Define, Validate, Execute, Observe, Verify, and Persist keep every run traceable.
Featured platform
Automation-first control plane for mission sustainment.
Spire turns approved infrastructure, security, and sustainment procedures into governed runs that validate inputs, execute deterministic workflows, track state, and retain artifacts as evidence.
Dashboard workspace
Run state, evidence, findings, and operator actions stay tied to the same record.
Reports, logs, outputs, and run metadata become durable operational records.
Structured OSCAP and XCCDF outputs become reviewable findings and remediation inputs.
Permissions, workflow versions, and operator gates keep high-impact actions controlled.
Deployment model
Supported platforms for governed automation.
Spire keeps the governed run lifecycle consistent across Rancher Government Solutions, VMware, Hyper-V, Red Hat Enterprise Linux, Ubuntu, Windows, Android, and disconnected edge environments. Operators can use the same workspace to provision, validate, remediate, and preserve evidence across different mission platforms.
Rancher Government Solutions
Coordinate cluster workflows, content delivery, node readiness, and application deployment patterns for controlled environments.
ESXi, vCenter, and vSAN
Automate ESXi host provisioning, vCenter deployments and configurations, vSAN configuration, distributed switch configuration, and workload configuration.
Windows virtualization
Support host preparation, VM provisioning, virtual switch configuration, baseline checks, and repeatable validation tasks.
Red Hat Enterprise Linux automation
Use Kickstart, PXE staging, package delivery, post-install validation, baseline checks, and repeatable rebuild workflows.
Ubuntu automation
Use autoinstall, cloud-init, package and content delivery, post-install validation, and controlled sustainment workflows.
Endpoint and runtime operations
Run Windows-hosted Spire through managed WSL, inspect runtime health with Spire Command, and execute controlled host tasks.
Device and app workflows
Provision devices, apply app and configuration packages, validate state, and include mobile endpoints in orchestrated runbooks.
Connected and disconnected nodes
Use offline bundles, controlled registries, remote provisioning, image delivery, package updates, and baseline visibility.
Automation preview
Run deployment work as governed, repeatable execution.
Spire keeps target selection, runtime access, execution state, and retained output tied to the same run so platform automation can move from plan to validation without losing operator context.
Security, compliance, and evidence
Security work stays tied to evidence.
Spire connects STIG/OpenSCAP, Sauron scans, approved remediation, compliance readiness, Red Team validation, and AI Guard visibility in one evidence-backed workflow.
STIG/OpenSCAP and Sauron assessments
Normalize failed controls, asset posture, network exposure, and scan evidence.
Approved fix paths
Turn findings into reviewed remediation, rechecks, validation, and retained logs.
Compliance, Red Team, and AI Guard
Map evidence to HIPAA, PCI-DSS, FISMA, NIST, assessment, and AI-risk views.
Cascades orchestration
Repeatable operations become governed runbooks.
Cascades package recurring security, deployment, and sustainment work into reusable workflows with controlled targets, review points, retries, and retained outputs.
Runbooks for common work
Capture repeatable tasks once and run them consistently across teams and sites.
Targets, review, and retry
Keep scope, operator gates, run state, and recovery paths visible while work executes.
Outputs stay with the run
Preserve logs, artifacts, results, and operator context for handoff or review.
Spire mesh management
SpireLink connects command nodes, suites, and remote sites from one topology view.
SpireLink provides encrypted mesh transport between approved nodes. Operators can use offline enrollment, remotely provision edge nodes, synchronize remote assets, inspect stream context, and preserve topology awareness when connectivity is intermittent.
Suite and command-node visibility
View command nodes, pinned suite locations, remote nodes, ownership state, paired-node status, and inventory footprint in one map.
Encrypted mesh transport
Track approved node relationships, degraded or offline links, and remote reachability before dispatching operational work.
Site health and selected-node context
Inspect role, location, stream availability, update time, health counts, and edge/core context without leaving the topology view.
