DevOps Sign in

Multi-provider control plane

Every environment you run, on one map.

x‑devops connects your AWS accounts, Azure subscriptions, Atlas projects and the rest into a single inventory — then draws how they actually reach each other, from configuration the providers themselves reported. Not a guess. Not a diagram somebody drew last year.

Thirty seconds. Tell us what you run and we’ll reply within one working day.

architecture · production · scanned 4 min ago
vpc-0a41c8 · us-east-1 subnet · public subnet · private internet inbound edge-alb load-balancer active api ecs-service 4/4 running worker ecs-service 2/3 running identity apprunner-service running orders-db rds-instance available sessions atlas-cluster idle why this edge exists: sg-0db allows tcp/5432 from sg-0app
reach ingress declared 7 relationships · 0 inferred
Connects AWS Azure MongoDB Atlas Google Cloud Cloudflare SendGrid Firebase Azure DevOps Self-hosted Postgres & MongoDB

How it is organised

Three levels, and nothing above them you have to think about.

Every credential in x‑devops is bound to one place in this hierarchy. There is no ambient account, no shared profile on somebody’s laptop, and no way for a screen to reach a provider you did not explicitly connect.

Project

The thing you ship

One product or service. Holds its own pipelines, blueprints, alert rules and cost rollup — and its own people, with their own roles.

Environment

Where it runs

QA, staging, production — as many as you need. Production is the one the platform treats differently, on purpose.

Connection

The account behind it

One provider account, one region, one stored secret. Resolved live on each request, never returned by an API and never written to a log.

Architecture discovery

We only draw a line when the provider told us it exists.

A connection is drawn when a security group on the target admits a security group on the source — and the diagram carries that rule as the reason. Sharing a VPC is never enough.

the one rule the scanner is built around

It sounds pedantic until you see the alternative: a forty-resource VPC drawn as sixteen hundred meaningless lines. Ingress semantics settle the direction too, so nothing has to guess which way traffic flows. Route tables, listener rules, VPC links, event source mappings, Atlas peerings, Azure virtual-network rules and API Gateway stage variables are all read the same way — real configuration, or no edge at all.

What we refuse to draw

“These two share a VPC, so connect them.” “It’s a Lambda, so it probably talks to the queue.”

What a real edge looks like

sg-0db allows tcp/5432 from sg-0app

HTTPS:443 /api/* → target group orders-tg

rtb-0f2 routes 0.0.0.0/0 via nat-04c

And when a credential can’t read something

The scan says so, per connection, and returns the rest. A partial picture with the gap named beats a blank screen.

Capabilities

The day-to-day, without four consoles and a spreadsheet.

Everything below reads through the same connections and the same permission model, so what one screen shows, another can act on.

Inventory

One resource catalog

Import what already exists across every connected account, tag it with an owner, a repo and docs, and let status refresh on a schedule.

  • Table, cards, topology and architecture views
  • Bulk reassign, restart, untrack
  • A detail panel built for each resource type

Cost

What each resource costs

A monthly estimate per resource, priced from its own live configuration against each provider’s public rate card — not from a billing export that lands a day late.

  • Rolls up per environment and per project
  • Instance types, tiers, replicas, storage
  • Stated plainly as a list-price estimate

Databases

Backup, restore, query

Managed snapshots where the provider has them, real pg_dump and mongodump where it doesn’t. A restore always creates a new resource — it never overwrites the source.

  • Recurring schedules into your own S3 bucket
  • SQL, Redis and OpenSearch consoles, read-only by default
  • Access grants that expire on their own

Delivery

Pipelines and jobs

Author a pipeline in a guided form or lay one out on a canvas, trigger it, and watch every long-running job — copies, scans, restores — in one place.

  • Deploy targets named by the service they deploy
  • Live build status and run history
  • A notification when your job finishes

Signals

Alerts that know the difference

Failure spikes, status flapping, disk pressure, sync failures — and the one an ECS service can’t report itself: running capacity below desired, while its status still reads ACTIVE.

  • A rollout in progress is not an outage
  • Per-resource mute for the legitimate exceptions
  • In the app, and by email when you want it

Application

Your own /metrics, charted

Point x‑devops at a Prometheus endpoint and the dashboard builds itself — one panel per metric family, histograms as p50/p95/p99, counters as rates.

  • No panels to define, so none to go stale
  • Reaches into a VPC over a paired bastion
  • A failed scrape is recorded, not skipped

Guardrails

Built for the moment somebody clicks the wrong thing.

A control plane holding real provider credentials has to be accountable before it is convenient. None of this is held back for the expensive plan.

Production

Two people, not one

A run against a production environment waits for a second administrator to approve it. Both decisions are atomic, so a race can’t start the build twice.

Credentials

Secrets never round-trip

Secret material goes straight to a secrets store on the way in and is stripped before anything is saved or returned. The platform’s own functions hold no provider permissions at all.

Audit

Every change, recorded centrally

The router writes the entry, not the route handler — so a feature shipped next year is audited whether or not anybody remembered to add it.

Identity

Federated sign-on only

GitHub, Microsoft or Google, with an optional fingerprint on your own device. There is no password to leak and no API key to paste into a browser.

Access

Roles you can shape

Viewer, operator and admin out of the box, or build your own permission set. Roles are held per organisation, with per-project overrides where a team needs them.

Tenancy

One organisation cannot see another

Tenant scoping is enforced in the type system and again at the router, before any handler runs. A cross-tenant listing isn’t something a mistake can express.

Pricing

Start on Free. Stay on it as long as it fits.

Flat monthly plans, per organisation. Every plan includes the audit trail, the roles, the alerts and the two-person production approval.

Free

$0 / month

One project, connected properly. See and ship.

Projects
1
Connections
2
Environments
2 per project
Tracked resources
25
Members
3
  • Inventory, cost estimates and pipelines
  • Alerts, roles and the full audit trail
  • Two-person production approval
  • Community support

Business

$499 / month

For an estate that spans accounts, teams and providers.

Projects
Unlimited
Connections
Unlimited
Environments
Unlimited
Tracked resources
2,000
Members
100
  • Everything in Pro
  • Self-hosted database backup
  • Stored database credentials
  • Restrict which sign-on providers are allowed
  • Priority support, with an SLA

Bigger than this, or paying by invoice? We’ll agree limits and terms with you directly — contact@x-devops.com. A lapsed subscription degrades to read-only; it never locks you out of your own inventory.

Connect one account. See what you actually have.

The first scan takes a couple of minutes, and reads nothing it wasn’t given permission to read.

Request a demo

Rather see it against your own estate?

Tell us what you run and we’ll walk you through x‑devops on infrastructure you recognise — not a sandbox with three tidy resources in it.

  1. 01

    You send this form

    Thirty seconds. The provider list is the only part that shapes what we prepare.

  2. 02

    We reply within one working day

    With a couple of times, and a read-only IAM policy you can look over beforehand.

  3. 03

    Thirty minutes, screen shared

    Connect one account, import what’s there, run a scan, and read the diagram together.

  4. 04

    You keep the organisation

    It’s a real Free organisation, not a trial that expires. Disconnect the account whenever you like.

demo-request · new