The Open Source Discovery Point showcases open-source components developed within the IPCEI-CIS ecosystem. This tool provides visibility into OSS components functionalities, repositories, licences, and architecture domains across participating initiatives, supporting interoperability, collaboration, and knowledge sharing within the European cloud-edge ecosystem.

Add your IPCEI-CIS OSS component

Network Fabric Automation provides a Kubernetes-based framework for automating network device deployment, configuration, and monitoring for IronCore opinionated underlay network stack. It currently supports Sonic Edgecore switches via the sonic-operator.
  • Device Discovery: Automatically discover network devices across the data center.
  • Provisioning: Automate the provisioning of network devices at scale.
  • Configuration Management: Manage and apply configurations across multiple devices consistently.
IronCore is a next-generation, cloud-native Infrastructure as a Service and Bare Metal Automation platform. It is a modular and scalable system designed to manage compute, networking, and storage resources efficiently across cloud and near-edge environments.
  • Cloud-Native IaaS: Provides an IaaS layer built directly on Kubernetes principles, managing virtual machines, storage, and networking using familiar Kubernetes concepts — offering a unified control plane for both containerized and traditional workloads.
  • Bare Metal Automation: Automates the entire lifecycle of physical servers, including automatic discovery, provisioning, firmware, and BIOS settings.
  • Vendor-Neutrality and Modularity: Modular, pluggable architecture avoids vendor lock-in across compute, storage, and networking layers.
  • DevOps-Ready by Design: Designed for modern DevOps workflows, providing end-to-end infrastructure and lifecycle management through a declarative API.
  • Seamless Kubernetes Integration: Native integrations with CSI (Container Storage Interface), CCM (Cloud Controller Manager), Cluster API, and Gardener.
Luigi is a micro frontend JavaScript framework for building modular, scalable, and technology-agnostic web applications with a unified user experience across distributed UI modules.
  • Modular: Monolithic web applications decompose into consistent, clearly scoped UI modules that reflect the underlying backend modularity.
  • Extensible: UI modules from external systems integrate seamlessly, and applications can be extended with additional functionality from third-party vendors in a secure way.
  • Scalable: End-to-end feature development distributes across an arbitrary number of teams, each able to independently develop, deploy, maintain, and operate their solutions.
  • Technology-Agnostic: Luigi is technology-agnostic, allowing teams to adopt new trends quickly and preventing technology lock-in as the landscape evolves.
Naira is an open-source AI Engineering Hub for discovering, governing and operating AI assets and services. It connects context across models, datasets, inference endpoints, gateways, applications, documentation and observability signals. Rather than replacing specialized systems, it makes the relationships between them visible and actionable - helping teams understand what AI capabilities exist, who owns them and how they can be used safely.
  • Unified AI Engineering Context: Connects models, datasets, endpoints, gateways, applications, documentation, observability and ownership information into one understandable hub.
  • Stand Up Against Shadow AI: Helps organizations gain visibility into AI assets and services that are otherwise spread across disconnected tools, teams and platforms.
  • Relationships, Not Just Lists: Shows how AI assets are connected, for example which model is served by which endpoint, exposed through which route and consumed by which application.
  • Governance Built Into Discovery: Makes ownership, lifecycle state, approval status, access constraints, documentation and operational signals visible close to the AI asset or service.
  • Reduce Cognitive Load: Rather than having dozens of tools handy, Naira is a single-entry point providing minimal signals and transparency across workflows and deep links where it matters.
  • Extensible and Tool-Neutral: Integrates with existing AI engineering tools through plugins instead of forcing teams into one monolithic platform.
  • From Visibility to Safe Action: Starts by making the AI landscape visible and understandable, then grows toward guided onboarding, golden paths, policy-aware access and safe operational workflows.
The Open Component Model (OCM) is an open-source, technology-agnostic model and toolset for secure software delivery. OCM provides a standard way to describe, sign, ship and deploy software components across any environment - including air-gapped and sovereign clouds - ensuring a tamper-proof, verifiable supply chain from build to deployment.
  • One standard for every artifact: Any artifact — images, Helm charts, binaries, configs — is described as a single, versioned component with a cryptographic packing list.
  • Sign once, trust everywhere: Using established algorithms like RSA and X.509 - and keyless signing via Sigstore. Location-independent signatures stay valid across registries, organizations, and air gaps, providing a verifiable Software Bill of Delivery.
