Kumoss

Kumoss turns natural-language infrastructure requests into reviewed, compliant Terraform-compatible code. Platform engineers and application developers describe what they need; Kumoss generates the code, validates it against the target cloud, and audits it for compliance, then hands over a pull request that a developer applies explicitly — every blocking decision is computed by application code, never by a model.

Get started

Start here

Run it locally with Docker Compose, only LLM credentials and a Git personal access token (GIT_USER/GIT_TOKEN) are yours to supply.

Production

Harden OIDC, project-level authorization, secrets, persistence, and TLS before running Kumoss beyond a trusted workstation.

Architecture

The layered FastAPI core, the four contract-first sidecars, and the request lifecycle from filter to apply.

Guides

Step-by-step guides for making a request, following a session, and merging and applying the result.

Key capabilities

What Kumoss does for you

Describe what you need and pick the project you are working on. The assistant takes it from there.

Kumoss reads your code and the infrastructure deployed in the cloud, treats what is deployed as the source of truth, corrects impacted drift, and delivers a successful Terraform or OpenTofu plan that meets your organization’s standards.

A high-impact or non-compliant request locks the session until your administrator team reviews it.

Every session ends with a human-readable summary of the proposal, its impact, and a cost estimate.

Create new infrastructure, remediate drift, or import existing resources, for part of a project or all of it.

Kumoss opens a pull request from the reviewed plan and applies it only after an explicit apply request, never on its own.

Built to fit your organization

You define what is allowed, what is high risk, and which compliance checks apply, from special projects to all of production.

Use your existing IaC repositories, Terraform state, and Git provider: GitHub, Azure DevOps, or GitLab.

AWS, Azure, Google Cloud, Oracle Cloud Infrastructure, and Kubernetes.

An admin panel shows users, sessions, and roles, all stored in a database.

Every agent run and every system prompt read at runtime is traced with OpenTelemetry and Arize Phoenix.

Bring your own

Each integration point is a sidecar behind an OpenAPI contract: implement the contract and Kumoss uses your service instead of the bundled one.

Any LiteLLM-supported model.

Any OIDC provider for sign-in.

Your rules for who may request infrastructure, and where.

Your own Terraform or OpenTofu runtime, version, and environment.

Free & open source

Kumoss is open source and actively developed — issues, feedback, and contributions are welcome; see how each default component is licensed in the licensing table.

Frequently asked questions

More questions? See the full FAQ.

Where does Terraform state live?

Out of the box, Kumoss keeps state itself, in a bucket dedicated to state with one file per project. Your platform team can instead point it at the remote backend your repository’s own Terraform files declare. Either way, your pull request never contains a state or backend file.

Which cloud credentials does Kumoss use?

The identity your platform team configured for the execution engine — never yours. An optional external authorization service can also be asked, at the start of each session, whether you may work on that cloud, repository, and path.

What data leaves Kumoss when I make a request?

Your request text, the conversation, the repository files the agent reads, the plan, and validation errors are sent to the language model your platform team configured, and stored in the tracing system for review.

Do I have to open a pull request?

The API allows a direct apply, but the web application has no standalone Apply button. As a developer, the pull request is your route to apply — the recommended path, since it brings your team’s review and CI into the decision.

Can other people see my sessions?

Only reviewers who hold a panel role (viewer, editor, or admin) can read them, including the conversation. Nobody but you can continue, merge, or apply your sessions.