Offline enrollment, remote provisioning, and sync
Use inventory suites, enrollment bundles, remote provisioning, and asset sync to keep distributed edge nodes ready.
Remote stream ingest
Bring remote kit video into the mesh workspace.
Spire can ingest streams from remote kits or remote Spire instances. Operators can select a deployed instance for kit-level streams or view all available streams across the mesh.
KVM and edge HCI
Run KVM infrastructure at the edge.
Overwatch gives compact hyperconverged clusters a browser workspace for host inventory, VM lifecycle actions, storage, virtual networking, consoles, snapshots, migrations, tasks, and alarms.
- See host health, VM placement, storage, and virtual networks without jumping between tools.
- Run common actions such as console access, snapshots, migrations, inventory refresh, and task review.
- Keep alarms and operational context close to the systems that need hands-on attention.
Hosts, VMs, storage, and networks
See the cluster tree, host health, VM placement, virtual networks, storage, and shared infrastructure from one operator surface.
VM lifecycle and task control
Run VM actions, snapshots, migrations, console sessions, inventory refresh, tasks, and alarms with auditability.
Field infrastructure control
Support KVM and edge HCI patterns where local visibility, browser-accessible consoles, and durable operations matter.
Android automation
Mobile endpoints become part of the same governed run model.
Spire can provision Android devices, deliver approved app and configuration packages, validate device state, and retain operator-visible evidence alongside the rest of the mission workflow.
Device onboarding and readiness
Bring Android endpoints into a repeatable workflow with tracked setup, state checks, and operator review.
Apps and configuration packages
Apply approved applications, settings, and mission packages through controlled automation runs.
Evidence for mobile operations
Capture outcomes, failures, remediation actions, and run context as part of the same Spire record.
Feature map
Spire connects governed execution, evidence, topology, and sustainment into one operating model.
STIG/OpenSCAP scan-to-remediation workflow
Register assets, execute scans, review failed controls, run approved automated remediation, and retain reports and logs.
Rancher Government Solutions workflows
Coordinate hardened cluster workflows, content delivery, node readiness, application deployment, and evidence capture.
ESXi, vCenter, and vSAN workflows
Automate ESXi host provisioning, vCenter deployments and configurations, vSAN configuration, distributed switch configuration, and workload configuration.
Red Hat Enterprise Linux bring-up
Support Kickstart, PXE staging, package and content delivery, baseline checks, and post-install validation for repeatable rebuilds.
Ubuntu bring-up
Support autoinstall, cloud-init, package delivery, controlled registries, validation, and connected or offline sustainment.
Windows-hosted local operations
Use WSL installer tooling to deploy, sustain, and inspect local Spire runtime health on edge laptops and lab systems.
Android device and app workflows
Provision endpoints, apply approved apps and settings, validate state, and include mobile devices in governed runbooks.
Functions, cascades, approvals, and branching
Build reusable runbooks with preflight checks, runtime credentials, fan-out execution, review points, and retained run records.
Encrypted mesh and topology awareness
Create approved mesh links, use offline enrollment, remotely provision edge nodes, synchronize assets, and track readiness.
Hyper-V host and VM workflows
Prepare hosts, configure virtual switches, provision VMs, validate baselines, and run repeatable maintenance tasks.
Controlled updates and sustainment
Stage packages, image updates, offline bundles, baseline checks, and validation records for connected or disconnected operations.
Validated recovery readiness
Track restore points, verify recovery paths, preserve run evidence, and report readiness against mission continuity expectations.
Why it matters
Spire turns controlled operations into repeatable mission workflows.
Spire organizes target selection, preflight validation, deterministic execution, findings, artifacts, automated remediation, approvals, and retained evidence into one governed operating surface.
It is built for teams that need traceable security work, repeatable infrastructure builds, connected or disconnected sustainment, role-controlled execution, and a practical bridge between engineering, security, and operations.
Spire demos
Launch the Spire Demo.
Step through a live-style workspace for security scans, infrastructure automation, and governed orchestration workflows.