Cantilever sits above the stack you already bought.
An overlay control plane, not a replacement platform. These are the systems it governs, reads and writes today — and the list is a starting point, not a ceiling.
Cloud & Kubernetes
Live inventory and inventory-driven targeting across every environment you run.
AWS
Compute, networking, storage, IAM, managed services, serverless
Microsoft Azure
Full resource discovery normalised into the unified inventory schema
Google Cloud
Cross-domain dependency correlation with the rest of the estate
Oracle Cloud (OCI)
Inventory and automation targeting across OCI tenancies
Kubernetes
OpenShift, RKE2, EKS, AKS, GKE — clusters, namespaces, workloads, ConfigMaps
Databases
Relational and managed database discovery, engine, version, tier and ownership
CI/CD & infrastructure as code
Cantilever does not replace your execution engines. It decides whether they are allowed to run.
Terraform / Terraform Cloud
Plan preview, policy checks, drift detection, state management, TFC and Terraform Enterprise
Ansible Automation Platform
Job templates for configuration, remediation and diagnostics with credential injection
GitHub Actions
workflow_dispatch with parameterised inputs; status and artifacts returned to the execution record
GitLab CI
Pipeline integration with the same governance and evidence capture
Harness
Progressive delivery and canary release management under catalog governance
Azure DevOps
Enterprise pipeline execution with change-evidence linkage
Serverless & KNative
Event-driven functions for rotation, health checks and compliance snapshots
Security & identity
Identity comes from your IdP. Secrets come from your vault. Neither is stored here.
OIDC / SAML
Enterprise identity federation; identity propagated across every connected engine
HashiCorp Vault
Dynamic, short-lived credential issuance injected at runtime
Akeyless
Secrets management integration for runtime injection
AWS KMS / Azure Key Vault / GCP KMS
Cloud-native key and secret integration per environment
OPA / Rego
Policy-as-code evaluated at every execution gate, including Terraform plan inspection
JIT & RBAC
Time-bound least-privilege roles evaluated at execution time, not cached at login
ITSM & observability
Change evidence and telemetry stitched into the same timeline as the execution itself.
ServiceNow
RITM and CMDB context injection, full change lifecycle governance, status feedback
Jira
Story, issue and sprint traceability linked to infrastructure changes
Confluence
Automated documentation updates reflecting what actually shipped
Datadog
Deploy monitors, SLO burn evaluation and event-driven remediation triggers
Splunk
Telemetry correlation for diagnostics and incident investigation
Elastic
Search and telemetry integration for the diagnostics microservice
FinOps & cost governance
Cost becomes a policy gate, not a monthly surprise. Estimated spend is evaluated before a run is approved, and every resource lands with the allocation tags finance actually needs.
Infracost
Terraform plan cost estimation surfaced before approval — reviewers see the spend delta alongside the resource diff
Budget policy gates
OPA/Rego policies that block or escalate runs exceeding a threshold, budget or forecast variance
AWS Cost Explorer & CUR
Cost and usage data correlated to the executions, owners and change records that produced it
Azure Cost Management
Subscription and resource-group cost attribution linked to execution lineage
GCP Billing & OCI Cost Analysis
Billing export integration normalised into the unified inventory schema
Apptio Cloudability & CloudHealth
Enterprise cost platforms fed with execution-linked allocation metadata
Kubecost / OpenCost
Kubernetes cost allocation by namespace, workload and team
Tag-driven allocation
The Tag Registry enforces cost-centre, owner and business-unit tags at provisioning time, making showback and chargeback possible
AI & models
The agentic layer can run on hosted models or entirely inside your boundary.
Anthropic (Claude)
Claude models for RCA narrative synthesis, intent-to-execution translation and risk explanation, invoked through the agent layer under the same policy boundary
AWS Bedrock
Model access inside your own AWS account and VPC, with Bedrock Guardrails — no inference traffic leaves your boundary
OpenAI
Hosted model integration for diagnostics, NLQ and RCA workflows
IBM watsonx
Enterprise model integration option
Private / self-hosted models
Sovereign and air-gapped deployment so no prompt or telemetry leaves your environment
MCP servers
30 servers and tools exposing inventory, execution and policy context to agents under the same RBAC
Tell us what you run.
Connector coverage expands with customer environments. If a system in your estate is not listed, it is worth a conversation — it may already be in flight.
30 minutes · tailored to your stack · no slideware