Documentation
Everything you need to install infrawrench, connect your first account, and get the most out of the desktop and web apps.
Getting started
Core concepts
- Resources and accountsHow infrawrench organizes what you connect and what you manage.
- Output referencesWire one resource's output into another resource's input instead of copy-pasting.
- Secret rerollsReassign an output reference when the upstream resource changes.
- Desktop, web, and mobileWhat differs between the three surfaces, and how to pick.
- Resource AssociationsCross-resource relationships Infrawrench can create directly, and the association flows still planned.
- Credential preflightVerify what a credential can actually do — per capability — and generate a least-privilege policy to paste into the provider console.
- Resource ownershipOwner, purpose and ticket link as first-class fields on any resource — so the orphan finder names a person instead of a shrug, and alerts reach whoever actually cares.
Features
- DashboardPin the resources you actually use to a draggable grid.
- Cost graphs & budgetsSpend graphs, budgets, and overspend alerts for your connected accounts, right on the dashboard.
- Spotlight searchFuzzy-find any resource across every connected account with one shortcut.
- Cost reportsSave a cost graph as a named, addressable report, run it by name, and show it on as many dashboards as you like.
- Kubernetes cost allocationWork out what each namespace, workload, and pod in a cluster actually costs — compute, volumes, load balancers and the control-plane fee — including the capacity nobody is using.
- Live cost estimatesA running "$X/month" as you fill in a create form, the same figure on the resource afterwards, what an edit does to the bill before you save it, and the run-rate your week's changes leave behind.
- SSH terminalOpen a shell in any VM you can reach over SSH, without leaving the app.
- Tag policy, untagged spend & showbackRequire tags like owner and env on every resource, score compliance per account, find the spend that carries no tags, and map spend to cost centres.
- Unit costs & marginDivide your spend by the thing your business actually does — cost per customer, per request, per GB — and, for revenue metrics, margin.
- Fan-out SSHRun one command across many hosts at once, with identical output collapsed and the odd one out diffed.
- Scheduled cost exportsShip your raw cost rows to a warehouse or object store on a schedule, as CSV or NDJSON, with the restatement handling a finance system needs.
- SQL editorRun queries against Postgres, MySQL, Turso, Databricks, ClickHouse, and more.
- Jumpbox routingRoute SSH connections through one or more SSH jump hosts (ProxyJump), set up from the app.
- KV consoleRun Redis and Memcached commands against your connected caches.
- File browsersBrowse, upload, and download objects in cloud object storage and over SFTP.
- Linux applicationsOpen a graphical application from a Linux host in a workspace tab, over the SSH connection you already have.
- Speech testingSynthesize speech and transcribe audio against your connected AI providers, without leaving the app.
- SSH session recordingRecord every SSH session opened through the cloud and replay it later — who connected, to what, and exactly what crossed the terminal. Recordings are standard asciinema casts.
- Terraform exportEject a resource or a whole account's inventory as ready-to-import Terraform HCL.
- Custom graphsScript-defined dashboard charts — query costs, metrics, or any API from a sandboxed script that declares its own chart, controls, and refresh policy.
- Docker controlsStart, stop, and restart containers on a local or remote Docker host.
- Shared consolesPut a colleague on a live SSH session — one driver at a time, observers who genuinely cannot type, a short-lived invite, and an audit entry for every join and handover.
- Terraform providerManage Infrawrench's own configuration — budgets and cost policy, probes and alerts, schedules and freezes, accounts, roles and alert routing — as Terraform resources.
- Blast radiusWhat breaks if you delete a resource — dependants, the dashboards and probes that point at it, what talks to it over the network, and what couldn't be checked.
- Dependency graphSee how your resources are wired together — read from your synced cloud data and from output references — and what breaks if one of them goes down.
- DNS recordsBrowse a zone's DNS records as a table and point A/AAAA/CNAME records at other resources.
- Manifest editorEdit raw provider manifests (Kubernetes, Cloudflare) in a Monaco editor.
