Show HN: Spacelift – first all-in-one CI/CD for Infrastructure as Code Hi HN! We are the team behind Spacelift (https://spacelift.io/). Spacelift is the CI/CD for infrastructure-as-code, be it Terraform, Pulumi, CloudFormation or Ansible (coming soon), and policy as code. It enables collaboration, automates manual work and compliance, and lets teams customize and automate their workflows. Here’s what you can do with Spacelift - Build sophisticated Git-based workflows - Use Open Policy Agent to declare rules around your infrastructure, access control, state changes, and more - Author and maintain reusable modules for your organization; we even have a full CI solution for modules to make sure they’re healthy - Declare who can log in (and under what circumstances) and what their level of access to each of the managed projects should be (SAML 2.0 SSO out of the box!) using login and access policies respectively - Use Spacelift’s trigger policies to create arbitrary workflows and dependencies spanning multiple infrastructure-as-code stacks - Manage stacks, contexts, modules, and policies in a declarative way using Terraform or Pulumi Before Spacelift, we built bespoke solutions (e.g., Geopoiesis, https://ift.tt/3tPrMlN), currently used by two of the largest European scaleups. In the past few months, we’ve been onboarding our first customers and making sure everything works as expected. You can check out our starter repo at https://ift.tt/3qdPAO3. It's an easy way to learn all of Spacelift’s capabilities in 15 minutes without tapping into your own cloud resources. We’d love your thoughts on our approach and anything that has worked or hasn’t worked for you. P.S. We are hiring https://ift.tt/3q82opg P.P.S. We just announced our funding round https://ift.tt/371ktxI February 11, 2021 at 09:36PM
Show HN: Launch VM workloads securely and instantaneously, without VMs Hello HN! We've been working on a new hypervisor https://kwarantine.xyz that can run strongly isolated containers. This is still a WIP, but we wanted to give the community an idea about our approach, its benefits, and various use cases it unlocks. Today, VMs are used to host containers, and make up for the lack of strong security as well as kernel isolation in containers. This work adds this missing security piece in containers. We plan on launching a free private beta soon. Meanwhile, we'd deeply appreciate any feedback, and happy to answer any questions here or on our slack channel. Thanks! April 29, 2021 at 07:50AM
Comments