Private beta · self-hosted

Infrastructure operations, without the sprawl.

Build from versioned Terraform, OpenTofu, and Ansible templates. Route runs through customer-controlled workers. Review inputs, approvals, logs, and artifacts in one place; add plans, managed state, and plan-based drift for Terraform and OpenTofu.

Run

network-foundation / production

Approval required
01

Resolve release

network-foundation · v2.4.1

Verified
02

Validate inputs

Schema and secret bindings

Passed
03

Review plan

2 add · 1 change · 0 destroy

Pending
04

Apply

Blocked by policy

Production policy gate

Plan evidence is ready for an authorized reviewer.

Review plan

Platform

One record from intent to infrastructure.

Forgeplane coordinates the control points around IaC without hiding the tools underneath.

01

Delivery model

Versioned templates, instances, environments, and assembly DAGs turn infrastructure changes into explicit records.

02

Execution plane

Capability-aware worker pools claim queued work through NATS JetStream inside networks you control.

03

Evidence and state

Plans, logs, approvals, drift findings, audit events, and encrypted state remain linked through instance and run history.

Terraform and OpenTofu

A governed change path.

The preview-to-apply path keeps resolved context and evidence visible. Ansible uses a governed execute operation without plan promotion or teardown.

01

Define

Publish a versioned template with a schema and execution requirements.

02

Route

Resolve environment policy and select an eligible worker pool.

03

Review

Inspect the plan and satisfy the configured approval policy.

04

Apply

Execute with the accepted inputs, source, toolchain, and state generation.

05

Observe

Follow logs, artifacts, audit events, state, and drift from the run record.

Control plane and workers

Central policy. Execution inside your boundary.

The coordinator owns HTTP/API/UI traffic, authorization, scheduling, persistence, approvals, and audit. Explicitly tool-capable workers claim matching jobs and execute them in customer-controlled environments.

  • 01Capability-aware worker poolsPool identity, workload kind, capacity, health, and tool capability stay explicit.
  • 02Durable queue deliveryNATS JetStream carries jobs while gRPC handles enrollment, heartbeats, logs, artifacts, and state.
  • 03Customer-operated dependenciesUse external PostgreSQL, NATS, and S3-compatible storage or the chart's evaluation dependencies.
Forgeplane coordinatorControl plane
PolicySchedulingEvidence
NATS + gRPC
OnlineEU pooltofu
OnlineCloud poolterraform
OnlineOps poolansible

Managed state

State changes fail closed.

Forgeplane carries encrypted Terraform and OpenTofu state between disposable workers, fences stale assignments, and blocks later mutation when state capture cannot be verified.

Managed-state contract

One canonical state object per instance, versioned encrypted envelopes, assignment fencing, retention, and audited recovery.

Beta

Selective Undo

A disabled-by-default workflow uses fresh baseline and candidate plans to review one historical input removal. Promotion creates a normal change and still requires the configured approval path.

Read the operator guide

Deployment

Kubernetes first.

The Helm chart deploys the coordinator, migrator, and named worker pools with explicit security, storage, networking, and observability settings.

Open the Helm guide
01

Evaluation dependencies

The chart can supply PostgreSQL, NATS, and S3-compatible storage for bounded evaluation environments.

02

External infrastructure

Production deployments connect to operated PostgreSQL, NATS JetStream, object storage, secret backends, and OpenTelemetry.

Private beta

Test Forgeplane against one real delivery path.

Send the current infrastructure code, deployment boundary, and the workflow you want to move under control.

Email hello@forgeplane.io