Platform

Capabilities

VIN is a self-hosted operations control plane for teams that run clouds, clusters, and hosts — and need one place to discover assets, observe health, act with automation, and govern who can do what.

Instead of stitching inventory spreadsheets, FinOps tools, kube dashboards, script runners, and ticket queues, VIN puts day-2 ops behind one login, one RBAC model, optional org-wide 2FA, environments, Approvals, and a shared audit trail. Workloads stay on your infrastructure; the portal only issues licenses and validates licenses online.

Eleven pillars — listed separately

Cloud Hub · Assets · FinOps · Automation · Kubernetes · MCP · Security & Incidents · Backup & Restore · Monitoring & Observability · Access & Governance. Each section below stands alone so you can map capabilities to Community, Professional, or Enterprise.

vin.local/dashboard
VIN/Dashboard
A
128
Total Hosts
124
Online
12
Active SSH
4/4
Clouds
18/22
Integrations
36
Scripts
14
Playbooks

Explore

Observability
Agentless host metrics + Prometheus
Host Posture
CIS / PCI scans
Artifact Scan
Trivy image & K8s CVEs
Runtime Guard
Falco live threat detection
VIN DAST
OWASP ZAP web/API scans
Cloud Hub
Credentials & consoles
Cloud Assets
Inventory & topology
FinOps
Cost intelligence
Kubernetes
Install, backup, cost, fleet
Backup & Restore
Servers, DB & K8s workloads
Scripts
Run shell scripts
SSH Manager
Remote terminals
Ansible
Playbooks
Terraform
IaC workspaces
Automation Hub
Schedules & tools
Inventory
Hosts & instances
Users
RBAC & approvals

Integrations

Open Automation Hub
n8connected
Jeconnected
Vaconfigured
Prconnected
Grconnected
Soconfigured
Giconnected
Spoff
Arconnected
Daoff

Clouds

Manage
AWS
configured
OCI
configured
Azure
configured
GCP
not set

This Server

vin-host-01 · up 42d
CPU38%
Memory · 9.8/16 GB61%
Disk / · 148/200 GB74%

Recent Activity

cis.scandb-prod-012m ago
ansible.runweb-fleet9m ago
ssh.sessioncache-0114m ago
report.emailmanagement1h ago
script.runworker-072h ago

Regions

us-easteu-westme-central

Quick Actions

▶ harden-ssh.sh
⚙ patch-web-fleet

Cloud Hub

One console for every cloud

Cloud Hub is the credential and jump-off surface for AWS, Azure, GCP, and Oracle Cloud. Operators store encrypted credentials once, scoped to their user and environment, then open the right provider console without sharing long-lived keys in chat or spreadsheets. The goal is fewer shadow credentials and a clear path from VIN into native tooling when you need depth.

  • Per-user encrypted credentials for four clouds
  • Jump to each provider console from VIN
  • Environment-scoped vault isolation
  • Online-licensed, self-hosted control plane
Per-user encrypted credentials for four clouds
Jump to each provider console from VIN
Environment-scoped vault isolation
Online-licensed, self-hosted control plane

Cloud Assets

See every resource, and how it connects

Cloud Assets turns multi-cloud sprawl into a single inventory: compute, storage, networking, and related resources across accounts and projects. Topology and drift views help you see how things connect and when reality diverges from expected tags or configuration — so asset truth lives in the console, not in a weekly export.

  • Cross-cloud inventory in one table
  • Interactive topology graph
  • Drift and tag coverage views
  • Filter and export anytime
Cross-cloud inventory in one table
Interactive topology graph
Drift and tag coverage views
Filter and export anytime

FinOps

Spend you can explain

FinOps brings month-to-date spend, forecasts, budgets, rightsizing, and idle savings into the same place you already operate infrastructure. Budget breaches can surface as Incidents; scheduled Reports and Mail deliver board-ready summaries without a separate BI pipeline.

