Featured platform

Automation-first control plane for mission sustainment.

Spire turns approved infrastructure, security, and sustainment procedures into governed runs that validate inputs, execute deterministic workflows, track state, and retain artifacts as evidence.

STIG/OpenSCAP evidence workflow Register assets, run scans, review failed controls, trigger approved automated remediation, and retain reports.
Deployment and reconstitution Use cutsheets, PXE staging, inventory-backed targets, playbooks, validation, and execution recaps.
Governed reusable runbooks Compose functions and cascades with preflight checks, approvals, branching, state, and durable outputs.
Spire security dashboard with STIG and OpenSCAP scan evidence

Dashboard workspace

Run state, evidence, findings, and operator actions stay tied to the same record.

Lifecycle 6 phases

Define, Validate, Execute, Observe, Verify, and Persist keep every run traceable.

Evidence Artifacts

Reports, logs, outputs, and run metadata become durable operational records.

Security OpenSCAP

Structured OSCAP and XCCDF outputs become reviewable findings and remediation inputs.

Governance Approved

Permissions, workflow versions, and operator gates keep high-impact actions controlled.

Deployment model

Supported platforms for governed automation.

Spire keeps the governed run lifecycle consistent across Rancher Government Solutions, VMware, Hyper-V, Red Hat Enterprise Linux, Ubuntu, Windows, Android, and disconnected edge environments. Operators can use the same workspace to provision, validate, remediate, and preserve evidence across different mission platforms.

RGS

Rancher Government Solutions

Coordinate cluster workflows, content delivery, node readiness, and application deployment patterns for controlled environments.

VMware

ESXi, vCenter, and vSAN

Automate ESXi host provisioning, vCenter deployments and configurations, vSAN configuration, distributed switch configuration, and workload configuration.

Hyper-V

Windows virtualization

Support host preparation, VM provisioning, virtual switch configuration, baseline checks, and repeatable validation tasks.

Red Hat Enterprise Linux

Red Hat Enterprise Linux automation

Use Kickstart, PXE staging, package delivery, post-install validation, baseline checks, and repeatable rebuild workflows.

Ubuntu

Ubuntu automation

Use autoinstall, cloud-init, package and content delivery, post-install validation, and controlled sustainment workflows.

Windows

Endpoint and runtime operations

Run Windows-hosted Spire through managed WSL, inspect runtime health with Spire Command, and execute controlled host tasks.

Android

Device and app workflows

Provision devices, apply app and configuration packages, validate state, and include mobile endpoints in orchestrated runbooks.

Edge

Connected and disconnected nodes

Use offline bundles, controlled registries, remote provisioning, image delivery, package updates, and baseline visibility.

Automation preview

Run deployment work as governed, repeatable execution.

Spire keeps target selection, runtime access, execution state, and retained output tied to the same run so platform automation can move from plan to validation without losing operator context.

Target Execute Validate Evidence

Security, compliance, and evidence

Security work stays tied to evidence.

Spire connects STIG/OpenSCAP, Sauron scans, approved remediation, compliance readiness, Red Team validation, and AI Guard visibility in one evidence-backed workflow.

Sauron security dashboard with compliance, findings, and threat visibility
Scanning

STIG/OpenSCAP and Sauron assessments

Normalize failed controls, asset posture, network exposure, and scan evidence.

Remediation

Approved fix paths

Turn findings into reviewed remediation, rechecks, validation, and retained logs.

Readiness

Compliance, Red Team, and AI Guard

Map evidence to HIPAA, PCI-DSS, FISMA, NIST, assessment, and AI-risk views.

Cascades orchestration

Repeatable operations become governed runbooks.

Cascades package recurring security, deployment, and sustainment work into reusable workflows with controlled targets, review points, retries, and retained outputs.

Reusable

Runbooks for common work

Capture repeatable tasks once and run them consistently across teams and sites.

Controlled

Targets, review, and retry

Keep scope, operator gates, run state, and recovery paths visible while work executes.

Recorded

Outputs stay with the run

Preserve logs, artifacts, results, and operator context for handoff or review.

Spire mesh management

SpireLink connects command nodes, suites, and remote sites from one topology view.

SpireLink provides encrypted mesh transport between approved nodes. Operators can use offline enrollment, remotely provision edge nodes, synchronize remote assets, inspect stream context, and preserve topology awareness when connectivity is intermittent.

Spire mesh topology and suite link management workspace
Command topology

Suite and command-node visibility

View command nodes, pinned suite locations, remote nodes, ownership state, paired-node status, and inventory footprint in one map.