- WorkflowsAutomate across all your connected accounts with sandboxed TypeScript — triggered manually, on a schedule, or from git.
- Backup coverageWhat is actually recoverable across every provider — which resources have a backup, how old the newest one is, and which backups protect something that no longer exists.
- Bastion VMsRoute a cloud account's control-plane API calls through your own infrastructure instead of Infrawrench's.
- Bucket policy editorInteractive editor for S3-style bucket policies — statement builder, presets, lint, and plain-English summaries.
- Domains & dangling DNSEvery DNS zone and record across every provider in one view, with potential subdomain-takeover risks — a record pointing at a provider name nothing in the connected workspace claims — flagged automatically.
- Expose a service over a Cloudflare TunnelDrag a Cloudflare Tunnel onto a server to expose HTTP, SSH, or TCP over Cloudflare's edge — no inbound ports.
- InfrafileOne file at your repo root that describes how your project is built and deployed — the environments it supports, an interactive plan, a Dockerfile, and a deploy script.
- Provider status correlationInfrawrench watches your providers' public status pages and tells you when an upstream incident overlaps resources you actually hold — is it me, or is it them?
- Scenario modelsOverlay known future cost — a purchase, a new team, a migration — onto a forecast, without ever touching the trend or your recorded spend.
- Secret export to KubernetesDrag a cloud resource onto a cluster to create a K8s secret with its credentials.
- Billing rulesMarkups, discounts, fixed charges and reallocations applied to collected spend at report time — with the collected figure always shown beside the adjusted one.
- Expiry radarOne cross-provider countdown of everything with a clock on it — TLS certificates, domain registrations, API tokens, database passwords, secret rotation age — with alerts before anything runs out.
- Investigate a momentEnter a timestamp and get one merged, chronological narrative of everything that happened around it — changes, incidents, cost anomalies, workflow runs, deployments, audit entries and freezes.
- Operations calendarEvery dated thing your infrastructure already knows about, on one axis — change freezes, sleep windows, expiring certificates and leases, commitment terms, scheduled runs and incidents. Subscribe to it from any calendar app.
- SSH tunnelsReach a database or service that only listens on a bastion's loopback, by connecting to it through SSH.
- Managed accounts & invoicesBill customers for the infrastructure you run on their behalf — customers scoped to cost centres, invoices that freeze when you approve them, and a derivation you can hand to accounts payable.
- MCP serverDrive infrawrench from Claude Desktop, Cursor, or any other Model Context Protocol client.
- Posture checksPlugin-declared security checks over already-synced resources — public buckets, world-open firewall rules, unencrypted disks, stale credentials — ranked by severity, with alerts on the worst of it.
- RunbooksThe checklist somebody wrote at 03:00, kept where the steps are actually performed — with a record of who did what, which is the half a postmortem always misses.
- Sleep/wake schedulesStop non-prod resources outside working hours and start them back automatically — off at 19:00, on at 08:00, Mon–Fri — with a projected monthly saving quoted before you save.
- Synthetic probesHTTP uptime and latency checks run on an interval from outside your infrastructure, with auto-suggested endpoints, latency charts, trailing uptime, and alerts after N consecutive failures.
- Access reviewOne list of every principal inside your connected clouds — IAM users and roles, service accounts, app registrations, groups, bindings and long-lived keys — with stale, over-privileged, unrotated and unowned access flagged, and a CSV you can hand an auditor.
- Agent authenticationLet an AI agent register itself, work in a 24-hour trial workspace, and hand it to you when you're ready.
- AI chatDrive your infrastructure through an AI agent — same tools as the UI, with a human-in-the-loop for destructive actions.
- Environment diffTwo accounts of the same provider compared side by side — resource types present in one and not the other, count deltas, and the settings on which corresponding resources disagree.
- Incident modeDeclare an incident once and it opens the change freeze, pins the moment, tells your org, and posts the public update — then assembles the timeline and pre-fills the postmortem.
- Log workspaceTail several resources' logs in one pane, search across the merged stream, save the set-up as a named query, and optionally alert when a line matches.
