CloudPanorama

Self-hosted · AWS and Google Cloud · Evaluation by invitation

Your cloud estate, read as one record.

Inventory, health history, every change, spend with its owner, and approved changes, joined on one resource identity. The engineer, the finance lead and the approver read the same facts.

Book a call Open the demo

Runs in your own environment. No hosted signup, no anonymous trial. The demo needs evaluation credentials; its public status page does not.

Estate · Timelinedemo-production
Timeline
Status transitions, newest first
Operational1,384
Degraded3
Failed0
TimeResourceFromTo
14:42:03i-0…4d · eu-west-1 failed operational
14:42:03i-0…42 · eu-west-1 failed operational
14:02:11i-0…4d · eu-west-1 operational failed
14:02:11i-0…42 · eu-west-1 operational failed
Illustration. The timeline in the portal shell; times and ids are example data.

01 Estate

See what changed, when, and whether it recovered.

Health is derived from what AWS reports, never entered by hand. Every transition to operational, degraded, failed or deleted becomes a permanent timeline entry, from the environment down to the instance.

  • Fourteen collectors — EC2, EKS, RDS, S3, DynamoDB, load balancers, SQS, SNS, API Gateway, Backup, ACM, NAT gateways and CloudFront, each with the IAM actions it makes.
  • One outage, one message. Alerts group by incident and route to the owning team's Slack channel or webhook; a member acknowledges one with a note, and the acknowledgement is on the timeline.
  • Every change on one feed — configuration diffs between snapshots, status transitions, acknowledgements, provisioning outcomes, cost anomalies and budget thresholds, ordered by the event's own time, with the deploys and runbook steps your own systems post as markers.
  • Who owns it, and what it touches. One resolver decides every resource's owning team with confidence and evidence; its page draws what contains it, runs on it, fronts it, guards it, provisioned it and owns it.
  • Performance beside health — latency, errors and saturation from CloudWatch with statistics, interactive charts and topology, EKS from the control plane to each pod.
  • A public status page from the same data, with names, ids, accounts and regions left out — the front door for anyone without a session.
  • Google Cloud projects beside the AWS accounts: BigQuery datasets, service accounts, Firebase apps and Cloud Functions, read through workload identity with a metadata-only role.
StatusThu 4 Sep · 14:20
  • Down Production has been down since 14:02 (18 minutes). 1 service is affected. 14:02 ec2: 12 instances became failed
  • Healthy Staging is healthy.
  • Healthy Sdlc is healthy.
Illustration. The public status page; example data.
Team · paymentsSeptember, month to date · EUR
direct + allocated + untagged2,363.00
  • Direct 1,842.10
  • Allocated 402.55
  • Untagged 118.35
Billing but gonelast 14 days · 10 resources
ResourceLast seenAmount
i-0…a112 days ago41.20
i-0…b39 days ago27.85
i-0…c93 days ago6.10
Budget 12,000 / month 19.7 % used
Illustration. Spend by team; example amounts.

02 Spend

Every euro attributed to a team that can act on it.

Cost Explorer and Cost & Usage Report data land in one view, amortized or unblended, with each currency kept separate. Allocation rules map tags and accounts to teams; change a rule and history is recalculated in the open.

  • Gaps billing views miss — resources still billing after they vanished, and resources with no cost at all.
  • Monthly budgets, anomalies and Trusted Advisor recommendations, delivered to the same team channel as health alerts.
  • Kubernetes attribution by workload, from the pods and nodes last seen, with the approximation stated beside the figures.
  • A month-end forecast with its range and its measured error beside it, on the tenant, team and account pages; every figure with the owner the resolver decided.

03 Provisioning

A paved road for developers. The keys stay with you.

Publish versioned OpenTofu templates with typed inputs. Requests go through team-scoped approval, and the exact commit that was approved is the code the agent runs: inside your network, with your AWS and Git credentials.

  • Provenance on every resource — request, template version, requester and approver, as a tag.
  • Drift in both directions — approved resources now missing, and live resources with no request.
  • Partial applies stop for review. State is preserved and the recovery path is shown; nothing is destroyed on its own.

Templates, approvals, the agent, provenance, drift and an OpenTofu apply against a live AWS account are available now — a test estate is brought up and torn down through the product's own templates; the agent's page covers install, configuration and what it can never do.

Request 8f3c1d2e-… succeeded
Template
web-tier v3 · git 4e1a9c2
Account
000000000001 · eu-west-1
Provenance
panorama:request_id = 8f3c1d2e-…
Resources
12 aws/ec2/instance
  1. 10:14Submitted by m.kowalski
  2. 10:31Approved by j.ortiz, team payments
  3. 10:39Applied by agent-prod-eu · OpenTofu 1.12.6, pinned in the image
Illustration. A provisioning request; names and ids are example data.

What the build does today.

The capability matrix, by module, with the same three words the documentation uses: available now is implemented and test-backed in the build, in development has a live verification or a dependency still open, planned has no date. This section is generated from the matrix, which the build's own tests hold to what runs.

