Gateway
A reverse proxy that already knows your platform identity, with routing, load balancing, rate limits and WASM plugins on both the request and the response path.
Managed or self-hosted
Identity and secrets, observability, SLOs and incidents, feature flags, an API gateway, an AI stack and durable execution — in one cloud-native platform, run as a managed service or on your own infrastructure. Broad enough to replace a shelf of SaaS subscriptions, small enough that one team can operate it. You write the business logic; OpsPlane covers everything around it.
The platform
Each service runs independently, with its own database and API. Run all of them, or only the ones you need — they share one identity model, one gateway and one audit trail.
A reverse proxy that already knows your platform identity, with routing, load balancing, rate limits and WASM plugins on both the request and the response path.
A vendor-neutral flag service that speaks OFREP, so any OpenFeature SDK works against it out of the box.
One chat interface over the whole AI surface, with many separate AI components behind a single front end and the same identity and audit trail as everything else.
Long-running work that survives restarts, retries and deploys, so you are not hand-writing the bookkeeping around it.
Metrics, logs and traces from your services under one query surface, feeding the same objectives and alerts the incident side runs on.
Service objectives that decide what counts as a problem, and a reviewable incident record built from the alerts they raise.
Who someone is and what they can reach, in one place, with a single API in front of every secret store you already run.
How you run it
It is the same software either way, and it runs on any cloud — so the choice is a deployment decision rather than a commitment. Start managed and bring it in-house later, or the other way round.
We run the platform for you. Nothing to install, upgrade or keep available, and one bill instead of the shelf of subscriptions it replaces.
You run it on your own Kubernetes cluster — on AWS, Google Cloud, Azure or your own hardware — against your own PostgreSQL and inside your own network boundary, so your incident data and your prompts never leave your infrastructure.
The economics
Every service here is something teams normally buy separately. Bought separately, each one also has to be integrated separately, reviewed separately and renewed separately — and that is rarely the bill anyone counts.
Feature flags, observability, incident management, secret management, a gateway and an AI layer are six or seven vendors at most companies. Here they are one thing you run.
The services share identity, gateway and audit trail by design, so you are not writing glue between vendors who never planned for each other.
One codebase, one deployment, one data boundary to assess — instead of a fresh questionnaire per vendor, every renewal cycle.
A handful of services and one PostgreSQL. Self-hosted, it is not meant to become a platform team’s full-time job — and managed, there is nothing to run at all.
Declarative by default
A Kubernetes operator watches your custom resources and reconciles them into the services behind them. Users, roles, gateway routes, rate limits and secret connectors all live in your Git repository — not in a UI someone clicked through once.
Every platform resource is a custom resource, so changes go through the same review and rollback process as your application code.
The operator syncs resources to each service through create-if-not-exists endpoints. Re-applying is always safe.
The console covers dashboards, incidents, flags, connectors and settings — with dark mode and full mobile support.
Why it is built this way
Everything a product needs but no product is really about — login, flags, secrets, alerts, long-running work — is the platform’s job. That division is the whole point.
Identity is defined once and every service reads it. No duplicated user tables, no permission model that drifts from service to service.
Kubernetes-native from the start, so it runs on any conformant cluster — any cloud, or your own hardware — and the managed service is the same software. Moving is a deployment decision, not a migration, and never a re-platforming.
OFREP for flags, Grafana webhooks for alerts, standard OAuth for login. Swap OpsPlane out and your integrations still make sense.
Tell us what your team is paying for today and we will help you work out whether OpsPlane replaces enough of it to be worth the move — or say so plainly if it does not.