Skip to content

open-component-model/open-delivery-gear

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Open Delivery Gear Logo

Open Delivery Gear

Open Delivery Gear (ODG) is a production-ready compliance automation engine built for software components modelled with the Open Component Model. It helps teams continuously scan delivery artifacts, keep findings actionable, and enforce service-level expectations through automation. ODG implements a trust-but-verify solution for public and sovereign clouds.

The project is under neutral governance by the NeoNephos Foundation, as part of the Apeiro Reference Architecture.

REUSE status OpenSSF Baseline OpenSSF Scorecard

Tip

Check out the live ODG Demo playground

Index

What Is It?

ODG is an extensible security and compliance automation toolbox designed for cloud-native delivery and Kubernetes-centric environments.

Core capabilities include:

  • Kubernetes-native deployment and operating model
  • Asynchronous and autonomous security and compliance scans
  • Extensible architecture for custom integrations and policies
  • Finding tracking with configurable SLAs
  • "Trust, but verify" operating model for delivery assurance
  • Assisted rescoring to extract value from available runtime context information

The goal is to reduce manual governance effort while increasing confidence in software delivery quality and compliance posture across public and sovereign cloud scenarios.

How Does It Work?

Open Delivery Gear follows an automation-first workflow:

  • Users subscribe to OCM component versions.
  • Scans are executed automatically and asynchronously.
  • Scanner capacity scales both vertically and horizontally.
  • Findings are tracked against discovery dates and SLA timelines.
  • Assisted rescoring can adjust due dates or classify findings as false positives.
  • Processing remains traceable and transparent.
  • Assessments can be transported and imported via OCM.

Look and Feel

Open Delivery Gear is designed for both platform operators and application teams. Operators interact with ODG through the Kubernetes API to integrate it into cluster-native workflows. End users can work with findings and delivery insights either through the Delivery Dashboard UI or via HTTP APIs for automation and integration scenarios.

Delivery Dashboard

Getting Started

To get a feel for ODG before setting it up yourself, visit the Demo Playground. It provides a live instance of ODG connected to real data, so you can explore OCM components, findings, and the overall user experience without any installation required.

Related Repositories and Codebases

Core Components and Extensions

The codebase is distributed across multiple repositories.

delivery-service

Core APIs
Extensions

delivery-dashboard

cc-utils

odg-prometheus

Community

Open Delivery Gear is part of the OCM community.

  • Join the regular OCM community call to discuss roadmap topics, integrations, and operational best practices.
  • Use community discussions to share feedback, report gaps, and collaborate on new automation scenarios.

Documentation

Contributing

Code contributions, feature requests, bug reports, and help requests are very welcome. Please refer to the Contributing Guide in the Community repository for more information on how to contribute to ODG.

To make ODG a welcoming and harassment-free experience for everyone, we follow the NeoNephos Code of Conduct.

Licensing

Please refer to the LICENSE for copyright and license information. Detailed information, including third-party components and their licensing/copyright information is available via the REUSE tool.


Bundesministerium für Wirtschaft und Energie (BMWE)-EU funding logo

About

Home of ODG, an extensible and cloud-native compliance delivery engine

Resources

License

Code of conduct

Contributing

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages