v1.0.0 — 39 browser-based DevOps tools
39 DevOps and SRE tools that run entirely in your browser. No signup, no backend, nothing uploaded.
Most online tools for this work ask you to paste a workflow file, a JWT or a Terraform plan into a page that quietly POSTs it somewhere. OpsCanopy does the computation locally instead — in JavaScript, and in WebAssembly where that is what it takes.
opscanopy.com · MIT
What's in it
| Area | Tools |
|---|---|
| Observability | Loki alert rule tester, Prometheus relabel tester, Alertmanager route tester, PromQL explainer, LogQL ↔ PromQL helper, Grafana dashboard validator |
| CI/CD | GitHub Actions validator, GitHub Actions expression & trigger tester, GitLab CI validator |
| Kubernetes | Resource calculator, label selector tester |
| Networking | Subnet calculator, subnet splitter, CIDR checker, IP converter, MAC formatter, reverse DNS / PTR |
| Containers | Dockerfile linter, docker run → Compose converter |
| Security | Certificate decoder & chain checker, JWT decoder & verifier, hash generator, CVE-ignore converter |
| Scheduling | Cron expression tester, cron → systemd converter, systemd unit validator |
| Everything else | jq playground, regex log tester, JSON ↔ YAML, Base64, URL codec, timestamp, UUID/ULID, chmod, data size, case converter, slugify, .env.example checker, Terraform plan summarizer |
A few that don't exist elsewhere
- Loki alert rule tester —
promtool test ruleshas no Loki equivalent, and grafana/loki#7655 has been open since 2022. The rule engine compiles to WebAssembly and runs in the tab: paste ruler YAML plus synthetic log lines, assert which alerts fire. - Prometheus relabel tester — step through what each rule does to a label set, including which rule dropped a target. prometheus/prometheus#8606 has wanted this since 2021.
- GitHub Actions expression tester — evaluates
${{ }}against a versioned conformance corpus, becauseif:conditions silently coerce to truthy strings. - jq playground — the real jq 1.8.2 binary via WebAssembly, not a reimplementation, so the filter you test is the one your CI runs.
Self-hosting
docker compose up -d # http://localhost:8080No database, no volumes, nothing to configure. The image is nginx serving static files, running unprivileged and read-only. It keeps the same Content-Security-Policy as production — _headers is Cloudflare syntax, so the build translates it into nginx form rather than quietly dropping the policy.
Privacy
There is no backend to send anything to. Tool input never leaves the browser; most tools keep working with the network disconnected. See /security and /privacy.
Built with
Astro 7 (static output, native i18n) · Tailwind v4 · TypeScript · WebAssembly · deployed on Cloudflare Static Assets. Localized in English, German, Spanish, French and Brazilian Portuguese. Engines are tested against real RFC/NIST vectors — 3,655 unit tests plus a Playwright journey suite covering accessibility, XSS and keyboard paths.