Get started

OpenSourceOM component layout

How a self-hosted CSPM is shaped, as a category, is in Architecture of a self-hosted CSPM. This page is the layout of this repository.

Core is one Go module. The CLI and the API share internal/graph, internal/rules, and the collectors. PostgreSQL is the graph store. Phase 3 adds the plugin SDK, the embedded rule pack, a Helm chart, and cloud audit context from CloudTrail, Activity Log, and Admin Activity logs, on top of the Phase 2 feature set.

Cloud / Kubernetes APIs
        │
        ▼
   Collectors (in-process or plugin stdout)
        │
        ▼
   Postgres nodes + edges
        │
        ├── named path queries and blast radius
        ├── CSPM rules + inventory CVE enrichment → Finding nodes
        └── API + console, and SIEM / Slack / Jira export

Components

Piece Where it lives
CLI cmd/om, internal/cmd
Collectors internal/collectors (AWS, Azure, GCP, Kubernetes, demo)
Plugin SDK sdk/collector, runner in internal/plugins
Graph store and queries internal/graph, SQL in migrations/
CSPM internal/rules and embedded packs/*.yaml
CVE enrichment internal/enrichment
Exports internal/export
API and console internal/api, static files in internal/api/web
Helm deploy/helm/opensourceom

Two ways in

The CLI opens Postgres and writes batches, findings, and export calls itself. The API opens the same database. POST /v1/ingest is the HTTP equivalent of an upsert. om scan does not call the API. That split is why scans work when you only start the Postgres container, and why the console API key is irrelevant to the CLI.

Deployment shapes

  • Docker Compose — Postgres 16 and the API image for a laptop or a single VM.
  • Helm — API Deployment, an init container that migrates, an optional Postgres StatefulSet with a PVC, and optional collector CronJobs.

Those CronJobs stay off until a collector is enabled and credentials are set. They run om scan on a schedule into the chart database. You can still run om scan from a laptop or CI. om scan demo is not a CronJob.

What this version leaves out

Multi-tenant RBAC, SAML, and platform audit logs of who clicked what in the console are outside the open source core. See Open source scope. Recursive path SQL is capped. Azure and GCP REACHABLE edges still ignore firewalls; the collector pages describe that and the IAM rules behind CAN_ACCESS. The design notes in the core repo (ARCHITECTURE.md and the ADRs) are the engineering record behind this page.

Questions

Does om scan call the OpenSourceOM API?

No. The CLI opens Postgres and writes the batch itself. The API reads the same database for the console and HTTP routes. Scans work when only the Postgres container is running.

Where does OpenSourceOM store the security graph?

In PostgreSQL, in nodes and edges tables. The om CLI and the API share that database. Path queries are named SQL walks, not a separate graph database.

Related reading