Multi-provider control plane
Every environment you run, on one map.
x‑devops connects your AWS accounts, Azure subscriptions, Atlas projects and the rest into a single inventory — then draws how they actually reach each other, from configuration the providers themselves reported. Not a guess. Not a diagram somebody drew last year.
Thirty seconds. Tell us what you run and we’ll reply within one working day.
How it is organised
Three levels, and nothing above them you have to think about.
Every credential in x‑devops is bound to one place in this hierarchy. There is no ambient account, no shared profile on somebody’s laptop, and no way for a screen to reach a provider you did not explicitly connect.
Project
The thing you ship
One product or service. Holds its own pipelines, blueprints, alert rules and cost rollup — and its own people, with their own roles.
Environment
Where it runs
QA, staging, production — as many as you need. Production is the one the platform treats differently, on purpose.
Connection
The account behind it
One provider account, one region, one stored secret. Resolved live on each request, never returned by an API and never written to a log.
Architecture discovery
We only draw a line when the provider told us it exists.
A connection is drawn when a security group on the target admits a security group on the source — and the diagram carries that rule as the reason. Sharing a VPC is never enough.
the one rule the scanner is built around
It sounds pedantic until you see the alternative: a forty-resource VPC drawn as sixteen hundred meaningless lines. Ingress semantics settle the direction too, so nothing has to guess which way traffic flows. Route tables, listener rules, VPC links, event source mappings, Atlas peerings, Azure virtual-network rules and API Gateway stage variables are all read the same way — real configuration, or no edge at all.
What we refuse to draw
“These two share a VPC, so connect them.” “It’s a Lambda, so it probably talks to the queue.”
What a real edge looks like
sg-0db allows tcp/5432 from sg-0app
HTTPS:443 /api/* → target group orders-tg
rtb-0f2 routes 0.0.0.0/0 via nat-04c
And when a credential can’t read something
The scan says so, per connection, and returns the rest. A partial picture with the gap named beats a blank screen.
Capabilities
The day-to-day, without four consoles and a spreadsheet.
Everything below reads through the same connections and the same permission model, so what one screen shows, another can act on.
Inventory
One resource catalog
Import what already exists across every connected account, tag it with an owner, a repo and docs, and let status refresh on a schedule.
- Table, cards, topology and architecture views
- Bulk reassign, restart, untrack
- A detail panel built for each resource type
Cost
What each resource costs
A monthly estimate per resource, priced from its own live configuration against each provider’s public rate card — not from a billing export that lands a day late.
- Rolls up per environment and per project
- Instance types, tiers, replicas, storage
- Stated plainly as a list-price estimate
Databases
Backup, restore, query
Managed snapshots where the provider has them, real pg_dump and mongodump where it doesn’t. A restore always creates a new resource — it never overwrites the source.
- Recurring schedules into your own S3 bucket
- SQL, Redis and OpenSearch consoles, read-only by default
- Access grants that expire on their own
Delivery
Pipelines and jobs
Author a pipeline in a guided form or lay one out on a canvas, trigger it, and watch every long-running job — copies, scans, restores — in one place.
- Deploy targets named by the service they deploy
- Live build status and run history
- A notification when your job finishes
Signals
Alerts that know the difference
Failure spikes, status flapping, disk pressure, sync failures — and the one an ECS service can’t report itself: running capacity below desired, while its status still reads ACTIVE.
- A rollout in progress is not an outage
- Per-resource mute for the legitimate exceptions
- In the app, and by email when you want it
Application
Your own /metrics, charted
Point x‑devops at a Prometheus endpoint and the dashboard builds itself — one panel per metric family, histograms as p50/p95/p99, counters as rates.
- No panels to define, so none to go stale
- Reaches into a VPC over a paired bastion
- A failed scrape is recorded, not skipped
Guardrails
Built for the moment somebody clicks the wrong thing.
A control plane holding real provider credentials has to be accountable before it is convenient. None of this is held back for the expensive plan.
Production
Two people, not one
A run against a production environment waits for a second administrator to approve it. Both decisions are atomic, so a race can’t start the build twice.
Credentials
Secrets never round-trip
Secret material goes straight to a secrets store on the way in and is stripped before anything is saved or returned. The platform’s own functions hold no provider permissions at all.
Audit
Every change, recorded centrally
The router writes the entry, not the route handler — so a feature shipped next year is audited whether or not anybody remembered to add it.
Identity
Federated sign-on only
GitHub, Microsoft or Google, with an optional fingerprint on your own device. There is no password to leak and no API key to paste into a browser.
Access
Roles you can shape
Viewer, operator and admin out of the box, or build your own permission set. Roles are held per organisation, with per-project overrides where a team needs them.
Tenancy
One organisation cannot see another
Tenant scoping is enforced in the type system and again at the router, before any handler runs. A cross-tenant listing isn’t something a mistake can express.
Pricing
Start on Free. Stay on it as long as it fits.
Flat monthly plans, per organisation. Every plan includes the audit trail, the roles, the alerts and the two-person production approval.
Free
$0 / month
One project, connected properly. See and ship.
- Projects
- 1
- Connections
- 2
- Environments
- 2 per project
- Tracked resources
- 25
- Members
- 3
- Inventory, cost estimates and pipelines
- Alerts, roles and the full audit trail
- Two-person production approval
- Community support
Pro Most teams
$149 / month
The full toolkit for a team running several services.
- Projects
- 5
- Connections
- 10
- Environments
- Unlimited
- Tracked resources
- 250
- Members
- 15
- Architecture scanning and diagrams
- Database backup, schedules and restore
- SQL, Redis and OpenSearch consoles
- Blueprint provisioning and DR scan
- Alert email and service accounts
- Email support
Business
$499 / month
For an estate that spans accounts, teams and providers.
- Projects
- Unlimited
- Connections
- Unlimited
- Environments
- Unlimited
- Tracked resources
- 2,000
- Members
- 100
- Everything in Pro
- Self-hosted database backup
- Stored database credentials
- Restrict which sign-on providers are allowed
- Priority support, with an SLA
Bigger than this, or paying by invoice? We’ll agree limits and terms with you directly — contact@x-devops.com. A lapsed subscription degrades to read-only; it never locks you out of your own inventory.
Connect one account. See what you actually have.
The first scan takes a couple of minutes, and reads nothing it wasn’t given permission to read.
Request a demo
Rather see it against your own estate?
Tell us what you run and we’ll walk you through x‑devops on infrastructure you recognise — not a sandbox with three tidy resources in it.
-
01
You send this form
Thirty seconds. The provider list is the only part that shapes what we prepare.
-
02
We reply within one working day
With a couple of times, and a read-only IAM policy you can look over beforehand.
-
03
Thirty minutes, screen shared
Connect one account, import what’s there, run a scan, and read the diagram together.
-
04
You keep the organisation
It’s a real Free organisation, not a trial that expires. Disconnect the account whenever you like.
Request received
Thanks — we’ll email you within one working day with a couple of times and the read-only policy to review.
Already have an account? Sign in — the demo works just as well on an organisation you’ve already set up.