Building meters for the engineering risks nobody can see
Kodebeat turns twenty years of building systems into open-source instruments, each with a paper explaining its numbers.
Services
Every service starts the same way: install open-source instruments, get a baseline, and only then change anything.
Secure development, from prompt to production
Developers use AI agents and builds pull a thousand dependencies. The rails go at both ends: a gateway that meters and redacts AI traffic, jails and per-command risk scoring for the agents, and a hardened supply chain with signed images, SBOMs and no secrets left in git history.
Cloud efficiency and GreenOps
Cost, energy and carbon per team and per workload, measured directly on the cluster and turned into a savings roadmap. The emissions figures come with a documented methodology, which is what makes them usable for CSRD reporting.
Resilience proved rather than assumed
The backup restored on a schedule, the rewrite proved on mirrored traffic before it serves any, the evidence captured before the fix destroys it, and requests rightsized from what the cluster actually used. Each claim arrives as a dated run somebody else can check.
What the codebase is worth before you bet on it
A model wrote most of the diff, and instincts trained on human mistakes do not fire on it. Repository scoring with every factor shown and nothing counted that could not be checked, architecture documentation computed from the tree rather than written, and review procedures for code no human wrote.
The toolbox
All public, falling into groups. Each one exists because a real question kept going unanswered.
Secure AI development
metered, redacting AI gateway, agent jail, network sandbox, command risk scoring, secret scanning, what this machine can run
GreenOps
the measurement stack, energy linting, carbon per build, carbon budgets in CI, SCI to ISO/IEC 21031, cleanest region to run in, the long version
terraform-kubernetes-greenops greenlint carbon-badge carbon-budget-action sci-disclose carbon-region-picker the GreenOps book
Supply chain and hardening
one scanner bundle, what changed in the SBOM, the hardened Dockerfile, as a diff, unsigned images blocked, least privilege from real usage, RBAC drift, everything that expires
security-scanner-toolbox sbom-diff dockerfile-hardener cosign-verify-init iam-shrink rbac-auditor expiry-radar
Operational meters
CI toil priced in euros, dependencies worth worrying about, what moved the cloud bill, rightsizing as committable YAML, a rewrite proved on live traffic, backups restored on a schedule, a repo score that means something
toil-audit depwatch cost-diff k8s-rightsizer-report dark-canary backup-verify gradebook
By theme: AI infrastructure GreenOps security & supply chain cloud cost platform & SRE repo intelligence teaching & writing
nginx-lua has 3.5 million Docker Hub pulls and 54 public repositories building on it. The browser-based tools run at tools.fabiocicerchia.it with nothing to install.
Some of the tools became products Kodebeat builds and operates: castellan, a managed cache and WAF; lastresort, dated evidence that backups restore; stillvalid, everything about to expire in one list; boneyard, what a dependency bump changed; proofhouse, one scorecard across every repository; ephemera, a cluster audited against compliance frameworks; paved, a white-label developer platform; manager-os, a private desk for management questions; mockterview, interview rehearsal; fleetmux, a console for a fleet of coding agents; and the newsletters, briefings built from primary sources. Pricing is on each product's own site, and the products page marks the status of each.
Start with a paper
Every tool ships with one: the problem, the method, the numbers, and what the tool deliberately does not do. The book is free; the papers cost an email address.
Read the papers or send a request