Releases: opscanopy/opscanopy.com
Release list
v1.1.0 — answers in the HTML, two more practice exams
Fifty-eight commits since v1.0.0. No breaking change: the documented docker run command is unchanged.
Tools answer before you type
Every tool page now carries a worked answer for its first example in the static HTML. AI assistants and crawlers do not run JavaScript, so until now they saw an empty panel and a "type something here" prompt on all 39 tools. 37 of 39 now server-render a real result.
The two exceptions are deliberate. The certificate decoder needs asynchronous WebCrypto and prints expiry text that goes stale daily; the jq playground's answer needs its WebAssembly binary at build time. The UUID generator is seeded but only with the all-zero Nil UUID and a fixed inspector example — baking a minted UUID into a page would serve every visitor the same "freshly generated" value.
Two more full-length practice exams
- DOP-C02 Practice Set 3 — 75 questions, 180 minutes
- AIF-C01 Mock Exam 2 — 65 questions, 90 minutes
Both are real exam length and follow the domain weightings AWS publishes. All 140 questions are original and share no scenario with the 95 already on the site, which is enforced by a similarity check in the test suite.
Every answer key was re-derived independently from a copy with the keys and explanations removed, so agreement is evidence rather than an echo. That pass caught three services that had closed to new customers mid-2026 — Amazon Kendra, Bedrock Agents (now Agents Classic) and SageMaker A2I — and changed one answer key outright.
The existing AIF mock was also rebalanced: option B had been correct in 40 of its 54 single-answer questions, so always picking B beat studying.
Also in this release
- A design pass: three elevation tiers, dark-stable instrument panels for tool results, figure captions, and an amber tick on values that changed.
- Tool FAQs moved into one registry so
/llms-full.txtcan carry them. - Four new comparison articles and a 14-day AIF-C01 study plan that now uses both mocks.
Self-hosting fixes
Two things were wrong in v1.0.0 and are fixed here:
- The hardened run crash-looped. A tmpfs mounts root-owned and masks the image's ownership, so nginx (uid 101) could not create its scratch directories.
docker runneeds--tmpfs /var/cache/nginx:uid=101,gid=101, and Compose cannot express uid/gid, sodocker-compose.ymlnow uses long-form volumes. .dockerignoreexcludes.git, so every image build produced the same service-worker cache name and served stale pages after an upgrade. The Dockerfile now takes aBUILD_IDbuild argument, which CI supplies.
docker run -d --name opscanopy -p 8080:8080 \
--read-only \
--tmpfs /var/cache/nginx:uid=101,gid=101 \
--tmpfs /var/run:uid=101,gid=101 \
--security-opt no-new-privileges:true \
ghcr.io/opscanopy/opscanopy.com:1.1.0Verified by pulling anonymously and running with exactly that command: healthy, no restarts, and /sw.js carries this release's build id.
v1.0.0 — 39 browser-based DevOps tools
39 DevOps and SRE tools that run entirely in your browser. No signup, no backend, nothing uploaded.
Most online tools for this work ask you to paste a workflow file, a JWT or a Terraform plan into a page that quietly POSTs it somewhere. OpsCanopy does the computation locally instead — in JavaScript, and in WebAssembly where that is what it takes.
opscanopy.com · MIT
What's in it
| Area | Tools |
|---|---|
| Observability | Loki alert rule tester, Prometheus relabel tester, Alertmanager route tester, PromQL explainer, LogQL ↔ PromQL helper, Grafana dashboard validator |
| CI/CD | GitHub Actions validator, GitHub Actions expression & trigger tester, GitLab CI validator |
| Kubernetes | Resource calculator, label selector tester |
| Networking | Subnet calculator, subnet splitter, CIDR checker, IP converter, MAC formatter, reverse DNS / PTR |
| Containers | Dockerfile linter, docker run → Compose converter |
| Security | Certificate decoder & chain checker, JWT decoder & verifier, hash generator, CVE-ignore converter |
| Scheduling | Cron expression tester, cron → systemd converter, systemd unit validator |
| Everything else | jq playground, regex log tester, JSON ↔ YAML, Base64, URL codec, timestamp, UUID/ULID, chmod, data size, case converter, slugify, .env.example checker, Terraform plan summarizer |
A few that don't exist elsewhere
- Loki alert rule tester —
promtool test ruleshas no Loki equivalent, and grafana/loki#7655 has been open since 2022. The rule engine compiles to WebAssembly and runs in the tab: paste ruler YAML plus synthetic log lines, assert which alerts fire. - Prometheus relabel tester — step through what each rule does to a label set, including which rule dropped a target. prometheus/prometheus#8606 has wanted this since 2021.
- GitHub Actions expression tester — evaluates
${{ }}against a versioned conformance corpus, becauseif:conditions silently coerce to truthy strings. - jq playground — the real jq 1.8.2 binary via WebAssembly, not a reimplementation, so the filter you test is the one your CI runs.
Self-hosting
docker compose up -d # http://localhost:8080No database, no volumes, nothing to configure. The image is nginx serving static files, running unprivileged and read-only. It keeps the same Content-Security-Policy as production — _headers is Cloudflare syntax, so the build translates it into nginx form rather than quietly dropping the policy.
Privacy
There is no backend to send anything to. Tool input never leaves the browser; most tools keep working with the network disconnected. See /security and /privacy.
Built with
Astro 7 (static output, native i18n) · Tailwind v4 · TypeScript · WebAssembly · deployed on Cloudflare Static Assets. Localized in English, German, Spanish, French and Brazilian Portuguese. Engines are tested against real RFC/NIST vectors — 3,655 unit tests plus a Playwright journey suite covering accessibility, XSS and keyboard paths.