Factory Builder

Build Your Container

One hardened baseline image. 100 toggleable add-ons. Zero Critical or High CVEs — guaranteed on every weekly rebuild. Select your OS, enable the tools you need, and deploy.

Your configuration
$0/mo
0 add-ons × $9/mo
Preview image name
registry.opencentric.ai/baseline:wolfi
Zero Critical / High CVEs guaranteed
Base OS
Cloud Infrastructure

Select a cloud to unlock Terraform templates for each add-on that supports it. $79 one-time per template.

Trivy CVE Scanner

Weekly automated Trivy scans across all OS packages and application dependencies.

Cosign Image Signing

Every build is signed with Cosign — verify authenticity before any pull.

Syft SBOM Generator

CycloneDX and SPDX bill of materials generated automatically on each rebuild.

Falco Runtime Security

Real-time kernel-level threat detection for running containers.

OPA Policy Engine

Open Policy Agent enforces admission and runtime policies as code.

HashiCorp Vault

Secrets management, dynamic credentials, and encryption-as-a-service.

cert-manager TLS

Automatic TLS certificate provisioning and renewal via Let's Encrypt or custom CA.

Kyverno Policy Controller

Kubernetes-native policy engine for validating and mutating resources.

Anchore Grype Scanner

Vulnerability scanning for container images and filesystems using Grype's database.

CIS Benchmark Hardening

CIS Level 1 & 2 hardening profiles applied at build time.

AppArmor / seccomp

Mandatory access control profiles for reduced syscall attack surface.

Network Policy Enforcement

Default-deny network policies to isolate workloads by namespace.

Pod Security Standards

Kubernetes PSS restricted profile — no privileged containers, no host PID.

SOPS Encrypted Secrets

Mozilla SOPS for encrypting secrets in Git with KMS, PGP, or age.

Notary v2 Image Trust

OCI-native image signing and verification with Notation CLI.

Prometheus Metrics

Open-source monitoring with a powerful query language (PromQL).

Grafana Dashboards

Visualization dashboards for metrics, logs, and traces from any source.

Loki Log Aggregation

Horizontally scalable log aggregation built for Kubernetes.

Tempo Distributed Tracing

High-scale distributed tracing backend, natively integrated with Grafana.

OpenTelemetry Collector

Vendor-agnostic telemetry pipeline for metrics, logs, and traces.

Jaeger Tracing

End-to-end distributed tracing for microservices with Jaeger backend.

Alertmanager

Handles alerts from Prometheus with routing, grouping, and silencing.

PagerDuty Integration

Forward critical alerts directly to PagerDuty on-call rotations.

New Relic Agent

New Relic APM agent for full-stack performance visibility.

Datadog Agent

Datadog infrastructure and APM agent with auto-discovery.

Fluent Bit Log Forwarder

Lightweight log processor and forwarder for Kubernetes environments.

Vector Telemetry Pipeline

High-performance observability data pipeline for logs, metrics, and events.

Redis Cache

In-memory data structure store used as cache, session store, and pub/sub.

PostgreSQL

Advanced open-source relational database with full ACID compliance.

MongoDB

Document-oriented NoSQL database for flexible, schema-less storage.

MySQL 8

Widely deployed open-source RDBMS with strong replication support.

Apache Kafka

Distributed event streaming platform for high-throughput pipelines.

Elasticsearch

Distributed search and analytics engine for structured and unstructured data.

MinIO Object Storage

S3-compatible object storage for on-prem or air-gapped deployments.

ClickHouse Analytics DB

Column-oriented OLAP database for real-time analytics at petabyte scale.

RabbitMQ

Message broker with support for multiple messaging protocols.

Debezium CDC

Change data capture for streaming database changes to Kafka.

NATS Messaging

Cloud-native messaging system for microservices, IoT, and edge computing.

etcd Key-Value Store

Distributed reliable key-value store used by Kubernetes control plane.

NGINX Ingress

Production-grade Kubernetes ingress controller with load balancing.

