Enterprise Kubernetes operators for OpenShift.
Enforce governance policies, manage emergency access, track resource lifecycles, and keep Git in sync with runtime state.
Built for platform teams to manage clusters at scale.

01
Governance

Karma

Automated trust scoring and behavioral guardrails for OpenShift platforms. Collects signals from deployments, tests, scans, and incidents to calculate dynamic karma scores; then enforces appropriate platform constraints based on trust tiers.
Reliable teams get autonomy; others get protection.

  • Signal aggregation from any source (webhooks, Prometheus, CRDs)
  • Trust tiers with configurable thresholds
  • Uses Validating Admission Policies for efficient and OpenShift native enforcement
  • Anti-gaming measures prevent artificial score inflation
Karma
02
Metadata

Tagger

Declarative metadata management for Kubernetes and OpenShift. Define labeling policies once; Tagger enforces them across your entire cluster automatically. Eliminate manual tagging drift, enable accurate cost attribution, and maintain compliance without operational overhead.

  • Populate dynamic values from namespaces, ConfigMaps, or external APIs
  • Continuous reconciliation or via webhook at creation time
Tagger
06
Governance

URO

Unused Resource Operator for Kubernetes cluster hygiene. Automatically detects orphaned Secrets, ConfigMaps, PVCs, Services, and 20+ other resource types that are no longer used by any workload. Configurable grace periods and safety scoring ensure nothing is deleted by mistake.
Stop paying for resources nobody uses.

  • Policy-driven scanning with cron schedules and namespace filters
  • Multi-strategy reference detection (owner refs, Helm, ArgoCD, pod mounts)
  • Safety scoring and grace periods before any deletion
  • Optional S3 backup for deleted resources with retention policies
URO
03
Security

Breakglass

Time-limited, auditable emergency access for Openshift. When users need elevated privileges to resolve incidents or perform critical tasks, Breakglass provides a secure, self-service, policy-driven workflow with automatic expiration and comprehensive audit trails.
Zero standing privileges. Full accountability.

  • Policy-driven approval: auto-approve, manual, or deny based on configurable rules
  • Multi-approver workflows with deadlines and self-approval prevention
  • Automatic RBAC binding creation and cleanup on expiration
  • Full audit logs exportable to S3, Elasticsearch, Loki, or via webhooks
Breakglass
04
Governance

Clotho

Change management for OpenShift. Intercepts resource creation and routes them through configurable approval workflows; maintaining a complete audit trail of all changes.
Every change tracked. Every approval recorded.

  • Multi-step approval workflows with Kubernetes native approvers
  • Scheduled deployment windows with automatic expiration
  • S3-compatible archival of manifests and audit history for compliance
Clotho
05
GitOps

Scribe

Synchronize your cluster state back to Git. Captures runtime state changes from cluster resources and commits them back to Git automatically. When resource requests resize, operators generate metadata, or teams make any intentional changes—Scribe ensures your source of truth stays current.
Reconcile drift, keep source control accurate.

  • Flexible field capture with smart transforms for accurate data extraction
  • Intelligent batching and rate limiting to prevent commit storms
  • Pull request workflows with multi-provider support (GitHub, GitLab, Bitbucket, Gitea)
  • Multiple output formats: YAML patches, Kustomize patches, or full resources
Scribe
07
Governance

IVO

Image Inventory Operator for OpenShift. Discovers every container image running in your cluster, tracks usage, image age, enforces security policies, and automates cleanup of unused images. Automatically notify teams through webhooks, Slack, or email the moment a non-compliant image is deployed.
Complete visibility. Automatic governance.

  • Automatic discovery and tracking of all container images across workloads
  • Policy enforcement: registry allowlists, tag denylists, digest requirements, signature verification
  • Vulnerability threshold rules with Trivy, Grype, and Clair integration
  • Lifecycle management with configurable cleanup for unused and outdated images
IVO

Get Started

Check the documentation for the Cosmos Catalog.
For support, custom features, or just to say hello, email below.