Proof-checked orchestrator

It refuses to run what it cannot prove.

Bring proof checks to the infrastructure workflow you already use. Vizier reads your existing Terragrunt tree, verifies each module’s evidence, and blocks what falls below your policy.

Download and installation options

Availability - v1.7.2

A free download for Linux, macOS and Windows (amd64 and arm64), with a free IaC Bazaar account.

export IACBAZAAR_TOKEN=iacb_...
curl -fsSL https://raw.githubusercontent.com/CyberCoreSystems/vizier/main/install.sh | sh

From a terminal or CI, the installer takes a token from your account and checks the archive against its published digest before it installs anything.

341 live-tested modules Vizier will run, enforce mode by default.

Evidence before execution
Vizier's holographic estate: a slowly rotating sphere of circuit tracks and orbital rings. Ambient geometry, not a live view of any infrastructure.
Precision. Oversight. Control.

Terragrunt runs any module.
Vizier runs only proven ones.

Terragrunt and native Stacks orchestrate whatever you point them at, and they check the plan. Vizier checks the module: it resolves each source against a catalog of live-tested, signed modules and refuses what cannot clear your bar. A wrapper can add that check, but the check is only worth as much as the catalog behind it, and the catalog is the part that takes years.

Proof check

A catalog module is resolved against the catalog and its signature checked against a key compiled into the binary. Your own module is checked against a digest you pin. Either way it is settled before a single resource is planned.

Fail-closed

In enforce mode an unreachable catalog or a missing proof blocks the run. Vizier never applies on doubt - verification refuses it.

vizier.lock

Verified proofs are pinned to a lockfile so re-verification is reproducible. The catalog stays the source of truth: an unreachable catalog blocks the run unless you pass --offline, because a signature proves a digest, not which module or status it belongs to.

Watch it block.

The check runs for every unit before a single apply. A module below your bar stops the run with a precise reason - which unit, which module, why - and exit status 3, which is vizier's own code for a refusal so a pipeline can route it somewhere other than a broken plan.

--verify-mode enforcefail-closed
$ vizier verify
[BLOCK] app - [email protected] status "statically_validated" below required "live_tested"
[ok] kms - [email protected] proven (live_tested, signature verified)
vizier: 1 unit(s) failed the proof check
exit status 3

Three verbs, one proof check

01 / 03

Describe the unit

One vizier.hcl per unit: an iacbazaar:// module source, its inputs, dependencies, and a verify {} policy.

02 / 03

vizier verify

Read each unit’s proof against the catalog and report ok or blocked - no tofu runs, no cloud touched.

03 / 03

vizier run-all apply

Check every unit first, then apply in dependency order, threading outputs to dependents. Blocked means blocked.

A slowly rotating sphere of circuit tracks, orbital rings and a bright central aperture.

Ambient geometry. Not a live view of your estate.

Meet Vizier

The whole estate, before you touch it.

Vizier holds every unit in view at once - what it depends on, what changed, and what evidence it carries - and decides from that rather than from the order you happened to type. Calm, precise, and unwilling to guess.

“I read the proof, not the promise.”

In enforce mode, missing or insufficient evidence blocks the run.

Alone, or with your team

The same binary runs one operator on one tree, or joins a control plane your company hosts on its own Postgres. Roles, one evidence floor per environment, review before an apply, and durable history. It stores no cloud credentials and no Terraform state, and it never executes anything: your machine runs the apply, Central decides whether it may and records what happened.

Roles that hold

Viewer, operator, admin, owner. An operator applies and cannot destroy; weakening an environment is an owner act. The refusal happens on the server, so a client nobody controls cannot talk its way past it.

One floor per environment

Production demands live-tested, signed and pinned; a sandbox need not. The floor is handed to the runner at the start of every run, so nobody has to remember the right flags and nobody can quietly not pass them.

History that outlives the process

Every run from every operator lands in one place with its receipt attached, verbatim. A local console cannot offer this: its history ends when you close it.

Review, where the diff is the plan

A change is a pull request for infrastructure. A code diff tells you what the HCL says; it does not tell you that this apply replaces a database. What gets reviewed here is the plan, and it arrives with the receipt saying which modules were admitted, on what evidence, against which policy. Two rules make the review mean something, and both are enforced in the database rather than in a client anybody could edit: the author cannot approve their own change, and an approval is pinned to one commit - approve one, apply another, and the approval was theatre.

# the engineer
vizier central propose --title "Add a read replica" --head 8f2c41a --verb apply

# somebody else, and it must be somebody else
vizier central review 58384dc6 --approve --note "Parameter group only."

# and now the apply is allowed, at that commit and no other
vizier apply --dir envs/prod

Availability - Central

Central is the paid edition and is not on the public releases page. Subscribe, and the build and your licence both appear on your account page, with the sha256 of each archive beside it. Linux, macOS and Windows, amd64 and arm64.

The free binary does not contain it, and says so rather than pretending the feature is missing.

What it costs

Priced per organisation, not per seat, and self-hosted against your own Postgres. A lapsed licence never locks you out of your own history: reads and the audit log keep working, and only new privileged writes are refused.

Run these, verified

Point Vizier at any live-tested module in the Bazaar.

View all 901 →
Live-tested

ansible-rsyslog-forward

rsyslog ships logs in clear over port 514, which is what most examples do. This role configures the sending side with the gtls driver, the collector's CA and x509/name, so a host with a certificate from elsewhere in the estate cannot collect your logs. The live test watches a line arrive and reads the handshake. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-ssh-ca

sshd can trust a CA and accept any certificate it signed, so access is granted by signing rather than by editing authorized_keys everywhere. The live test proves it four ways over a real connection: the matching certificate gets in, one for another principal does not, one that expired does not, and a key the CA never signed does not. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

gcp-filestore

A managed Cloud Filestore NFS share for GKE and Compute Engine, VPC-peered with no public exposure, optional per-client export rules for least-privilege access, and deletion protection on.

View module
Live-tested

gcp-vertex-ai

A Vertex AI Endpoint for online prediction with optional CMEK, optional Private Service Access networking and request/response logging - model deployment left to you, so it stands up for cents.

View module
Live-tested

gcp-composer

Managed Apache Airflow on Cloud Composer 2 with small-by-default sizing, worker autoscaling pinned for predictable cost, and an opt-in private environment posture.

View module
Live-tested

gcp-dataproc

A single-node Dataproc cluster (1 master, 0 workers), the cheapest managed Spark/Hadoop cluster that still applies and destroys cleanly, with internal-only IPs and deletion protection on.

View module

Orchestrate what you can prove.

One binary, no runtime dependencies beyond a tofu on your PATH. Point it at a tree of verified modules and it refuses anything it cannot vouch for.

Availability - v1.7.2

A free download for Linux, macOS and Windows (amd64 and arm64), with a free IaC Bazaar account.

export IACBAZAAR_TOKEN=iacb_...
curl -fsSL https://raw.githubusercontent.com/CyberCoreSystems/vizier/main/install.sh | sh

From a terminal or CI, the installer takes a token from your account and checks the archive against its published digest before it installs anything.