About

What Opsy does.

Opsy is an Internal Developer Platform for Kubernetes. It onboards new services self-service, standardizes delivery and keeps control - all without giving the platform access to your cluster. Below: how it works and what's inside.

Opsy
Architecture

An agent inside the cluster. Zero access from outside.

The Opsy agent lives inside your perimeter and initiates outbound HTTPS requests for tasks. It runs kubectl, helm and git locally. No inbound port is open, and no cluster key ever leaves.

Your cluster

  • agent (ServiceAccount)
  • kubectl · helm · git - local
  • kubeconfig and secrets stay here
outbound HTTPS

Opsy control-plane

  • task queue · policy
  • audit and status
  • no kubeconfig · no cluster creds
No inbound to the cluster
kubeconfig in the cluster
Secrets in the perimeter
Token revoked instantly
Capabilities

From service onboarding to production control.

Onboarding

Service to prod from a description

Opsy parses the project and generates Helm, Dockerfile and a pipeline under one policy.

History

History & Rollback

All deploys in one place. One-click rollback.

Strategies

Canary & Blue-Green

Gradual rollout with metric-based auto-rollback.

Environments

Environment promotion

dev → stage → prod with approvals and config carry-over.

Logs

Log analysis

AI parses pod logs and events, finds the crash cause and OOM.

Resources

Resource savings

CPU and memory recommendations, not just charts.

Standard and control

Self-service - within your guardrails.

Single golden path

Every new service is onboarded the same way, under one policy.

RBAC by namespace

Who can deploy where is your decision, not chance.

Prod & merge approvals

Critical changes go through a human, not automatically.

SAST gate

Deploy is blocked on critical vulnerabilities before rollout.

Immutable audit

Who, what, when and with what result - in the log.

Product topics

More on each area.

Stack

Sits on top of what you already have.

CI sources

GitLab CI, Azure DevOps Pipelines, GitHub Actions.

Orchestration

Kubernetes and OpenShift · Helm · werf.

Registries

Private Docker registry, Harbor, ACR, GHCR.

Deployment

SaaS or fully on-premise in your perimeter.

Ready to see it on your workloads?

We'll deploy into a test environment and go through your security checklist.