  • Spend, forecasts and budget alerts
  • Rightsizing and idle-resource savings
  • Tag allocation coverage
  • Scheduled Reports with Mail & SMTP
vin.local/finops
VIN/FinOps
A
$48.2k
Monthly spend
-4.1%
MoM change
$6.4k
Savings found

Spend by cloud

AWS62%
Azure21%
GCP12%
OCI5%

Top recommendations

Rightsize 12 idle EC2$2.9k/mo
Delete 340 orphan disks$1.6k/mo
Buy savings plan$1.2k/mo
Schedule dev shutdown$0.7k/mo

Automation Hub

Run the boring stuff on a schedule

Automation Hub is where scripts, Ansible, Terraform, and connected DevOps tools run under VIN identity. Deploy or link tools your team already uses, watch live output, schedule unattended jobs, and keep full execution history — so routine ops is repeatable and auditable, not a private laptop ritual.

  • One-click deploy or connect existing tools
  • Ansible, scripts and Terraform runners
  • Cron for jobs, scans and reports
  • Full execution history and logs
vin.local/automation
VIN/Automation Hub
A

Upcoming schedules

cronNightly CIS scanin 2h
ansiblePatch web-fleetin 6h
reportWeekly cost reportMon 08:00
terraformTerraform drift checkin 12h

Recent runs

playbook: harden-sshsuccess42s
script: rotate-keyssuccess8s
playbook: patch-allrunning1m 12s
terraform: apply vpcfailed23s

Kubernetes

Build, run, back up, and cost clusters end to end

The Kubernetes surface covers the full cluster lifecycle: guided RKE2 install with preflight checks, a multi-cluster workload browser with live logs and in-pod exec, one-click addon installs, node/pool efficiency and rightsizing, a live fleet health board, and Velero-backed namespace/PVC backup and restore. Cluster-wide cost breakdowns (powered by OpenCost) sit next to FinOps so Kubernetes spend is never a separate spreadsheet.

  • Guided RKE2 install with preflight checks
  • Multi-cluster workloads, live logs and in-pod exec
  • One-click addon installs and fleet health board
  • Velero-backed namespace/PVC backup & restore
  • Node/pool efficiency, rightsizing and OpenCost breakdowns
  • Signals can raise Incidents
Guided RKE2 install with preflight checks
Multi-cluster workloads, live logs and in-pod exec
One-click addon installs and fleet health board
Velero-backed namespace/PVC backup & restore
Node/pool efficiency, rightsizing and OpenCost breakdowns
Signals can raise Incidents

AI & MCP

Let assistants operate VIN safely

VIN exposes a self-hosted MCP endpoint with curated tools and prompts so AI assistants can investigate and act inside your environment. Assistants inherit your auth and RBAC; destructive or high-risk writes can sit in Approvals until a human clears them — so automation stays governed.

  • Governed, self-hosted MCP server
  • Curated prompts and read/write tools
  • Same auth + RBAC as the REST API
  • Approvals queue for destructive actions
Governed, self-hosted MCP server
Curated prompts and read/write tools
Same auth + RBAC as the REST API
Approvals queue for destructive actions

Security & Incidents

Find risk, prove it, then respond

Security starts with agentless CIS and compliance scans over SSH that land in Findings for severity triage. VIN Artifact Scan (Trivy) covers container images, filesystems, and Kubernetes workloads for CVEs and misconfig; VIN DAST (OWASP ZAP) runs baseline, full, and API scans against live URLs; VIN Runtime Guard (Falco) watches syscalls and container behavior for live threats. Alert rules route any signal, and Incidents is the shared response queue: ack, assign, annotate, and resolve drift, budget breaches, Kubernetes signals, and every scanner's findings in one place.

