Skip to main content
Open source · Kubernetes-native IDP

All-in-one developer platform,
in a single command.

Shoulders turns Kubernetes into a self-service Internal Developer Platform: apps, databases, Kafka, observability, security and GitOps — composed from best-in-class open source, ready after shoulders up.

20+
integrated open-source components
5
developer-facing APIs (XRDs)
3
interfaces: CLI · portal · MCP
1
command to a running platform
terminal — zsh
$ brew install jherreros/tap/shoulders
$ shoulders up
✓ vind cluster “shoulders” ready (control-plane + 2 workers)
✓ FluxCD bootstrapped — 24 HelmReleases reconciled
✓ Crossplane XRDs established — platform API live
$ shoulders workspace create team-a
$ shoulders app init checkout --image my-registry/checkout:v2
✓ checkout.team-a live at https://checkout.example.com

Standing on the shoulders of giants

CrossplaneFluxCDCiliumGateway APIStrimzi KafkaCloudNativePGPrometheusGrafanaLokiTempoKyvernoTrivyFalcoDexHeadlampGarage S3

Why Shoulders exists

Platform engineering is expensive

Every company re-builds the same stack: clusters, networking, databases, Kafka, monitoring, security policies, developer portals. Months of undifferentiated work — and developers still wait on tickets to ship.

A reference platform, ready to run

Shoulders packages those decisions into an opinionated, production-shaped platform: Crossplane APIs for developers, FluxCD reconciliation for operators, and small/medium/large profiles plus airgap support for real-world constraints.

What teams get

Everything around the app, included

Self-service in seconds

Developers ship WebApplications, workers, jobs and cronjobs from one declarative API — no YAML archaeology, no tickets to platform teams.

Data & streaming included

PostgreSQL, Redis, S3-compatible buckets and full Kafka clusters provisioned with the same workflow as the app itself.

Observability from day zero

Metrics, logs and traces wired automatically through Prometheus, Loki, Tempo and Grafana. Every app is born observable.

Secure & compliant by default

Network policies, admission guardrails, vulnerability scanning and runtime threat detection — auditable in one reporter UI.

GitOps under the hood

The entire platform reconciles from git via FluxCD — with OCI snapshots for dirty-tree iteration and airgap bundles for offline installs.

AI-native operations

An MCP server exposes the whole platform to AI assistants, plus a Headlamp portal for humans and a CLI for automation.

How it works

From zero to developer self-service in three steps

01

Boot the platform

One command creates the cluster and installs 20+ components via GitOps — networking, identity, data, observability, security.

shoulders up
02

Give teams a workspace

Isolated namespaces with network policy and naming guardrails. Developers self-serve from there — no cluster-admin required.

shoulders workspace create team-a
shoulders app init checkout --image my-registry/checkout:v2
03

Observe everything

Dashboards, logs, traces and compliance reports are already wired. Open Grafana or the portal and start operating.

shoulders dashboard
shoulders portal

Fits your constraints

One platform, three footprints

Small

Laptops & small clusters

Core IDP, Prometheus + Grafana, Dex, Headlamp, PostgreSQL, S3. No event streams, no heavy scanners.

Default

Medium

The full local platform

Adds Kafka, Loki/Tempo/Alloy, Trivy, Falco and Policy Reporter on 2 workers.

Large

Maximum headroom

Full feature set on 3 workers with longer Prometheus retention.

Plus OCI snapshot iteration for contributors and single-file airgap bundles — profiles guide · airgap · local loop

“If I have seen further it is by standing on the shoulders of Giants.”— Isaac Newton, and the reason this platform is called Shoulders

Your platform is one command away.

Open source (MIT). Runs on your laptop today, on your cluster tomorrow.