Managed or self-hosted

Everything around your business logic, in one platform.

Identity and secrets, observability, SLOs and incidents, feature flags, an API gateway, an AI stack and durable execution — in one cloud-native platform, run as a managed service or on your own infrastructure. Broad enough to replace a shelf of SaaS subscriptions, small enough that one team can operate it. You write the business logic; OpsPlane covers everything around it.

The platform

One control plane, everything behind it

Each service runs independently, with its own database and API. Run all of them, or only the ones you need — they share one identity model, one gateway and one audit trail.

Gateway

A reverse proxy that already knows your platform identity, with routing, load balancing, rate limits and WASM plugins on both the request and the response path.

MethodPathUpstream
GET/api/v1/incidentsincidents-api
POST/api/v1/flagsflags-api
GET/api/v1/secretssecurity-api

Feature Flags

A vendor-neutral flag service that speaks OFREP, so any OpenFeature SDK works against it out of the box.

FlagEnv
checkout-v2prod
new-onboardingstaging
pricing-bannerprod

AI Stack

One chat interface over the whole AI surface, with many separate AI components behind a single front end and the same identity and audit trail as everything else.

Assistantclaude-opus-5
Which services breached their SLO this week?
Two — checkout-api and search. Both burned their budget on Tuesday.

Durable Execution

Long-running work that survives restarts, retries and deploys, so you are not hand-writing the bookkeeping around it.

RunStatusDuration
wf_8c21f4Running4m 12s
wf_7b04aeCompleted1m 03s
wf_6a91c7Completed52s

Observability

Metrics, logs and traces from your services under one query surface, feeding the same objectives and alerts the incident side runs on.

p95 latency142 ms

SLOs & Incident Management

Service objectives that decide what counts as a problem, and a reviewable incident record built from the alerts they raise.

IDIncidentSeverity
INC-482Checkout latencyCriticalInvestigating
INC-479Queue backlogHighMonitoring

Security & Identity

Who someone is and what they can reach, in one place, with a single API in front of every secret store you already run.

ConnectorBackend
vault-prodHashiCorp Vault
aws-secretsAWS Secrets Manager
azure-kvAzure Key Vault

How you run it

Managed, or on your own infrastructure

It is the same software either way, and it runs on any cloud — so the choice is a deployment decision rather than a commitment. Start managed and bring it in-house later, or the other way round.

Managed

We run the platform for you. Nothing to install, upgrade or keep available, and one bill instead of the shelf of subscriptions it replaces.

Self-hosted

You run it on your own Kubernetes cluster — on AWS, Google Cloud, Azure or your own hardware — against your own PostgreSQL and inside your own network boundary, so your incident data and your prompts never leave your infrastructure.

The economics

Fewer vendors, lower cost, less to hold together

Every service here is something teams normally buy separately. Bought separately, each one also has to be integrated separately, reviewed separately and renewed separately — and that is rarely the bill anyone counts.

One deployment instead of seven subscriptions

Feature flags, observability, incident management, secret management, a gateway and an AI layer are six or seven vendors at most companies. Here they are one thing you run.

One integration, not one per pair

The services share identity, gateway and audit trail by design, so you are not writing glue between vendors who never planned for each other.

One security review

One codebase, one deployment, one data boundary to assess — instead of a fresh questionnaire per vendor, every renewal cycle.

Small enough to actually run

A handful of services and one PostgreSQL. Self-hosted, it is not meant to become a platform team’s full-time job — and managed, there is nothing to run at all.

Declarative by default

Your platform, described in YAML

A Kubernetes operator watches your custom resources and reconciles them into the services behind them. Users, roles, gateway routes, rate limits and secret connectors all live in your Git repository — not in a UI someone clicked through once.

GitOps from day one

Every platform resource is a custom resource, so changes go through the same review and rollback process as your application code.

Reconciled, not scripted

The operator syncs resources to each service through create-if-not-exists endpoints. Re-applying is always safe.

A web UI when you want one

The console covers dashboards, incidents, flags, connectors and settings — with dark mode and full mobile support.

Why it is built this way

Opinions worth having

01

You bring the business logic

Everything a product needs but no product is really about — login, flags, secrets, alerts, long-running work — is the platform’s job. That division is the whole point.

02

One identity, everywhere

Identity is defined once and every service reads it. No duplicated user tables, no permission model that drifts from service to service.

03

Cloud native, wherever it runs

Kubernetes-native from the start, so it runs on any conformant cluster — any cloud, or your own hardware — and the managed service is the same software. Moving is a deployment decision, not a migration, and never a re-platforming.

04

Open protocols over lock-in

OFREP for flags, Grafana webhooks for alerts, standard OAuth for login. Swap OpsPlane out and your integrations still make sense.

Bring your platform under one roof

Tell us what your team is paying for today and we will help you work out whether OpsPlane replaces enough of it to be worth the move — or say so plainly if it does not.