Open-source cloud security docs
OpenSourceOM Core is a self-hosted security graph. Collectors pull cloud and Kubernetes inventory
into PostgreSQL. Named path queries, CSPM rules, and CVE enrichment rank what an outsider can
reach. These pages describe the om CLI, REST API, and collectors as they ship in
OpenSourceOM/core. Phase 3 has shipped.
Start
- Getting started — Compose, migrations, the demo graph, and a first scan
- Configuration — environment variables for the CLI and API
Graph
- The graph — nodes, edges, and how findings attach
- Schema — node types, edge types, and ID format
- Attack paths — the six named queries, attack-path findings, and cloud audit events on a path
- Blast radius — what an identity can reach
- Prioritization — how graph context changes a score
Platform
- CLI —
omcommand reference - API — REST endpoints under
/v1 - Console — the embedded graph explorer
- CSPM rules — built-in checks and how findings are written
- Rule packs — YAML packs compiled into the binary
- CVE enrichment — match workload packages and images, then write findings
- Exports — SIEM JSONL, Slack, and Jira
Collectors
- Overview — what a scan writes, and what it does not
- AWS, Azure, GCP, Kubernetes
- Plugins — external collectors via
om scan plugin
Operate
- Architecture — components and data flow
- Docker Compose — local Postgres and API
- Kubernetes — Helm chart
- Security — API secret, read-only collectors, vulnerability reports
- Open source scope — what stays in Core versus planned commercial work
Questions
What is OpenSourceOM?
OpenSourceOM is a self-hosted, Apache-2.0 cloud security platform. Collectors inventory AWS, Azure, GCP, and Kubernetes into a Postgres graph so you can query attack paths and rank CSPM findings by what an outsider can reach.
Is OpenSourceOM a CNAPP?
It covers the security-graph, attack-path, and CSPM parts of a CNAPP, and you run it in your own environment. SAML, multi-tenant RBAC, and a commercial SaaS console are not part of the open-source core.
Where do I start?
Install with Docker Compose, run om migrate, then om scan demo. That loads a sample graph with no cloud credentials. Real AWS, Azure, GCP, and Kubernetes scans use each provider’s default read-only credentials.
Related reading
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.