Traefik Proxy

Edge router with native Kubernetes integration and automatic TLS.

Istio Service Mesh

Full-featured service mesh with mTLS, traffic management, and telemetry.

Linkerd Service Mesh

Ultralight service mesh focused on simplicity, security, and observability.

Envoy Proxy

High-performance L7 proxy and communication bus for large service meshes.

CoreDNS

Flexible, extensible DNS server used as the Kubernetes cluster DNS.

MetalLB Load Balancer

Bare-metal load-balancer implementation for Kubernetes clusters.

Cilium eBPF Networking

eBPF-based networking, observability, and security for Kubernetes.

Argo CD GitOps

Declarative GitOps continuous delivery for Kubernetes.

Tekton Pipelines

Cloud-native CI/CD pipelines running directly in Kubernetes.

Jenkins

Extensible open-source automation server for CI/CD pipelines.

GitLab Runner

Run GitLab CI/CD jobs inside your container environment.

BuildKit (Dockerfile)

Next-generation Docker image builder with cache mounts and secrets.

Kaniko Image Builder

Build container images inside Kubernetes without a Docker daemon.

Skaffold Dev Loop

Fast inner-loop development with automatic build, push, and deploy.

Helm Package Manager

The Kubernetes package manager for defining, installing, and upgrading applications.

Kustomize

Kubernetes native configuration management without templates.

Earthly Build

Repeatable builds combining Dockerfile and Makefile syntax.

PyTorch

Open-source machine learning framework with GPU acceleration support.

TensorFlow Serving

Flexible, high-performance serving system for ML models.

Ray Distributed ML

Distributed computing framework for scaling AI and Python workloads.

MLflow Tracking

Platform for the ML lifecycle including experimentation and deployment.

Kubeflow Pipelines

Machine learning toolkit for Kubernetes with pipeline orchestration.

Triton Inference Server

NVIDIA Triton for high-throughput, multi-framework model inference.

Seldon Core

Platform for deploying, scaling, and monitoring ML models on Kubernetes.

Qdrant Vector DB

High-performance vector similarity search engine for AI applications.

Weaviate Vector DB

Cloud-native vector database with built-in vectorization modules.

Ollama LLM Runtime

Run large language models locally with a simple container-native interface.

Node.js LTS

Latest LTS Node.js runtime with npm and yarn.

Python 3.12

Python 3.12 with pip, virtualenv, and common scientific libraries.

Go 1.22

Go toolchain with modules and cross-compilation support.

Rust Toolchain

Rust stable toolchain with Cargo and common crates.

Java 21 (Temurin)

Eclipse Temurin JDK 21 with Maven and Gradle.

Swagger UI API Docs

Render and interact with OpenAPI specifications in a browser UI.

curl + jq

Essential HTTP and JSON processing tools for debugging and scripting.

Git LFS

Git Large File Storage for versioning large assets and models.

Terraform CLI

HashiCorp Terraform for infrastructure-as-code provisioning.

Ansible

Agentless IT automation for configuration management and deployments.

k9s Cluster UI

Terminal-based UI for interacting with Kubernetes clusters in real time.

kubectl

Kubernetes command-line tool for cluster management.

eksctl (AWS EKS)

Official CLI for creating and managing EKS clusters.

AWS CLI v2

Command-line interface for managing AWS services.

Google Cloud SDK

CLI tools for interacting with Google Cloud Platform services.

Azure CLI

Command-line tools for managing Azure resources.

Velero Backup & Restore

Backup and restore Kubernetes cluster resources and persistent volumes.

Restic Backup

Fast, encrypted, and deduplicated backups to any storage backend.

ExternalDNS

Synchronizes Kubernetes Ingresses and Services with DNS providers.

Crossplane

Kubernetes-native infrastructure provisioning via CRDs.

0 add-ons selected — $0/mo

All builds include weekly Trivy scans, Cosign signing, SBOM, and zero Critical/High CVE guarantee.