Blueprint library
A blueprint library, not a one-off integration.
A blueprint is a battle-tested combination of catalog modules: the exact infrastructure as code, composed the way a senior platform engineer would build it, every setting editable before anything exists. Cloud-agnostic by design.
- Governed cloud foundation: accounts, network, guardrails, and identity, the foundation everything else lands on.
- Kubernetes workload platform: clusters, access, registry, and observability, where your apps run.
- Encrypted data service: a managed database with encryption at rest and governed secrets, a data tier by the book.
Every one editable, every change through the same gate.
Coming next
New module combinations
Admitted onto the same gate and evidence machinery.
On the roadmap
Beyond the first cloud
The gate and the evidence layer don’t care which cloud is underneath.
Don’t see what you need? Bring your own modules and Helm charts, governed the same, or request it: we turn requests around in 24 to 48 hours.

What a blueprint stands up, an example
One example combination: Blueprint #1’s governed foundation with the Kubernetes workload platform composed on top. Every unit is editable, and yours is only the units you choose.
AWS accounts & guardrails
A clean multi-account structure with organization-level guardrails, so teams can move fast inside safe boundaries.
VPC networking
Production-shaped networks: subnets, routing, and egress, designed once and stamped out consistently per environment.
EKS clusters
Managed Kubernetes clusters built to run real workloads, with upgrades and access handled as reviewed changes.
GitOps delivery (Flux)
Delivery that pulls from your Git, not our servers.
Workloads sync from your repositories via Flux: the same source of truth your platform code lives in. What's running is what's merged.
Access & SSO
Single sign-on wired to your identity provider, with cluster and account access granted by role, not by shared keys.
Add-ons
The operators that make a cluster a platform: load balancing, DNS, certificates, secrets, and observability, with their Helm values visible and editable, delivered through GitOps.
Any standard module can become a governed module.
Breadth here means composability, not a wall of tiles. Three doors into the same gate:
A curated catalog
Battle-tested modules, vetted and kept current, composed the way a senior platform engineer would build them. Quality over volume: every module earns its place.
Bring your own, first-class
Your Terraform or OpenTofu modules and Helm charts, private or from the open-source commons. CozyHawk reads their variables, makes them editable, and governs them through the same gate as the catalog.
Don’t see it? Request it.
Ask for a module or a blueprint and we turn it around in 24 to 48 hours, onto the same gate and the same evidence machinery. Request a module
Inside every blueprint
Standard infrastructure as code in your Git, front to back, and leaving is always possible. See the whole story →
Want this platform, governed?
Start from the foundation blueprint, or bring the platform you already run.