OpenSourceOM component layout
How a self-hosted CSPM is shaped, as a category, is in Architecture of a self-hosted CSPM. This page is the layout of this repository.
Core is one Go module. The CLI and the API share internal/graph,
internal/rules, and the collectors. PostgreSQL is the graph store. Phase 3 adds
the plugin SDK, the embedded rule pack, a Helm chart, and cloud audit context from
CloudTrail, Activity Log, and Admin Activity logs, on top of the Phase 2 feature set.
Cloud / Kubernetes APIs
│
▼
Collectors (in-process or plugin stdout)
│
▼
Postgres nodes + edges
│
├── named path queries and blast radius
├── CSPM rules + inventory CVE enrichment → Finding nodes
└── API + console, and SIEM / Slack / Jira export Components
| Piece | Where it lives |
|---|---|
| CLI | cmd/om, internal/cmd |
| Collectors | internal/collectors (AWS, Azure, GCP, Kubernetes, demo) |
| Plugin SDK | sdk/collector, runner in internal/plugins |
| Graph store and queries | internal/graph, SQL in migrations/ |
| CSPM | internal/rules and embedded packs/*.yaml |
| CVE enrichment | internal/enrichment |
| Exports | internal/export |
| API and console | internal/api, static files in internal/api/web |
| Helm | deploy/helm/opensourceom |
Two ways in
The CLI opens Postgres and writes batches, findings, and export calls itself. The API opens
the same database. POST /v1/ingest is the HTTP equivalent of an upsert.
om scan does not call the API. That split is why scans work when you only start
the Postgres container, and why the console API key is irrelevant to the CLI.
Deployment shapes
- Docker Compose — Postgres 16 and the API image for a laptop or a single VM.
- Helm — API Deployment, an init container that migrates, an optional Postgres StatefulSet with a PVC, and optional collector CronJobs.
Those CronJobs stay off until a collector is enabled and credentials are set. They run
om scan on a schedule into the chart database. You can still run
om scan from a laptop or CI. om scan demo is not a CronJob.
What this version leaves out
Multi-tenant RBAC, SAML, and platform audit logs of who clicked what in the console are
outside the open source core. See Open source scope.
Recursive path SQL is capped. Azure and GCP REACHABLE edges still ignore
firewalls; the collector pages describe that and the IAM rules behind CAN_ACCESS.
The design notes in the core repo
(ARCHITECTURE.md
and the ADRs) are the engineering record behind this page.
Questions
Does om scan call the OpenSourceOM API?
No. The CLI opens Postgres and writes the batch itself. The API reads the same database for the console and HTTP routes. Scans work when only the Postgres container is running.
Where does OpenSourceOM store the security graph?
In PostgreSQL, in nodes and edges tables. The om CLI and the API share that database. Path queries are named SQL walks, not a separate graph database.
Related reading
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.