- Network costsWhich two things are talking, across which billing boundary, and what that costs — priced egress and cross-zone attribution from your VPC flow logs.
- On-call rotationsWho to wake, rather than which channel to shout into — rotations, covers, and an alert routing destination that keeps meaning "whoever is on call" after Monday's handover.
- Public status pagesPublish the synthetic probes you already run at a public link — current state, 24-hour uptime and 90 days of history, with no probe URLs or account details exposed.
- Quota & limit radarPer-account provider quota utilisation, the trend that says whether it is getting closer, and an alert before a limit stops your next deploy.
- Resource leasesPut an expiry on any resource — "a test cluster for 3 days" — get nagged through the expiry radar as it approaches, and optionally have the resource auto-deleted when the lease runs out.
- Command-line interfaceRun Infrawrench from any terminal — an interactive TUI dashboard plus scriptable JSON and text output, sharing the desktop app's accounts and cloud session.
- Credit burndownPrepaid balances with a measured burn rate and a runway — "$42 left, six days at your current spend" — for the providers that expose a credit balance.
- Ephemeral environmentsCapture the environment you already have as a reusable template, stamp out a fresh copy on demand with a required time-to-live, and let it delete itself when the clock runs out.
- Query monitorsA read-only SQL query on a schedule, with a threshold and an alert — for the incidents that are visible in your data and in no metric.
- Reading the site as markdownEvery page on infrawrench.com is available as markdown, for agents and anything else that would rather not parse HTML.
- Send test messagesPublish a one-off message into a queue, topic, stream, or event bus straight from the resource detail page.
- Alert routing rulesRoute each alert to the right channel by condition, hold alerts during quiet hours, and escalate the ones nobody acknowledges.
- CommitmentsReserved instances, savings plans and committed-use discounts — what you hold, how much of your bill it covers, whether it's being used, and what to buy next.
- Mobile appThe Infrawrench app for iOS and Android — browse resources, watch dashboards, chat with the AI, and open an SSH terminal from your phone.
- Orphan & idle resource finderFlag likely-wasted resources — unattached volumes, unassigned IPs — across your connected accounts, with the monthly cost where billing data exists.
- Right-sizing (Oversized resources)Find machines whose two-week p95 CPU (and memory, where measured) sits well under their size, get the smallest size that still leaves headroom, and apply the resize in one click.
- WallboardOne screen, read from across the room — everything that is wrong right now, in type large enough to see from four metres.
- Mobile push notificationsIncident and budget alerts delivered to the Infrawrench mobile app, with per-org toggles and web-managed devices.
- Slack alerts and commandsRoute alerts to Slack channels, approve or deny workflow and agent approvals with message buttons, and query costs and resource status with /infrawrench.
- Microsoft Teams alertsDeliver Infrawrench alerts to Microsoft Teams channels by webhook URL, routed by your alert rules.
- Jira issuesTurn a cost anomaly, orphaned or oversized resource, posture finding, expiring credential, or failed probe into a tracked Jira issue, with the issue link kept on the finding.
- Push from your own serversRaise on-call pages and report your own cost data over the HTTP API, from code running anywhere.
- Linear issuesTurn a cost anomaly, orphaned or oversized resource, posture finding, expiring credential, or failed probe into a tracked Linear issue, with the issue link kept on the finding.
- Weekly digestA scheduled summary of last week's spend, top movers, sync incidents, and resource churn, delivered to Slack, Microsoft Teams, and email.
- AgentsProvision coding VMs from VM-capable cloud accounts and reconcile their branches locally.
- T3 Code serversRun the T3 Code harness on an agent VM, provisioned and authorized from Infrawrench.
- Account settingsManage your name, password, two-factor authentication, and active sessions from Settings → General.
- Change timelineA cross-provider drift feed — see every resource that appeared, changed, or disappeared between polls, org-wide or per resource, with optional batched drift alerts.