  • Deliver to any environment: Software ships across public cloud, on-prem, and fully disconnected sovereign environments without breaking integrity or traceability.
  • Fits any stack: An extensible plugin model integrates with existing registries, signing services, and GitOps tooling - and OCM components serve as a shared anchor for downstream compliance tooling like Open Delivery Gear.
Open Delivery Gear (ODG) is an open-source compliance automation platform that continuously scans OCM component versions for security and compliance issues. ODG tracks findings against configurable SLAs and provides a Delivery Dashboard for platform operators and application teams - enabling trust-but-verify assurance across public and sovereign cloud environments.
  • Aggregated Component View: Provides an aggregated view of component versions and metadata from multiple sources, including vulnerabilities and licenses.
  • Technology-Agnostic Rescoring: Tooling- and technology-agnostic (semi-automated) rescoring of compliance findings across different software supply chain tools.
  • Compliance Issue Tracking: Compliance issue tracking with a fine-granular "rolling due-date barrier" for managing remediation timelines.
  • Extensible via ODG Extension Model: Extensible through the ODG Extension Model, allowing organizations to add custom compliance checks and integrations.
  • Correlated to Component IDs: All findings are correlated to OCM Component IDs, facilitating alignment of different processes and tools across software lifecycle stages.
OpenBao is an identity-based secrets and encryption management system. In addition to storing key/value data such as passwords or tokens, it can host public key infrastructures (PKIs) for issuing certificates.
  • Secure Secrets Storage: Provides secure, identity-based storage for secrets, credentials, tokens, and certificates with strong access controls.
  • HSM-Backed Encryption at Rest: Protects secrets at-rest through different seal/unseal mechanisms including HSM-backed protection for high-security environments.
  • Multi-Tenancy via Namespaces: Supports multi-tenancy through namespaces, enabling isolated secret management for different teams, applications, or customers.
OpenKCM is an open source central key chain manager for customer-owned encryption keys. It gives organizations full governance over their key hierarchy — from root keys down to data encryption keys — across cloud-native and on-premise deployments. Customers retain exclusive control over their key material, with immediate revocation across all governed workloads.
  • Customer-Owned Key Governance: Puts the customer in control of the full key hierarchy — from root keys to data encryption keys — without handing key material to any platform or vendor.
  • Unified Keystore Control Plane: Manages encryption keys across several platforms and heterogeneous infrastructure providers from a single control layer.
  • BYOK & HYOK Support: Supports Bring-Your-Own-Key and Hold-Your-Own-Key scenarios so customers retain full control over their cryptographic keys and can revoke access at any time.
  • Keychain Composition & Lifecycle Control: Composes data encryption keys into keychains and controls the key lifecycle of different keychains individually.
  • Pluggable Keystore Backends: Connects to OpenBao, AWS KMS, Azure Key Vault, GCP KMS, and HSMs — key material never leaves the customer's own keystore.
  • Compliance Ready: Ensures compliance with stringent security and privacy standards across multi-tenant cloud-native and enterprise platforms.
OpenControlPlane is a managed Infrastructure-as-Data orchestration layer, designed to streamline and automate the management of cloud resources and corresponding services using the Kubernetes Resource Model.
  • Full Cloud Landscape Orchestration: Equips teams with everything needed to orchestrate their cloud landscapes — from application to account and infrastructure management — using the control plane pattern.
  • Declarative Resource API: All resources in the cloud-edge continuum are accessible and managed via a declarative API based on the Kubernetes Resource Model, with corresponding controllers and operators.
  • Centralized Infra-as-Data Capabilities: Enables organizations to centrally offer Infrastructure-as-Data capabilities, leveraging open-source providers like Crossplane, Flux, External Secrets Operator, and OCM.
  • GitOps at the Edge: Together with declarative deployment orchestrators, consumers implement automated, GitOps-driven deployment workflows at the edges.
  • Release Train Subscription: Consumers subscribe to a product release-train from software producers, enabling continuous and controlled delivery across distributed environments.
  • Custom Platform Builder: Allows larger organizations to pre-configure control planes tailored to their needs and grow their own internal developer platform.
  • Managed Control Planes as a Service: Allows any company to offer managed control planes to their engineers, reducing platform complexity for individual teams.