A modern, multi-cloud infrastructure provisioning platform that enables self-service Kubernetes deployments across AWS, Azure, and GCP.
Features β’ Quick Start β’ Architecture β’ Usage β’ Configuration β’ Contributing
OneClickOps is an open-source infrastructure provisioning platform that allows teams to self-service their Kubernetes environments. Instead of waiting for DevOps teams to manually provision infrastructure, developers and stakeholders can:
- Select a cloud provider (AWS, Azure, or GCP)
- Choose environment specifications (size, type, region)
- Click deploy and get a fully configured Kubernetes cluster with a managed database
The platform handles all the complexity of cloud provisioning, including VPC setup, security groups, IAM roles, and Kubernetes configuration.
| Traditional Approach | With OneClickOps |
|---|---|
| Submit ticket to DevOps | Self-service portal |
| Wait 2-5 days for provisioning | Automated in 15-20 minutes |
| Manual, error-prone process | Consistent, repeatable deployments |
| No cost visibility | Real-time cost estimation |
| Single cloud vendor lock-in | Multi-cloud flexibility |
| No lifecycle management | Automated TTL and cleanup |
- 83% faster provisioning (90 min β 15 min)
- 100% reduction in engineer wait time (async processing)
- 3x cloud options (AWS, Azure, GCP)
- Full cost visibility before deployment
- AWS: EKS (Elastic Kubernetes Service) + RDS (PostgreSQL)
- Azure: AKS (Azure Kubernetes Service) + Azure Database for PostgreSQL
- GCP: GKE (Google Kubernetes Engine) + Cloud SQL
- Web UI: Modern React-based dashboard for stakeholders
- REST API: Full-featured API for automation
- CLI Tool: Command-line interface for power users
- Pre-deployment estimates: Know costs before you deploy
- Provider comparison: Compare costs across AWS, Azure, and GCP
- Annual projections: See reserved instance savings
- Non-blocking: Submit request and continue working
- Real-time updates: WebSocket-based progress tracking
- Task management: Monitor all provisioning tasks
- JWT Authentication: Secure API access
- Role-Based Access Control: Fine-grained permissions
- Secret Management: HashiCorp Vault integration (optional)
- No credential storage: Bring your own cloud credentials
- Prometheus metrics: Monitor platform health
- Grafana dashboards: Visualize operations
- Structured logging: JSON logs for analysis
- Distributed tracing: Debug complex flows
- TTL (Time-to-Live): Auto-cleanup environments
- Scheduled actions: Stop/start on schedule
- Extension management: Request more time when needed
- Docker & Docker Compose v2.0+
- Cloud credentials for your target provider(s):
- AWS: Access Key ID & Secret Access Key
- Azure: Service Principal credentials
- GCP: Service Account JSON key
git clone https://github.com/thegde/oneclickops.git
cd oneclickops/cloud_provider# Start with minimal setup (recommended for first run)
docker-compose -f docker-compose.minimal.yml up -d
# Check status
docker-compose -f docker-compose.minimal.yml ps| Service | URL | Description |
|---|---|---|
| Web UI | http://localhost:3000 | Self-service dashboard |
| API Docs | http://localhost:8022/api/docs | Interactive API documentation |
| Flower | http://localhost:5555 | Task monitoring |
Option A: Using the Web UI
- Open http://localhost:3000
- Select your cloud provider (AWS/Azure/GCP)
- Enter customer name and environment name
- Choose environment size
- Click "Create Environment"
Option B: Using the API
# Create infrastructure
curl -X POST http://localhost:8022/api/v1/infrastructure \
-H "Content-Type: application/json" \
-d '{
"cloud_provider": "aws",
"customer_name": "mycompany",
"environment_name": "dev",
"environment_type": "dev",
"environment_size": "small"
}'Option C: Using the CLI
# Install CLI
cd cli && pip install -e .