Estate

  • Inventory, derived health and the permanent status history available now
  • Alerts, Slack and webhook notifications, and a public status page without identifiers — the front door for a visitor with no session available now
  • Acknowledgeable alerts: a member acknowledges with a required note; the alert leaves the list until the resource changes again, and the acknowledgement is on the timeline available now
  • Tag-defined application groups and declared apps, and freshness by each module's cadence available now
  • Configuration diffs between snapshots on every resource's page, sensitive fields suppressed available now
  • The change feed: configuration diffs, status transitions, acknowledgements, provisioning outcomes, cost anomalies and budget thresholds in one timeline per resource, account, app and team, ordered by the event's own time, with markers the customer's own systems post under a marker credential available now
  • Ownership: one resolver deciding every resource's owning team from overrides, provenance, tags, the account and its relationships, with confidence and evidence, on every page that names an owner available now
  • Relationships: a resource's neighbours — what contains it, what runs on it, what fronts and guards it, what provisioned it, the apps it belongs to, the team that owns it — each with evidence and confidence, drawn on its page available now
  • Performance: latency, errors and saturation from CloudWatch with statistics, interactive charts and topology diagrams; EKS in depth, from the control plane to each pod available now
  • Google Cloud projects: BigQuery datasets, service accounts, Firebase apps and Cloud Functions, read through workload identity federation with a metadata-only custom role (p7_82) available now

Spend

  • Cost Explorer ingestion with a 12-month backfill; Cost & Usage Report ingestion and amortization available now
  • Tag allocation rules, inventory exceptions, anomalies, team budgets and Trusted Advisor recommendations available now
  • Kubernetes attribution by the pods and nodes last seen, a current-placement approximation stated beside the figures available now
  • Month-end forecasts with their range and measured error, on the tenant, team and account pages available now

Provisioning

  • Versioned templates, typed inputs, approvals, provenance tags, drift detection and scrubbed execution logs available now
  • The customer-run agent: a broker that holds the token and a worker that runs OpenTofu under another user available now
  • An OpenTofu apply against a live AWS account: the test estate brought up and torn down through the product's own templates (p7_81) available now
  • In-place updates of a provisioned stack not in v1

Platform

  • Users, roles and teams; sessions with a per-user cap; step-up for destructive administrator actions; the audit trail available now
  • The Admin area — the organisation, the audit log and an overview of the licence, the people and the accounts — and each user's own settings: profile, sessions, notifications, preferences available now
  • Backups and a restore that does not replay cloud changes (the runbook, "Backing up and restoring the database") available now
  • Single sign-on through the organisation's OpenID Connect provider (Entra ID, Okta, Google, IAM Identity Center), beside passwords or enforced with break-glass administrators; with the Enterprise licence's sso capability available now
  • Directory group sync: teams bound to the provider's groups, membership following the directory available now
  • SAML single sign-on and SCIM provisioning planned
  • The AI reviewer channel: alerts and cost anomalies handed to an operator's own reviewer as claim checks, its answer on the subject and in the inbox, with evidence the tenant can see available now
  • The reviewer service itself, with a local model first in development
  • The operator's manual, served to administrators inside the product in development

Why it holds together

One resource key. Every view resolves to it.

Health tools, billing exports and infrastructure-as-code each keep their own record of the same instance. Here they share one stable identity, so a line in a bill, a failed status and an approved request are the same row, not three spreadsheets to reconcile.

  • 000000000001
  • /
  • eu-west-1
  • /
  • aws
  • /
  • ec2
  • /
  • instance
  • /
  • i-0…42
  • EstateHealth, now and pastoperational since 14:42:03
  • SpendCost and allocationEUR 41.20 · team=payments
  • ProvisioningRequest and approval8f3c1d2e-… · web-tier v3
  • AppsGrouped by tagapp=checkout · 12 resources
  • ChangesEvery change, one feed14:02 config diff · 14:00 deploy marker
  • OwnerDecided, with evidenceteam=payments · tag · high

Runs where your credentials already live.

One image, PostgreSQL 16, and a read-only cross-account role you can audit line by line. Nothing leaves your environment unless you send it.

Self-hosted

available now
  • Docker Compose or Kubernetes kustomizations; one Deployment per runtime role.
  • A signed offline licence, verified by the binary alone. Nothing phones home; nothing is deleted when a licence lapses.
  • A reader role with an ExternalId per tenant, no s3:GetObject and no default passwords. The optional report role reads only your Cost & Usage Report prefix.
  • Row-level security on every tenant table; Prometheus metrics from every role.
  • An Admin area for the organisation, the audit log and the licence; an AI reviewer channel that hands alerts and anomalies to a reviewer you run, its answer on the subject.
# Postgres and every role, seeded
SEED_DEMO=true make compose-up

Private, today. The repository and image are invitation-only until the first pilot. With access, the installation guide takes it from here; without it, ask.

The capability matrix lists every module that runs, what it reads and the versions it is tested on; the security assessment lists the controls, their tests and their limits. An external penetration test has not been completed.

Hosted

planned
  • Operated for you, with tenant lifecycle, export and deletion.
  • Self-serve signup and billing.
  • A status page for the service itself.

No date is promised. Teams that want it early shape it: say so on the call.

Three tiers, scaled per connected AWS account.

Flat bundles of modules. Prices are not published yet; they are discussed on the call, and nothing is charged for evaluation.

Essentials

Know what runs and whether it is healthy.

  • Estate
  • Spend
  • Provisioning
Talk about Essentials

Enterprise

Approved changes, and the enterprise capabilities: single sign-on through your OpenID Connect provider and directory group sync, available now; SAML and SCIM planned.

  • Estate
  • Spend
  • Provisioning
Talk about Enterprise

Thirty minutes, your accounts, no slides.

A walk through the running demo, then the questions that matter for your estate: which collectors, which cost sources, where the agent runs. Evaluation access follows the call.