Open source, built in public

Developer tooling and platforms, engineered to be trusted.

We build local-first developer tools, Google Cloud foundations as code, and AI agents that open pull requests under their own names. All of it ships from one public monorepo, through one merge queue.

agent session
# Wren takes its own identity, not a human's
$ eval "$(bazel run //tools/agent-app -- env wren)"
$ gh pr create --fill
  ✓ opened by vitruvian-wren-agent[bot]

# A different agent reviews it
  ✓ approved by vitruvian-aegis-agent[bot]

$ bazel run //tools/watch-pr
  ● bazel test //...       passed
  ● merge queue           landed
  ● post-merge pipeline   running
$ 
1 public monorepo for every app, pipeline and cluster
10 standalone repos, mirrored one way from it
10 AI agents, each with its own GitHub identity
0 service-account keys: cloud deploys use workload identity
Projects

Tools we use every day, released for everyone.

Each one started as something we needed. They are maintained in the monorepo and published to their own repositories.

All projects

devx

Released

A local development orchestrator. One CLI provisions container VMs, ephemeral databases and cloud emulators, local K3s clusters and Cloudflare tunnel ingress, and starts everything in dependency order.

brew install VitruvianSoftware/tap/devx
  • Go
  • Lima
  • Kubernetes
  • Cloudflare

homelab

Released

Declarative multi-node K3s clusters on macOS. Describe the nodes in one file and homelab provisions Lima VZ virtual machines, networking and the cluster to match.

brew install VitruvianSoftware/tap/homelab
  • Go
  • K3s
  • Lima VZ
  • macOS

pulumi-library

Released

Reusable Pulumi ComponentResources for Google Cloud, published as Go and TypeScript packages: projects, networks, IAM, logging and the rest of an enterprise landing zone.

  • Pulumi
  • Go
  • TypeScript
  • GCP

mcp-slack

Mirrored

A Slack MCP server with dual-token auth: around forty tools covering channels, threads, search, files, user groups and Canvas editing, acting as the bot or as you.

  • TypeScript
  • MCP
  • Slack

NexusAgent

Mirrored

A macOS menu bar app and Telegram bot that forwards your messages to a locally installed AI coding CLI, so a full agent session is reachable from your phone.

  • TypeScript
  • Swift
  • Telegram

Sign in with an OAuth provider and see exactly what came back: decoded tokens, claims, scopes and user info. React and Express in one container on Cloud Run.

  • TypeScript
  • React
  • Cloud Run
How we ship

One path to production, for people and agents alike.

Every change to our cloud systems takes this route, and agents have no other.

  1. Isolated worktree

    Every change starts on its own branch in its own git worktree, so parallel sessions never share a checkout.

  2. Hermetic build

    One Bazel graph builds and tests Go, TypeScript, Python, Kotlin and Swift, so a laptop and CI agree.

  3. Independent review

    A second identity approves. Agents review each other as GitHub Apps; nobody approves their own work.

  4. Merge queue

    The queue tests each change against the latest main before it lands. Agents never merge around it.

  5. Deploy and mirror

    Pipelines deploy with short-lived credentials, and Copybara exports each project to its public repository.

How the platform works

Principles

Named for Vitruvius, who said a building must be strong, useful and beautiful.

Two thousand years later it is still a good test for software.

Firmitas Strength

Reproducible builds, everything as code, and a guard written for every incident so the same failure cannot happen twice.

Utilitas Utility

We build what removes friction from our own work first: one command to bring up a stack, one to tear it down.

Venustas Beauty

Clear interfaces, honest documentation, and one design language shared across our apps, from this site to the Android remote.

Writing

From the engineering log.

All posts
  • Every AI agent gets its own GitHub identity

    Ten coding agents work in our monorepo. Until recently, GitHub saw all of them as one person, so none of them could review another's work. Here is how we gave each agent its own GitHub App, what we had to...

    Read
  • The Reality of Agentic Coding Architecture

    The era of “chat wrappers” is completely dead. As of Q2 2026, the transition from basic text-generation LLMs to fully autonomous agentic code workflows is accelerating rapidly. However, a stark divide is emerging between teams trying to prompt their way...

    Read
  • Introducing ADK Agents: Your AI-Powered DevOps Companion

    Meet ADK Agents - the intelligent DevOps assistant that understands your codebase, executes commands safely, and helps you ship better software faster. Built on Google's ADK framework with developer productivity at its core.

    Read

Read the code, not the brochure.

Every tool, pipeline, guardrail and incident fix described on this site is in vitruvian-core, in the open.