# Create infrastructure
ssm create -c mycompany -e dev -p aws -s smallβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β USER INTERFACES β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ β
β β Web UI β β REST API β β CLI β β
β β (React) β β (FastAPI) β β (Python) β β
β βββββββββββββββ βββββββββββββββ βββββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β PLATFORM API LAYER β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
β β Auth β β Rate β β Validationβ β WebSocket β β
β β (JWT) β β Limiting β β (Pydantic)β β Updates β β
β βββββββββββββ βββββββββββββ βββββββββββββ βββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β ASYNC TASK PROCESSING β
β βββββββββββββ βββββββββββββ βββββββββββββ β
β β Celery β β Redis β β Flower β β
β β Workers β β Queue β β Monitoringβ β
β βββββββββββββ βββββββββββββ βββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β CLOUD PROVIDER ABSTRACTION β
β βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β Unified Provider Interface β β
β β create_cluster() | create_database() | create_vpc() β β
β βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β β β β
β βΌ βΌ βΌ β
β βββββββββββββ βββββββββββββ βββββββββββββ β
β β AWS β β Azure β β GCP β β
β β EKS + RDS β β AKS + PSQLβ β GKE + SQL β β
β βββββββββββββ βββββββββββββ βββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βΌ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β INFRASTRUCTURE AS CODE β
β βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β
β β Terraform Modules β β
β β VPC | Kubernetes | Database | Security β β
β βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Component | Technology | Purpose |
|---|---|---|
| Web UI | React | Self-service dashboard for stakeholders |
| API | FastAPI | REST API with OpenAPI documentation |
| Task Queue | Celery + Redis | Async processing of long-running tasks |
| Database | SQLite/PostgreSQL | Track infrastructure and tasks |
| IaC | Terraform | Provision cloud resources |
| Secrets | HashiCorp Vault | Secure credential storage (optional) |
The web interface is designed for stakeholders who need to provision infrastructure without technical expertise.
Creating an Environment:
- Select Cloud Provider: Choose AWS, Azure, or GCP based on your requirements
- Enter Details:
- Customer Name: Your organization identifier (e.g., "acme-corp")
- Environment Name: Purpose of the environment (e.g., "dev", "staging")
- Choose Configuration:
- Environment Type: dev, qa, stage, or uat
- Environment Size: small (3 nodes), medium (5 nodes), or large (8 nodes)
- Review Cost: See estimated monthly cost before deploying
- Deploy: Click "Create Environment" and monitor progress
Full API documentation is available at http://localhost:8022/api/docs
Authentication:
# Login to get JWT token
curl -X POST http://localhost:8022/api/v1/auth/login \
-H "Content-Type: application/json" \
-d '{"username": "admin", "password": "admin123"}'
# Use token in subsequent requests
export TOKEN="your-jwt-token"
curl -H "Authorization: Bearer $TOKEN" http://localhost:8022/api/v1/infrastructureKey Endpoints:
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/v1/auth/login |
Authenticate and get JWT token |
| POST | /api/v1/infrastructure |
Create new infrastructure |
| GET | /api/v1/infrastructure |
List all infrastructure |
| GET | /api/v1/infrastructure/{id} |
Get infrastructure details |
| DELETE | /api/v1/infrastructure/{id} |
Delete infrastructure |
| GET | /api/v1/tasks/{id} |
Get task status |
| POST | /api/v1/catalog/cost-estimate |
Estimate costs |
| GET | /api/v1/catalog/templates |
List environment templates |
The CLI is ideal for automation and power users.
Installation:
cd cli
pip install -e .Commands:
# Authentication
ssm login -u admin -p admin123
# Create infrastructure
ssm create \
--customer acme \
--environment staging \
--provider azure \
--size medium \
--type stage
# List infrastructure
ssm list
# Check task status
ssm task <task-id>
# Estimate costs
ssm cost --provider aws --size medium
# Delete infrastructure
ssm delete <infrastructure-id>Create a .env file in the cloud_provider directory:
# Application
APP_NAME=OneClickOps
ENVIRONMENT=production
DEBUG=false
# Authentication
JWT_SECRET=your-secure-secret-key-change-this
JWT_EXPIRE_MINUTES=60
AUTH_DISABLED=false
# Redis
REDIS_URL=redis://localhost:6379/0
CELERY_BROKER_URL=redis://localhost:6379/0
CELERY_RESULT_BACKEND=redis://localhost:6379/1
# Database
DATABASE_URL=postgresql://user:pass@localhost:5432/ssm
# Vault (optional)
VAULT_ENABLED=true
VAULT_ADDR=http://localhost:8200
VAULT_TOKEN=your-vault-tokenOneClickOps uses your cloud credentials to provision infrastructure. You have several options:
AWS:
export AWS_ACCESS_KEY_ID=your-access-key
export AWS_SECRET_ACCESS_KEY=your-secret-key
export AWS_REGION=us-east-1Azure:
export AZURE_SUBSCRIPTION_ID=your-subscription-id
export AZURE_TENANT_ID=your-tenant-id
