Code to Cloud
Follows every artefact from the commit that built it to the registry that holds it and the clusters that run it, with the exact version at each step.
What it watches
- Commit to build
Which commit, branch and pipeline run produced each artefact, and who approved the merge.
- What was pushed
Every image and package pushed to your registries: name, tag, version and immutable digest.
- What it carries
The SBOM, the signature and the build provenance attached to each digest, or the lack of them.
- What is deployed
The exact digest running in each environment and cluster, read from the runtime, not from the pipeline log.
- Drift
Running digests no pipeline built, tags that moved, prod ahead of staging, versions that never got promoted.
- Exposure
Which deployed versions carry a vulnerable or malicious package, so you fix what is running, not what is in the repo.
One service, every version, every place
A slice of the view for one project. The tower compares what each registry holds with what each cluster runs, digest by digest.
| Service | Commit | Pushed to registry | Staging | Production | Status |
|---|---|---|---|---|---|
| payments-api | a41f9c2 | 2.4.1 · sha256:7d1e… | 2.4.1 · 7d1e… | 2.4.1 · 7d1e… | Signed, SBOM, in sync |
| ledger-worker | 9be0d17 | 1.12.0 · sha256:c03a… | 1.12.0 · c03a… | 1.11.3 · 5f9b… | Waiting for promotion |
| partner-gateway | unknown | 3.0.2 · sha256:e88d… | 3.0.2 · e88d… | 3.0.2 · 1a4c… | Prod digest not built by CI |
| web-frontend | f20c6aa | 5.8.0 · sha256:42bd… | 5.8.0 · 42bd… | 5.8.0 · 42bd… | No signature |
| notify-svc | 77d2e01 | 0.9.4 · sha256:b6f0… | 0.9.4 · b6f0… | 0.9.4 · b6f0… | Carries a flagged package |
How it connects
Every module reports to the tower. Some feed each other.
The services behind it
The module watches. These services set the station up, with your team, so there is something worth watching.
In development. Early-access teams get it first and shape what it watches.
Join early access →