriver manage it for you.
Learn more
Galgos AI
Galgos AI is your AI DevOps Assistant for cloud infrastructure, enabling you to generate compliant, secure infrastructure-as-code from simple natural-language prompts. It integrates AI-guided DevOps best practices to automatically produce Terraform, CloudFormation, and Kubernetes manifests that adhere to organizational compliance policies and security standards. By requesting resources in plain English—such as network configurations, identity and access management settings, encryption, logging, and monitoring- you accelerate cloud provisioning while benefiting from built-in modules for cost optimization and industry-standard frameworks (CIS, NIST, PCI DSS). It keeps its policy library up to date, performs real-time validation with remediation suggestions, and offers drift detection with auto-generated fixes. Generated code can be previewed, versioned, and integrated into existing CI/CD pipelines via API or CLI, with support for GitHub Actions, Jenkins and HashiCorp Vault.
Learn more
Kyverno
Kyverno is a policy engine designed for Kubernetes. With Kyverno, policies are managed as Kubernetes resources and no new language is required to write policies. This allows using familiar tools such as kubectl, Git, and Kustomize to manage policies. Kyverno policies can validate, mutate, and generate Kubernetes resources plus ensure OCI image supply chain security. The Kyverno CLI can be used to test policies and validate resources as part of a CI/CD pipeline. Kyverno allows cluster administrators to manage environment specific configurations independently of workload configurations and enforce configuration best practices for their clusters. Kyverno can be used to scan existing workloads for best practices, or can be used to enforce best practices by blocking or mutating API requests. Block non-conformant resources using admission controls, or report policy violations.
Learn more