An agentic DevOps harness

Deploy with an AI that never sees your secrets.

VibeOps reads your repo, plans a deploy for every service in it, and runs it on your machine and your accounts. Credentials go from your keyboard straight to the command, never through the model.

Status
Beta
Platform
macOS and Windows
Source
Open, on GitHub
Runs on
Your machine
Deploys to
Your accounts
Fig. 01 One prompt, from a cold repo to a live domain.
01

How it works

Three steps, and you are present for all of them. Nothing about this is autonomous.

  1. Step 01

    Point it at a repo

    It reads every service in the project, not just the one at the root, and works out what each of them actually needs to run.

  2. Step 02

    Read the plan

    Every step arrives tagged SAFE, CAUTION or DESTRUCTIVE, with the exact command it intends to run. Looking around, it does freely.

  3. Step 03

    Approve once

    It runs the commands on your machine, against your own accounts, in an order that respects what depends on what, and stops the moment something fails a health check.

02

The secret boundary

Pasting a database URL into a chat box publishes it: what you share can persist somewhere you don't control. VibeOps is built so the AI can do the work without ever holding your password.

You typed

postgres://linkboard:s3cr3t@ep-cool-dust.eu-central-1.aws.neon.tech/main

Typed into a native dialog, kept in your OS keychain, and filled in only at the moment it's needed.

What the AI ever sees

$SECRET_DATABASE_URL

The AI is told only that the secret now exists. It writes the placeholder wherever the value belongs, and never resolves it.

Scrubbed on the way back, too

Protecting the input alone is theater. Deploy output leaks just as readily. Every saved value is stripped from each result before the AI is allowed to read it.

14:22:01 $ printenv DATABASE_URL
14:22:02 [redacted by VibeOps]
14:22:03 release v14 · api · healthy
03

One prompt ships every service

Your frontend, your API, your background jobs and your database rarely belong on the same cloud. Say what you want once. VibeOps figures out where each piece lives and ships them in the right order.

How VibeOps routed the four services in one example repository
Service Runtime Target Reasoning
web/ Next.js Vercel Framework-native build, deployed after the API it calls
api/ Go Fly VM Shells out to ffmpeg. Workers has no subprocesses, so it can't work there with any amount of config
worker/ TypeScript Cloudflare Scheduled, no filesystem, no long-running state
db Postgres Neon Managed, with a branch per environment

4 services → 3 providers Ordered so api/ ships before the frontend that needs its URL.

04

Bring the AI you already pay for

No new subscription to learn. VibeOps pairs with the AI you already use and trust, and it arrives knowing how to ship.

  • Claude logo Claude Your subscription
  • Openrouter logo OpenRouter Your key, any model
  • Cursor logo Cursor Your subscription
  • Opencode logo Opencode Your subscription
05

Connect your clouds. Keep the keys.

Your frontend on Vercel, your API on AWS, your data on Atlas. Connect the clouds you already use in a click, and VibeOps ships to all of them from one conversation, with the same guardrails on every one.

  • Vercel logo Vercel Frontends, previews, domains
  • Cloudflare logo Cloudflare Edge apps and storage
  • Neon logo Neon Serverless Postgres
  • Supabase logo Supabase Postgres, auth, functions
  • AWS logo AWS Containers, functions, databases
  • Azure logo Azure Web apps and containers
  • Google Cloud logo Google Cloud Containers and databases
  • MongoDB logo MongoDB Atlas Managed MongoDB

Powerful enough to ship. Never enough to surprise you.

An AI with your cloud login can do anything your account can. VibeOps makes sure it only does what you say yes to.

  1. Guard 01

    Nothing runs without your yes

    Every action is shown to you before it happens. Approve it, approve the whole plan, or say no and tell it why. No clever prompt talks its way past this.

  2. Guard 02

    Walled off from what matters

    The agent works in a locked room on your machine. Your SSH keys, saved passwords and browser stay out of reach, and each cloud stays closed until you connect it.

  3. Guard 03

    Secrets never enter the chat

    API keys and database passwords go straight to where they belong. The AI only ever sees a placeholder, and anything that slips into the output is wiped before it reads it.

Not on the list? Your own servers and anything else you deploy to work too, behind the same three guardrails.

06

Before you install

What do I need to get started?
The app and a project to ship. Connect the AI you already use (Claude, Cursor, opencode, or any model via OpenRouter), point it at your code and say what you want.
Which cloud providers and infrastructure platforms does VibeOps support?
Vercel, Cloudflare, Neon, Supabase, AWS, Azure, Google Cloud and MongoDB Atlas connect in a click from Settings. Beyond those, any server you own, on Hetzner, Oracle or anywhere else, over plain SSH.
Do I need to know DevOps?
No. Describe what you want in plain English; VibeOps scans the project, writes the plan, and shows you the exact commands before it runs a single one.
Can VibeOps deploy to self-hosted servers?
Yes, and it's a first-class target. If you own it and it takes an SSH key, VibeOps can deploy to it, check on it and fix it like any managed provider. No agent installed, no account linked.
Does it run without me watching?
No, and that's deliberate. Anything that changes a server stops for your approval first. Looking around, it does freely.
Is it open source?
Yes. The full source is on GitHub, so you can read exactly what it does with your machine and your secrets, or build it yourself. It's under the FSL license, which turns into MIT two years after each release.
How finished is this?
It's in beta. The secret handling, the planner and the approval gates all work today, but expect rough edges and expect things to change between builds. Try it on a side project before you point it at anything you'd hate to break.
What does the Windows build need?
WSL. VibeOps runs its work inside your WSL distro, so you need WSL installed with bubblewrap (bwrap) inside it for the sandbox. If Claude is your chosen AI, sign into it inside WSL too. The sign-in on Windows itself won't be picked up. Connecting AWS, Azure, Google Cloud or Atlas asks you to paste one setup command into WSL; VibeOps gives it to you.
How do I install this?
Unzip the contents from the zip file -> Try to open the app -> Go to Privacy & Security settings -> Allow 'Open Anyway' for the VibeOps request