Your infrastructure,unified.
The desktop and cloud platform for managing
Connect your provider accounts and Infrawrench discovers every resource in them, then gives you the tools to actually work on it: open an SSH terminal or a pod shell, run a query, browse a bucket, watch costs, and create new resources from typed forms, across 25+ providers, in one app instead of a dozen consoles.
Run it in your browser with nothing to install, or download the desktop app for macOS, Windows, and Linux and keep everything local, free and with no account required.
Feature tour
Everything your agents and infra team needs
Click a feature to explore. Infrawrench brings together the tools you'd normally need a dozen different apps for.
Manage everything from one place
Connect to 25+ cloud providers and manage hundreds of resource types from a single unified interface. Infrawrench discovers your infrastructure automatically and keeps it in sync every 30 seconds.
AWS, GCP, Azure, Cloudflare, DigitalOcean, Hetzner, Scaleway, OVH, and 17 more
Automatic resource discovery with background sync, no manual refresh
Right-click context menus with provider-specific actions per resource type
Drag-and-drop to attach disks, volumes, and Elastic IPs to compute resources
Spotlight search (⌘K) across all accounts and resource types at once

SSH into anything, anywhere
Launch full SSH terminals to any server directly from Infrawrench. No external client needed. On desktop, connections run locally. In the cloud web app, sessions are proxied securely through our WebSocket server.
Full terminal with resize, 256-color, and clipboard support
Reads keys from ~/.ssh/ or your saved in-app key store
One-click SSH from any VM resource (EC2, GCE, Droplet, Hetzner, and more)
SSH tunnels: proxy a database port through a bastion host with service presets
Windows Pageant SSH agent support on desktop

Full Kubernetes management
Browse, inspect, and manage your Kubernetes clusters. Exec into pods, stream logs, import YAML manifests, and edit live configs. The web app proxies exec sessions so nothing runs locally.
Supports any kubeconfig cluster: EKS, GKE, AKS, self-hosted
Pod exec / interactive shell (cloud-proxied via WebSocket in the web app)
Log streaming for pods, deployments, statefulsets, services, and jobs
YAML import (kubectl apply -f equivalent) with multi-document support
Monaco manifest editor for live resource config editing
Ephemeral scratch pods with configurable TTL (auto-terminated by the cluster)
Query your databases in context
A built-in SQL editor with schema autocomplete, per-resource connection management, and support for a wide range of databases: from traditional PostgreSQL to serverless edge databases.
Schema-aware autocomplete via INFORMATION_SCHEMA introspection
Per-resource SQL: connect directly to a specific RDS instance, Neon db, or Turso group
Supports PostgreSQL, MySQL, Turso/libsql, Databricks, ClickHouse, Cloudflare D1, Spanner
Query cost estimation for BigQuery (dry-run API, no quota consumed)
Connection strings resolved automatically from resource outputs
Browse and manage object storage
A built-in object storage file browser for S3, GCS, Cloudflare R2, Azure Blob Storage, and DigitalOcean Spaces. Upload, download, create folders, and delete, without leaving the app.
Prefix-based folder navigation with breadcrumbs
File upload with progress tracking
Batch download of multiple objects (desktop)
Storage stats: object count and total size on the dashboard card
Pin and monitor your key resources
Build custom dashboards by pinning any resource from any provider. Cards show live stats and status. Set metric thresholds and get native OS notifications when something goes out of range.
Drag-and-drop grid layout: pin resources from multiple providers on one dashboard
Live stats auto-refresh: table counts, container counts, storage size, and more
Metric ping alerts: native OS notification when a metric leaves a min/max range
Multiple named dashboards with a configurable default
Manage and export secrets safely
View, rotate, and export secrets from AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and more. Credentials are encrypted at rest and only decrypted on demand.
Secret versions: list, reveal, add, enable, disable, and destroy with one click
Credential export: IAM access keys, GCP service account JSON, Azure client secrets, Cloudflare tunnel tokens
Kubernetes-ready secret export templates on S3, R2, Cloudflare Tunnel, and more
Credentials encrypted at rest. Keys never leave the device (desktop)
Provision resources without leaving the app
Provision VMs, Kubernetes clusters, databases, queues, and buckets with a guided form backed by live data from the provider API. Includes real-time cost estimation, region and size pickers, and SSH key selection.
