Platform
Capabilities
VIN is a self-hosted operations control plane for teams that run clouds, clusters, and hosts — and need one place to discover assets, observe health, act with automation, and govern who can do what.
Instead of stitching inventory spreadsheets, FinOps tools, kube dashboards, script runners, and ticket queues, VIN puts day-2 ops behind one login, one RBAC model, optional org-wide 2FA, environments, Approvals, and a shared audit trail. Workloads stay on your infrastructure; the portal only issues licenses and validates licenses online.
Eleven pillars — listed separately
Cloud Hub · Assets · FinOps · Automation · Kubernetes · MCP · Security & Incidents · Backup & Restore · Monitoring & Observability · Access & Governance. Each section below stands alone so you can map capabilities to Community, Professional, or Enterprise.
Explore
Integrations
Open Automation Hub →Clouds
Manage →This Server
Recent Activity
Regions
Quick Actions
Cloud Hub
One console for every cloud
Cloud Hub is the credential and jump-off surface for AWS, Azure, GCP, and Oracle Cloud. Operators store encrypted credentials once, scoped to their user and environment, then open the right provider console without sharing long-lived keys in chat or spreadsheets. The goal is fewer shadow credentials and a clear path from VIN into native tooling when you need depth.
- Per-user encrypted credentials for four clouds
- Jump to each provider console from VIN
- Environment-scoped vault isolation
- Online-licensed, self-hosted control plane
Cloud Assets
See every resource, and how it connects
Cloud Assets turns multi-cloud sprawl into a single inventory: compute, storage, networking, and related resources across accounts and projects. Topology and drift views help you see how things connect and when reality diverges from expected tags or configuration — so asset truth lives in the console, not in a weekly export.
- Cross-cloud inventory in one table
- Interactive topology graph
- Drift and tag coverage views
- Filter and export anytime
FinOps
Spend you can explain
FinOps brings month-to-date spend, forecasts, budgets, rightsizing, and idle savings into the same place you already operate infrastructure. Budget breaches can surface as Incidents; scheduled Reports and Mail deliver board-ready summaries without a separate BI pipeline.
- Spend, forecasts and budget alerts
- Rightsizing and idle-resource savings
- Tag allocation coverage
- Scheduled Reports with Mail & SMTP
Spend by cloud
Top recommendations
Automation Hub
Run the boring stuff on a schedule
Automation Hub is where scripts, Ansible, Terraform, and connected DevOps tools run under VIN identity. Deploy or link tools your team already uses, watch live output, schedule unattended jobs, and keep full execution history — so routine ops is repeatable and auditable, not a private laptop ritual.
- One-click deploy or connect existing tools
- Ansible, scripts and Terraform runners
- Cron for jobs, scans and reports
- Full execution history and logs
Upcoming schedules
Recent runs
Kubernetes
Build, run, back up, and cost clusters end to end
The Kubernetes surface covers the full cluster lifecycle: guided RKE2 install with preflight checks, a multi-cluster workload browser with live logs and in-pod exec, one-click addon installs, node/pool efficiency and rightsizing, a live fleet health board, and Velero-backed namespace/PVC backup and restore. Cluster-wide cost breakdowns (powered by OpenCost) sit next to FinOps so Kubernetes spend is never a separate spreadsheet.
- Guided RKE2 install with preflight checks
- Multi-cluster workloads, live logs and in-pod exec
- One-click addon installs and fleet health board
- Velero-backed namespace/PVC backup & restore
- Node/pool efficiency, rightsizing and OpenCost breakdowns
- Signals can raise Incidents
AI & MCP
Let assistants operate VIN safely
VIN exposes a self-hosted MCP endpoint with curated tools and prompts so AI assistants can investigate and act inside your environment. Assistants inherit your auth and RBAC; destructive or high-risk writes can sit in Approvals until a human clears them — so automation stays governed.
- Governed, self-hosted MCP server
- Curated prompts and read/write tools
- Same auth + RBAC as the REST API
- Approvals queue for destructive actions
Security & Incidents
Find risk, prove it, then respond
Security starts with agentless CIS and compliance scans over SSH that land in Findings for severity triage. VIN Artifact Scan (Trivy) covers container images, filesystems, and Kubernetes workloads for CVEs and misconfig; VIN DAST (OWASP ZAP) runs baseline, full, and API scans against live URLs; VIN Runtime Guard (Falco) watches syscalls and container behavior for live threats. Alert rules route any signal, and Incidents is the shared response queue: ack, assign, annotate, and resolve drift, budget breaches, Kubernetes signals, and every scanner's findings in one place.
- CIS / compliance scans over SSH
- VIN Artifact Scan — Trivy image, filesystem & K8s scanning
- VIN DAST — OWASP ZAP baseline/full/API scans with scheduling
- VIN Runtime Guard — Falco live syscall & container threat detection
- Configurable alert rules and suppressions
- Incidents: ack, assign, annotate, resolve
Findings inbox · CIS · Artifact Scan · DAST · Runtime Guard
Export report →Backup & Restore
Encrypted, scheduled, restorable — servers to clusters
Backup & Restore covers three layers from one console: VIN's own config as a passphrase-encrypted .vinbak archive, server/database backup jobs with pluggable storage destinations, and Kubernetes workload backup via Velero (namespaces, PVCs, cluster resources) with point-in-time restore. Run logs, retention policies, and restore history are all in the same audit trail as the rest of VIN.
- VIN config backup as encrypted .vinbak archives
- Scheduled server & database backup jobs
- Pluggable storage destinations (local, S3-compatible, cloud)
- Velero-backed Kubernetes namespace/PVC backup & restore
- Retention policies and restore run history
Monitoring & Observability
See the whole fleet at a glance
Monitoring pulls agentless host metrics over SSH — CPU, memory, disk, processes, and ports — into dashboards that work for engineers and managers. Observability layers in a Prometheus-backed metrics agent for deeper trend analysis and alerting on hosts and clusters. Platform Health and VIN Status keep the control plane itself visible; fleet health can feed scheduled reports.
- Host health without agents
- Live resource metrics and detail drawers
- Prometheus-backed metrics agent and trend charts
- VIN Status and platform Health checks
- Fleet health reports on a schedule
Requests / sec
web-01 logs
This Server
Access & Governance
Team isolation with an audit trail
Access & Governance is how VIN scales beyond a single admin: environments isolate teams, Approvals gate high-risk MCP writes, Notifications reach Slack/email/webhooks, Mail & SMTP power Reports, and Audit plus passphrase-encrypted Backup (.vinbak) keep a durable trail. Enterprise adds single sign-on (OIDC) and SCIM-based user provisioning for centralized identity. RBAC scopes and optional org-wide forced 2FA close the loop. Secrets can stay local (Fernet) or move into VIN's built-in HashiCorp Vault.
- Environments (Pro: 3 · Enterprise: unlimited)
- Approvals for high-risk MCP writes
- Notifications to Slack, email and webhooks
- Mail & SMTP, Audit export, encrypted Backup (.vinbak)
- Single sign-on (OIDC) & SCIM provisioning — Enterprise
- Built-in Vault for SSH keys & cloud secrets (optional)
- RBAC scopes and optional org-wide forced 2FA
Integrations
Works with your stack
Official brand marks for the clouds, clusters, CI, observability, and secret stores VIN connects from the console — under the same identity and audit model.
Deploy on your infrastructure
Start free with Community — install on Windows or Linux, activate online, and keep host metrics, credentials, and audit history on your network.