  • CIS / compliance scans over SSH
  • VIN Artifact Scan — Trivy image, filesystem & K8s scanning
  • VIN DAST — OWASP ZAP baseline/full/API scans with scheduling
  • VIN Runtime Guard — Falco live syscall & container threat detection
  • Configurable alert rules and suppressions
  • Incidents: ack, assign, annotate, resolve
vin.local/security/findings
VIN/Security — Findings & Incidents
A
72%
Compliance
128
Hosts scanned
+64
Fixed this week

Findings inbox · CIS · Artifact Scan · DAST · Runtime Guard

Export report
CriticalSSH permits root logindb-prod-01CIS
CriticalCVE-2024-3094 in liblzma5web-fleet:nginxTrivy
HighReflected XSS on /searchapp.example.comZAP
HighShell spawned in containercache-01Falco
HighUFW firewall inactivecache-01CIS
MediumAuditd not enabledworker-07CIS

Backup & Restore

Encrypted, scheduled, restorable — servers to clusters

Backup & Restore covers three layers from one console: VIN's own config as a passphrase-encrypted .vinbak archive, server/database backup jobs with pluggable storage destinations, and Kubernetes workload backup via Velero (namespaces, PVCs, cluster resources) with point-in-time restore. Run logs, retention policies, and restore history are all in the same audit trail as the rest of VIN.

  • VIN config backup as encrypted .vinbak archives
  • Scheduled server & database backup jobs
  • Pluggable storage destinations (local, S3-compatible, cloud)
  • Velero-backed Kubernetes namespace/PVC backup & restore
  • Retention policies and restore run history
VIN config backup as encrypted .vinbak archives
Scheduled server & database backup jobs
Pluggable storage destinations (local, S3-compatible, cloud)
Velero-backed Kubernetes namespace/PVC backup & restore
Retention policies and restore run history

Monitoring & Observability

See the whole fleet at a glance

Monitoring pulls agentless host metrics over SSH — CPU, memory, disk, processes, and ports — into dashboards that work for engineers and managers. Observability layers in a Prometheus-backed metrics agent for deeper trend analysis and alerting on hosts and clusters. Platform Health and VIN Status keep the control plane itself visible; fleet health can feed scheduled reports.

  • Host health without agents
  • Live resource metrics and detail drawers
  • Prometheus-backed metrics agent and trend charts
  • VIN Status and platform Health checks
  • Fleet health reports on a schedule
vin.local/observability
VIN/Observability
A
126/128
Hosts healthy
38%
Avg CPU
3
Alerts

Requests / sec

web-01 logs

200 GET /api/health 3ms
200 POST /api/scan 41ms
429 rate-limited 8.8.8.8
200 GET /metrics 2ms

This Server

CPU38%
Memory · 9.8/16 GB61%
Disk / · 148/200 GB74%

Access & Governance

Team isolation with an audit trail

Access & Governance is how VIN scales beyond a single admin: environments isolate teams, Approvals gate high-risk MCP writes, Notifications reach Slack/email/webhooks, Mail & SMTP power Reports, and Audit plus passphrase-encrypted Backup (.vinbak) keep a durable trail. Enterprise adds single sign-on (OIDC) and SCIM-based user provisioning for centralized identity. RBAC scopes and optional org-wide forced 2FA close the loop. Secrets can stay local (Fernet) or move into VIN's built-in HashiCorp Vault.

  • Environments (Pro: 3 · Enterprise: unlimited)
  • Approvals for high-risk MCP writes
  • Notifications to Slack, email and webhooks
  • Mail & SMTP, Audit export, encrypted Backup (.vinbak)
  • Single sign-on (OIDC) & SCIM provisioning — Enterprise
  • Built-in Vault for SSH keys & cloud secrets (optional)
  • RBAC scopes and optional org-wide forced 2FA
Environments (Pro: 3 · Enterprise: unlimited)
Approvals for high-risk MCP writes
Notifications to Slack, email and webhooks
Mail & SMTP, Audit export, encrypted Backup (.vinbak)
Single sign-on (OIDC) & SCIM provisioning — Enterprise
Built-in Vault for SSH keys & cloud secrets (optional)
RBAC scopes and optional org-wide forced 2FA

Integrations

Works with your stack

Official brand marks for the clouds, clusters, CI, observability, and secret stores VIN connects from the console — under the same identity and audit model.

AWS
Azure
GCP
Oracle Cloud
Kubernetes
Docker
Terraform
Ansible
Prometheus
Grafana
Splunk
New Relic

Deploy on your infrastructure

Start free with Community — install on Windows or Linux, activate online, and keep host metrics, credentials, and audit history on your network.