Link state

Encrypted mesh transport

Track approved node relationships, degraded or offline links, and remote reachability before dispatching operational work.

Remote nodes

Site health and selected-node context

Inspect role, location, stream availability, update time, health counts, and edge/core context without leaving the topology view.

Asset sync

Offline enrollment, remote provisioning, and sync

Use inventory suites, enrollment bundles, remote provisioning, and asset sync to keep distributed edge nodes ready.

Remote stream ingest

Bring remote kit video into the mesh workspace.

Spire can ingest streams from remote kits or remote Spire instances. Operators can select a deployed instance for kit-level streams or view all available streams across the mesh.

Remote kits Spire instances All streams

KVM and edge HCI

Run KVM infrastructure at the edge.

Overwatch gives compact hyperconverged clusters a browser workspace for host inventory, VM lifecycle actions, storage, virtual networking, consoles, snapshots, migrations, tasks, and alarms.

  • See host health, VM placement, storage, and virtual networks without jumping between tools.
  • Run common actions such as console access, snapshots, migrations, inventory refresh, and task review.
  • Keep alarms and operational context close to the systems that need hands-on attention.
Overwatch KVM cluster management workspace
Cluster view

Hosts, VMs, storage, and networks

See the cluster tree, host health, VM placement, virtual networks, storage, and shared infrastructure from one operator surface.

Operations

VM lifecycle and task control

Run VM actions, snapshots, migrations, console sessions, inventory refresh, tasks, and alarms with auditability.

Edge ready

Field infrastructure control

Support KVM and edge HCI patterns where local visibility, browser-accessible consoles, and durable operations matter.

Android automation

Mobile endpoints become part of the same governed run model.

Spire can provision Android devices, deliver approved app and configuration packages, validate device state, and retain operator-visible evidence alongside the rest of the mission workflow.

Provision

Device onboarding and readiness

Bring Android endpoints into a repeatable workflow with tracked setup, state checks, and operator review.

Configure

Apps and configuration packages

Apply approved applications, settings, and mission packages through controlled automation runs.

Validate

Evidence for mobile operations

Capture outcomes, failures, remediation actions, and run context as part of the same Spire record.

Feature map

Spire connects governed execution, evidence, topology, and sustainment into one operating model.

Security

STIG/OpenSCAP scan-to-remediation workflow

Register assets, execute scans, review failed controls, run approved automated remediation, and retain reports and logs.

RGS

Rancher Government Solutions workflows

Coordinate hardened cluster workflows, content delivery, node readiness, application deployment, and evidence capture.

VMware

ESXi, vCenter, and vSAN workflows

Automate ESXi host provisioning, vCenter deployments and configurations, vSAN configuration, distributed switch configuration, and workload configuration.

Red Hat Enterprise Linux

Red Hat Enterprise Linux bring-up

Support Kickstart, PXE staging, package and content delivery, baseline checks, and post-install validation for repeatable rebuilds.

Ubuntu

Ubuntu bring-up

Support autoinstall, cloud-init, package delivery, controlled registries, validation, and connected or offline sustainment.

Windows

Windows-hosted local operations

Use WSL installer tooling to deploy, sustain, and inspect local Spire runtime health on edge laptops and lab systems.

Android

Android device and app workflows

Provision endpoints, apply approved apps and settings, validate state, and include mobile devices in governed runbooks.

Orchestration

Functions, cascades, approvals, and branching

Build reusable runbooks with preflight checks, runtime credentials, fan-out execution, review points, and retained run records.

SpireLink

Encrypted mesh and topology awareness

Create approved mesh links, use offline enrollment, remotely provision edge nodes, synchronize assets, and track readiness.

Hyper-V

Hyper-V host and VM workflows

Prepare hosts, configure virtual switches, provision VMs, validate baselines, and run repeatable maintenance tasks.

Updates

Controlled updates and sustainment

Stage packages, image updates, offline bundles, baseline checks, and validation records for connected or disconnected operations.

Recovery

Validated recovery readiness

Track restore points, verify recovery paths, preserve run evidence, and report readiness against mission continuity expectations.

Why it matters

Spire turns controlled operations into repeatable mission workflows.

Spire organizes target selection, preflight validation, deterministic execution, findings, artifacts, automated remediation, approvals, and retained evidence into one governed operating surface.

It is built for teams that need traceable security work, repeatable infrastructure builds, connected or disconnected sustainment, role-controlled execution, and a practical bridge between engineering, security, and operations.

Spire demos

Launch the Spire Demo.

Try it out

Step through a live-style workspace for security scans, infrastructure automation, and governed orchestration workflows.