- Commitment & unit-cost alertsThree alerts derived from facts no spend total contains — a commitment about to lapse, a commitment nobody is using, and cost per unit of a business metric going the wrong way.
- Config as codeExport your organization's dashboards, workflows, budgets, graphs, alert rules and policies as one JSON document, keep it in git, and apply it back.
- Cost anomaly alertsAutomatic detection of unusual spend spikes and brand-new spend sources per provider and per service, with alerts through push, Slack, Microsoft Teams, and optional SMS.
- Cost change alertsConfigured alerts that fire when spend on a chosen scope moves more than a chosen percent or amount versus the prior period, on a daily, weekly, or monthly cadence.
- Cost per change & cost per deployWhat a change or a deployment actually did to your bill — a run-rate delta measured from collected provider spend either side of it, with the confidence to go with it.
- IaC reconciliationUpload the Terraform state you already have and Infrawrench classifies every synced resource as managed, drifted, or unmanaged — then writes the import blocks to adopt the unmanaged ones.
- Interface languageSwitch the app's UI language per device — English, Spanish, French, German, Japanese or Chinese — from Settings → General.
- Metric alertsThreshold rules over collected metrics — "CPU above 90% for 15 minutes" — that select resources by query and page you through push, Slack, and Microsoft Teams, with recovery notifications when the condition clears.
Plugins
- AWSManage EC2, EKS, RDS, Lambda, S3, and most of the AWS surface area.
- AzureManage VMs, AKS, App Service, SQL Database, CosmosDB, and storage.
- Google CloudManage Compute Engine, GKE, Cloud SQL, App Engine, BigQuery, and GCS.
- DigitalOceanManage Droplets, Kubernetes, managed databases, Spaces, and DNS.
- Hetzner CloudManage Hetzner servers, volumes, networks, load balancers, images, and IP resources, with estimated spend priced from the published rate card.
- ScalewayManage Scaleway Compute instances, Kapsule, managed RDB, Object Storage, and Block Storage.
- OVHcloudManage OVH public cloud projects and services.
- Fly.ioManage Fly apps, machines, volumes, certificates, and IP allocations across 36 regions.
- KubernetesBrowse, edit, and run workloads against any kubeconfig-reachable cluster.
- PostgreSQLAdd a Postgres account and get a live SQL editor with schema introspection.
- MySQLAdd a MySQL or MariaDB account and use the in-app SQL editor.
- NeonManage Neon projects, branches, databases, snapshots, object storage, functions, and auth; get connection strings as outputs.
- SQL ServerConnect to a Microsoft SQL Server database and run queries from the SQL editor.
- PlanetScaleManage PlanetScale databases, branches, deploy requests, backups, and passwords.
- TursoManage Turso groups, databases, instances, API tokens, members, and edge locations.
- RedisConnect to any Redis (or Redis-compatible) instance and run commands.
- MemcachedConnect to a Memcached server and run text-protocol commands.
- MongoDBBrowse MongoDB databases, collections, and documents.
- DatabricksManage Databricks compute, workflows, SQL, AI/BI, apps, model serving, vector search, and Unity Catalog.
- ClickHouseManage ClickHouse Cloud services and query HTTP interface endpoints.
- CloudflareManage zones, DNS, Workers, R2, KV, D1, Tunnels, Access, and more.
- NetlifyManage Netlify sites, deploys, forms, DNS zones, and environment variables.
- VercelManage Vercel projects, deployments, domains, environment variables, and teams.
- DockerControl containers on a local or remote Docker host.
- SSHRegister a plain SSH host so you can open a terminal from the app.
- CloudinaryManage Cloudinary folders, media assets, upload presets, and transformations.
- OpenSearchConnect to an OpenSearch (or Elasticsearch-compatible) cluster — browse indices, run searches, manage snapshots.
- KafkaConnect to any Apache Kafka cluster — browse topics, consumer groups, and cluster metadata.
- OpenAIModels, fine-tuning, batches, files, vector stores, containers and evals, plus organization projects, members, keys and real spend — with a Speech tab for text-to-speech and transcription.
