Skip to main content
CozyHawk

Blueprint library

A blueprint library, not a one-off integration.

A blueprint is a battle-tested combination of catalog modules: the exact infrastructure as code, composed the way a senior platform engineer would build it, every setting editable before anything exists. Cloud-agnostic by design.

Every change:ProposePlanReviewApplyEvidence
Available now · our first blueprints run on AWS
  • Governed cloud foundation: accounts, network, guardrails, and identity, the foundation everything else lands on.
  • Kubernetes workload platform: clusters, access, registry, and observability, where your apps run.
  • Encrypted data service: a managed database with encryption at rest and governed secrets, a data tier by the book.

Every one editable, every change through the same gate.

Coming next

New module combinations

Admitted onto the same gate and evidence machinery.

On the roadmap

Beyond the first cloud

The gate and the evidence layer don’t care which cloud is underneath.

Don’t see what you need? Bring your own modules and Helm charts, governed the same, or request it: we turn requests around in 24 to 48 hours.

The Infrastructure picker: your modules with draft files, a catalog search, and network modules like VPC and DNS ready to add.
The library as it looks in the product: your modules and the catalog, side by side, ready to add to your platform.

What a blueprint stands up, an example

One example combination: Blueprint #1’s governed foundation with the Kubernetes workload platform composed on top. Every unit is editable, and yours is only the units you choose.

AWS accounts & guardrails

A clean multi-account structure with organization-level guardrails, so teams can move fast inside safe boundaries.

VPC networking

Production-shaped networks: subnets, routing, and egress, designed once and stamped out consistently per environment.

EKS clusters

Managed Kubernetes clusters built to run real workloads, with upgrades and access handled as reviewed changes.

GitOps delivery (Flux)

Delivery that pulls from your Git, not our servers.

Workloads sync from your repositories via Flux: the same source of truth your platform code lives in. What's running is what's merged.

Access & SSO

Single sign-on wired to your identity provider, with cluster and account access granted by role, not by shared keys.

Add-ons

The operators that make a cluster a platform: load balancing, DNS, certificates, secrets, and observability, with their Helm values visible and editable, delivered through GitOps.

Any standard module can become a governed module.

Breadth here means composability, not a wall of tiles. Three doors into the same gate:

A curated catalog

Battle-tested modules, vetted and kept current, composed the way a senior platform engineer would build them. Quality over volume: every module earns its place.

Bring your own, first-class

Your Terraform or OpenTofu modules and Helm charts, private or from the open-source commons. CozyHawk reads their variables, makes them editable, and governs them through the same gate as the catalog.

Don’t see it? Request it.

Ask for a module or a blueprint and we turn it around in 24 to 48 hours, onto the same gate and the same evidence machinery. Request a module

Inside every blueprint

Standard infrastructure as code in your Git, front to back, and leaving is always possible. See the whole story →

Want this platform, governed?

Start from the foundation blueprint, or bring the platform you already run.