Multi-cloud honesty
Service coverage
Every individual service across Azure, AWS, GCP, Kubernetes, identity systems, and hybrid connectivity — with a fully / partially / planned / not-supported grade per capability. We do not pretend coverage we haven't built. See the guide.
- ○Active Directory Federation Services (ADFS)identity.adfs· identityPlannedSupported: observabilityDiscovery: Read Entra federation settings (we infer ADFS presence from external federation config). Auth: n/a — read Entra side only. Reads: Federation trust metadata, claim mappings.
- ○Active Directory (on-prem)identity.active_directory· identityPlannedSupported: observabilityDiscovery: Azure AD Connect sync state via Entra; on-prem LDAP optional via agent. Auth: Read sync state from Entra; on-prem agent for direct read. Reads: Hybrid join state, sync errors, stale objects (via Entra sync metrics).
- ○LDAP / OpenLDAPidentity.ldap· identityPlannedSupported: observabilityDiscovery: LDAP bind (on-prem connector or jump host). Auth: Bind DN + service-account password. Reads: OU tree, user/group attributes.
- ✕ExpressRoute (Azure)hybrid.azure.expressroute· hybridNot in scopeSupported: discovery · inventory · topology · networkAzure side discovered via Resource Graph; hybridConnectivity playbook validates the chain. On-prem peer + carrier device not visible.
- ✕VPN Gateway (Azure)hybrid.azure.vpngateway· hybridNot in scopeSupported: discovery · inventory · topology · networkAzure side discovered. On-prem peer requires CMDB or agent.
- ✕Direct Connect (AWS)hybrid.aws.directconnect· hybridNot in scopeSupported: discovery · inventory · topology · networkAWS side enumerable via aiobotocore. On-prem peer not visible.
- ✕Site-to-Site VPN (AWS)hybrid.aws.sitevpn· hybridNot in scopeSupported: discovery · inventory · topology · networkTunnel state visible AWS-side.
- ✕Cloud Interconnect (GCP)hybrid.gcp.interconnect· hybridNot in scopeSupported: discovery · inventory · topology · networkGCP side enumerable via google-cloud-resource-manager.
- ✕Cloud VPN (GCP)hybrid.gcp.cloudvpn· hybridNot in scopeSupported: discovery · inventory · topology · networkGCP side enumerable.
- ✕Hybrid DNS resolutionhybrid.dns.resolver· hybridNot in scopeSupported: discovery · inventory · topology · networkPrivate DNS Zones (Azure/AWS/GCP) plus conditional forwarders. Resolution chain validated end-to-end by privateEndpointImpact playbook for Azure only.
- ✕Identity federationhybrid.identity.federation· hybridNot in scopeSupported: discovery · inventory · topology · networkEntra ↔ ADFS / Entra ↔ Okta / Entra ↔ Ping. Discovery requires reading Entra federation settings + the peer IdP via its API.
- ✕ServiceNow CMDBhybrid.cmdb.servicenow· hybridNot in scopeSupported: discovery · inventory · topology · networkBusiness services from cmdb_ci_service ingested. Reconciliation against live cloud inventory is roadmap.
- ✕Webhook integration bridgehybrid.webhook.bridge· hybridNot in scopeSupported: discovery · inventory · topology · networkOutbound webhooks fire on recommendation status changes. Inbound webhooks (receiving from external systems) are roadmap.
Read-only and advisory by design — we never modify cloud resources. The grades describe what we can observe, not what we can change.