Kumoss

About Kumoss

What Kumoss is, who it is for, and why it exists.

Kumoss is an LLM-powered platform that turns natural-language requests into compliant, Terraform-compatible infrastructure-as-code (IaC). Platform engineers and application developers describe the infrastructure they need, and Kumoss’s agents generate the corresponding code, guided by the organization’s own standards.

It runs as a layered FastAPI orchestration core alongside four contract-first FastAPI sidecars — the IaC engine, repository mapping, notifications, and authorization — behind an nginx edge that also serves a React single-page application and proxies the API.

Every state change and every blocking decision — the in-flight guard, validation, the compliance verdict, the session lock, apply — is computed by application code, not by a model, and applying a reviewed plan is always a human action.

What you deploy

What you deploy: the browser and proxy, the core, the four sidecar services, the bundled core-db, Redis, object storage and Phoenix, and the external LLM, git hosting, cloud account and notification targets

Pan, zoom, search, trace a relationship, switch themes. Open in a new tab

The core platform components — the core orchestration API, the proxy (nginx), core-db (PostgreSQL), redis, object-storage, and the phoenix observability stack — run as shipped and are configured through config.yaml and the .env files. You never reimplement them; in production you replace only the bundled datastores.

Four sidecars are the integration points between Kumoss and your organization: iac (executes the IaC engine; mandatory, always on), notifications (posts session outcomes to Slack; disabled by default), mapping (resolves a repository reference; disabled by default), and authz (applies cloud-project authorization policy; disabled by default). Each implements an OpenAPI contract, so any implementation of that contract can replace the bundled reference. A disabled sidecar is never contacted.

The React single-page application is the user-facing portal, served by the proxy. The whole stack runs from one Docker Compose stack, with nginx as the only public entry point.

Key capabilities

What Kumoss does for you

  • Compliant infrastructure from plain language — a developer-friendly assistant needs only the request and the project you are working on.

  • A validated plan, every time — Kumoss reads your IaC code and the infrastructure deployed in the cloud, treats what is deployed as the source of truth, and transparently corrects existing and impacted drift, including day-2 changes. The result is a successful Terraform or OpenTofu plan that complies with your organization’s architecture, security, and governance standards, see Generate infrastructure.

  • Human review where it matters — a high-impact or non-compliant request locks the session until your administrator team reviews it, and applying a plan is always an explicit human action.

  • A report people can read — every session ends with a summary of the proposal, its impact, and a cost estimate.

  • Several modes of operation — generate, remediate drift, or import, for part of a project or all of it, see Operating modes.

Built to fit your organization

  • Works with what you already have — your existing IaC repositories, Terraform state, and Git provider (GitHub, Azure DevOps, or GitLab).

  • Multicloud — AWS, Azure, Google Cloud, Oracle Cloud Infrastructure, and Kubernetes.

  • Your rules, your definition of critical — you decide what is allowed, what is high risk, and which compliance checks apply, from special projects to every production environment or a cost threshold, see Customize prompts.

  • Full traceability — an admin panel over users, sessions, and roles, all stored in a database.

  • Observability built in — every agent and every system prompt read at runtime is traced with OpenTelemetry and Arize Phoenix.

Bring your own

  • Model — any LiteLLM-supported model, see LLM providers and models.

  • Identity provider — any OIDC provider for sign-in.

  • Authorization logic — your own rules for who may request infrastructure, and where, by implementing the authorization OpenAPI contract.

  • IaC executor — your own Terraform or OpenTofu runtime, version, and environment, by implementing the IaC OpenAPI contract. The bundled iac sidecar runs OpenTofu by default, with HashiCorp Terraform selectable via IAC_BINARY.

Kumoss’s runtime components, internal layering, and end-to-end request flow are covered in Architecture. To run the bundled stack locally, see Quickstart. From there, Guides walks through each task the web application supports, and Reference holds the configuration, environment-variable, role, and API details those guides point at.