Live cost estimates for EC2, GCE, AKS, Azure VMs, RDS, EBS, and more
Region picker: searchable by zone ID, flag, or human-readable location name
SSH key picker reads from ~/.ssh/ and your saved key store
IAM policy picker with live search and categorised results
Supported across AWS, GCP, Azure, DigitalOcean, Hetzner, Kubernetes, and more
Start local, go cloud
Use the desktop app fully offline. Sign in to sync your accounts, resources, dashboards, and credentials to the cloud, kept in sync bidirectionally.
Secure sign-in, no passwords stored or transmitted
Bidirectional sync every 60 seconds: desktop ↔ cloud
API keys for programmatic and CI pipeline access
Team management with per-seat billing ($20/seat/month)
Full audit trail for all mutations in the cloud app
Infrawrench Cloud
The same app, hosted for your team
Sign in and everything is already there: accounts, terminals, dashboards, and history, all shared with everyone you work with.
SSH and kubectl exec in the browser
Terminal sessions are proxied through our WebSocket server: shell into EC2, GCE, Droplets, or Hetzner boxes, exec into pods, stream logs, and tunnel a database through a bastion. No VPN, no local SSH client, no kubeconfig file.
One workspace for the whole team
Invite teammates into an organization and share every account, dashboard, and budget. Roles and permissions decide who can read, who can act, and who can hold the credentials.
Alerts that find you
Budget and resource pages route to Slack, Microsoft Teams, and push notifications on the Infrawrench mobile app, instead of an OS notification on a laptop that is closed.
AI chat and scheduled workflows
The agent loop and conversation history live in the cloud, so chat works everywhere you sign in. Workflows run server-side on a schedule, on a git push, or when a budget trips.
Audit log, API keys, and SDKs
Every action is recorded against a user. Issue scoped API keys and drive the same HTTP API from nine generated client SDKs. Audit log and API keys are on the paid plan.
Nothing to install, anywhere
The same app in any browser, always on the latest version, plus an iOS and Android companion for dashboards, resources, chat, and terminals while you are on call.
Resource wiring
Inputs & outputs connect your cloud
Every resource exposes typed outputs: IPs, connection strings, tokens, kubeconfigs, and more. Wire them as inputs to other resources so everything stays resolved automatically.
Connection string outputs
Databases expose a connectionString output. Link it directly to the SQL editor and it connects automatically. No copy-pasting credentials.
IP address outputs
Compute resources expose publicIp and privateIp outputs. Infrawrench uses these to open an SSH terminal with one click. No manual host entry.
Kubernetes peer outputs
Managed K8s clusters (EKS, GKE, AKS, DOKS) expose a kubeconfig output that automatically links to the Kubernetes plugin, so pods, services, and deployments appear without any manual setup.
Secret outputs
IAM users, service accounts, and app registrations expose credential outputs. Download as JSON, env files, or Kubernetes secrets, or reference them directly from other resources.
Cross-cloud resource wiring
Connect outputs from any AWS resource into another context. An RDS endpoint drives the SQL editor directly, or feed an EKS kubeconfig to the Kubernetes plugin, without touching config files.
Storage access tokens
Object storage resources (S3, R2, GCS, Azure Blob) generate scoped access tokens on demand so the in-app file browser operates without storing long-lived credentials.
Supported providers
24 providers · 225+ resource types across cloud, infrastructure, databases, and more.
Supported providers & resource types
24 providers · 225+ resource types
Cloud
AWS
51 resource types
Google Cloud
50+ resource types
Azure
26 resource types
Infrastructure
Kubernetes
12 resource types + exec/logs/YAML
Docker
Container management
SSH
Any Linux server
Databases
PostgreSQL
SQL editor + schema autocomplete
MySQL
SQL editor
Redis
KV console + command runner
Memcached
KV console
ClickHouse Cloud
Services, databases, SQL editor
Databricks
Clusters, warehouses, catalogs, SQL
Neon
Projects, branches, databases, roles
PlanetScale
Databases and branches
Turso
Groups and databases
CDN / Edge
Cloudflare
23 resource types
Vercel
Projects, deployments, domains, env vars
Netlify
7 resource types
Fly.io
Apps, machines, volumes
VPS
DigitalOcean
Droplets, DOKS, managed databases, Spaces
Hetzner
Servers, volumes, floating IPs, firewalls
Scaleway
Instances, Kapsule K8s, databases, object storage
OVH
Instances, volumes, K8s clusters
Media & Analytics
Cloudinary
Folders, assets, upload presets, transformations
Download Infrawrench
The desktop app for macOS, Windows, and Linux
Local-first and free. Credentials stay encrypted on your machine, and no account is required. Prefer nothing to install?Use the cloud app instead →