- AnthropicClaude models, Message Batches and Files, plus workspaces, members, invites, API keys, usage and cost reporting with an Admin API key.
- Google GeminiThe Gemini API on Google AI Studio — models, tuned models, files, context caches, batches and File Search stores, plus speech synthesis and transcription.
- DeepSeekDeepSeek's complete REST surface — the model list and the prepaid credit balance.
- CohereCohere's Command, Embed, Rerank and Transcribe models, plus the datasets, fine-tunes, embed jobs and batches in your account.
- xAIBrowse Grok models, files, batches and voices, manage team API keys and read the audit log, and run Grok speech synthesis and transcription from the Speech tab.
- OpenRouterBrowse the OpenRouter catalogue with per-provider pricing, uptime and latency percentiles, manage API keys and credits, and run speech synthesis and transcription from the Speech tab.
- Together AIDedicated endpoints, fine-tunes, files, batches and evaluations on Together AI — plus a Speech tab for text-to-speech and Whisper transcription.
- ReplicateBrowse Replicate predictions, models, trainings and files, and create or rescale deployments.
- Fireworks AIManage Fireworks deployments, models, datasets, fine-tuning and batch jobs, API keys, secrets and quotas — with real usage costs.
- GroqBrowse the GroqCloud model catalogue, batches, files, and LoRA adapters, and run Whisper transcription and Orpheus speech synthesis from the Speech tab.
- Mistral AIManage Mistral models, voices, files, fine-tuning and batch jobs, plus Voxtral transcription and speech synthesis from the Speech tab.
- ElevenLabsBrowse ElevenLabs voices, models, pronunciation dictionaries and generation history, and run text-to-speech and Scribe transcription from the Speech tab.
- DeepgramManage Deepgram projects, API keys, members, invites and prepaid balances, chart usage, and round-trip audio through Nova transcription and Aura voices.
- AssemblyAIBrowse the account's transcripts and run a full upload-submit-poll transcription from the Speech tab in one step.
- SpeechmaticsBatch transcription jobs on a regional endpoint, plus workspace projects and API keys through the Management API, and a Speech tab that transcribes in one request.
- CartesiaBrowse Cartesia voices and pronunciation dictionaries, list API keys and track estimated credit spend with an admin key, and run Sonic synthesis and Ink Whisper transcription from the Speech tab.
- Rev AIRev AI transcription jobs, custom vocabularies and account balances on either deployment, with a Speech tab that submits and polls a clip in one step.
- GladiaGladia pre-recorded transcription jobs and their results, with a Speech tab that uploads, submits and polls a clip in one step.
- WorkOSManage WorkOS organizations, users, memberships and invitations, watch SSO connections and Directory Sync directories, define roles, and wire up webhook endpoints.
- UploadThingBrowse, upload, rename, re-permission, and delete the files in an UploadThing app, and watch its storage quota.
Team & billing
- Organizations and invitesShare a workspace with teammates.
- Roles and permissionsSystem roles, custom roles, and the permission model.
- Billing and plansWhat is free, what is paid, and how to upgrade.
- Audit logSee who did what across your organization.
- Break-glass accessTime-boxed permission elevation. Ask for the permissions you need, for the minutes you need them, with a reason; someone else approves; the elevation lapses on its own.
- API keysIssue tokens for programmatic access to your infrawrench organization.
- Credential hygieneAPI keys nobody uses, SSH keys nothing references, and members holding write permissions they never exercise — from data Infrawrench already holds, with nothing to install.
- API reference (OpenAPI)How to find, generate, and use the OpenAPI 3.1 spec for the Infrawrench cloud API.
- SSH keysSave private keys once and reuse them across every SSH session.
- Client SDKsGenerated, MIT-licensed API clients for nine languages, built from the OpenAPI spec.
- Trusted SSH hostsPinned SSH host-key fingerprints — review and revoke trust.
- Change freezesDeclare org-wide freeze windows that block destructive actions, with audited admin overrides.