export AZURE_CLIENT_ID=your-client-id
export AZURE_CLIENT_SECRET=your-client-secretGCP:
export GOOGLE_APPLICATION_CREDENTIALS=/path/to/service-account.json
export GCP_PROJECT_ID=your-project-idStore credentials securely in Vault:
# Enable KV secrets engine
vault secrets enable -path=ssm kv-v2
# Store AWS credentials
vault kv put ssm/cloud/aws \
access_key_id=your-access-key \
secret_access_key=your-secret-key
# Store Azure credentials
vault kv put ssm/cloud/azure \
subscription_id=your-subscription-id \
tenant_id=your-tenant-id \
client_id=your-client-id \
client_secret=your-client-secret
# Store GCP credentials
vault kv put ssm/cloud/gcp \
project_id=your-project-id \
credentials=@service-account.jsonFor production, configure remote state storage:
AWS S3:
terraform {
backend "s3" {
bucket = "your-terraform-state-bucket"
key = "ssm/terraform.tfstate"
region = "us-east-1"
dynamodb_table = "terraform-locks"
encrypt = true
}
}cloud_provider/
βββ app/ # FastAPI application
β βββ api/v1/endpoints/ # API endpoints
β β βββ auth.py # Authentication
β β βββ infrastructure.py # Infrastructure CRUD
β β βββ tasks.py # Task status
β β βββ catalog.py # Templates & costs
β β βββ websocket.py # Real-time updates
β βββ core/ # Core utilities
β β βββ config.py # Configuration
β β βββ logging.py # Structured logging
β β βββ dependencies.py # Dependency injection
β βββ models/ # Data models
β β βββ requests.py # Request schemas
β β βββ responses.py # Response schemas
β β βββ database.py # ORM models
β βββ providers/ # Cloud providers
β β βββ base.py # Abstract interface
β β βββ aws_provider.py # AWS implementation
β β βββ azure_provider.py # Azure implementation
β β βββ gcp_provider.py # GCP implementation
β β βββ factory.py # Provider factory
β βββ services/ # Business logic
β β βββ auth.py # Authentication service
β β βββ catalog/ # Service catalog
β β βββ gitops.py # ArgoCD integration
β β βββ observability.py # Metrics & tracing
β βββ tasks/ # Celery tasks
β βββ celery_app.py # Celery configuration
β βββ infrastructure.py # Provisioning tasks
β βββ notifications.py # Alert tasks
βββ frontend/ # React web UI
βββ terraform/ # IaC modules
β βββ modules/aws/ # AWS resources
β βββ modules/azure/ # Azure resources
β βββ modules/gcp/ # GCP resources
βββ cli/ # Command-line tool
βββ observability/ # Monitoring configs
βββ docker-compose.yml # Full stack
βββ docker-compose.minimal.yml # Minimal setup
βββ Makefile # Quick commands
# Run all tests
pytest
# Run with coverage
pytest --cov=app --cov-report=html
# Run specific test file
pytest tests/test_infrastructure.py -v# Format code
black app/
isort app/
# Type checking
mypy app/
# Linting
flake8 app/- Create provider class in
app/providers/:
# app/providers/digitalocean_provider.py
from app.providers.base import CloudProviderInterface
class DigitalOceanProvider(CloudProviderInterface):
def create_cluster(self, config: ClusterConfig) -> ClusterOutput:
# Implementation
pass
def delete_cluster(self, cluster_id: str) -> bool:
# Implementation
pass- Register in factory:
# app/providers/factory.py
from app.providers.digitalocean_provider import DigitalOceanProvider
class ProviderRegistry:
_providers = {
CloudProvider.AWS: AWSProvider,
CloudProvider.AZURE: AzureProvider,
CloudProvider.GCP: GCPProvider,
CloudProvider.DIGITALOCEAN: DigitalOceanProvider, # Add here
}- Add Terraform module in
terraform/modules/digitalocean/
# Full stack with observability
docker-compose up -d
# Minimal stack
docker-compose -f docker-compose.minimal.yml up -dHelm chart coming soon. For now, use the provided manifests:
kubectl apply -f k8s/AWS IAM Policy:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"eks:*",
"ec2:*",
"rds:*",
"iam:CreateRole",
"iam:AttachRolePolicy",
"iam:PassRole"
],
"Resource": "*"
}
]
}Azure RBAC:
- Contributor role on the subscription
- Or custom role with AKS, VNet, and PostgreSQL permissions
GCP IAM:
- Kubernetes Engine Admin
- Compute Network Admin
- Cloud SQL Admin
We welcome contributions! Please see our Contributing Guide for details.
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
- π Additional cloud providers (DigitalOcean, Oracle Cloud, etc.)
- π¨ UI/UX improvements
- π Documentation
- π§ͺ Test coverage
- π§ Bug fixes
- π Internationalization
- Multi-cloud support (AWS, Azure, GCP)
- Async task processing
- Cost estimation
- Web UI
- CLI tool
- Helm chart for Kubernetes deployment
- GitOps integration (ArgoCD)
- Backstage plugin
- Slack/Teams notifications
- Custom Terraform module support
- Multi-region deployments
- Disaster recovery automation
This project is licensed under the MIT License - see the LICENSE file for details.
- Built with FastAPI
- Task queue powered by Celery
- Infrastructure as Code with Terraform
- UI built with React
- Documentation: docs/
- Issues: GitHub Issues
- Discussions: GitHub Discussions
Made with β€οΈ by Tapan Hegde