The service that does each job on AWS, Azure, Google Cloud and open source, and where they differ.
Git repositories, code review and branch protection.
Infrastructure defined as code, so every environment is reproducible.
Ready-to-code cloud development environments, so a new developer starts in minutes (for example GitHub Codespaces).
AI pair programming in the editor and in code review, licensed per developer (for example GitHub Copilot or Claude Code).
Builds, tests and packages every change.
Stores, versions and scans container images.
Releases builds to environments with approvals and rollback.
Domain name resolution and routing.
Content delivery network that caches content close to users.
Web application firewall that filters malicious HTTP traffic.
Distributes HTTP traffic across healthy compute instances.
Managed HTTP API front door with auth, throttling and routing.
Runs containers without managing servers.
Managed Kubernetes cluster for containerised workloads.
Scales workloads on events such as queue length or stream lag (KEDA).
Event-driven functions billed per invocation and duration.
Managed access to large language models and embedding models.
Runs AI agents, multi-step LLM workflows that call tools and keep state (for example LangGraph).
Point-to-point queue that decouples producers and consumers.
Routes events between services by rules.
Ordered, replayable high-throughput event stream.
Orchestrates multi-step processes with retries and state.
Managed extract-transform-load jobs.
One API in front of many models, with keys, budgets, rate limits, fallbacks and caching (for example LiteLLM).
Screens prompts and answers for prompt injection, harmful content and personal data before they reach the model or the user.
Durable storage for files and blobs.
Managed SQL database.
Serverless key-value / document database with single-digit ms reads.
In-memory cache (Redis-compatible).
Similarity search over embeddings.
Analytical SQL over large datasets.
Very low-cost storage for records that must be kept for years but are rarely read; lifecycle rules move data there as it ages.
User sign-up, sign-in and tokens.
Stores and rotates credentials.
Metrics, logs, dashboards and alarms.
Traces prompts, tool calls, tokens, cost and answer quality in LLM apps (for example Langfuse).
Who may change the cloud - staff sign-in, roles with least privilege, access approved by the cloud architects, and regular access reviews.
Customer-managed encryption keys with rotation and a log of every key use.
A tamper-evident record of who did what in the cloud, kept for the retention period.
Scheduled, versioned backups with point-in-time restore, copied away from the primary account or region.
No services match. Try another search or clear a filter.
Click a service to see why it is there.
Read-only in this demo. Run clarchy serve to edit specs live.
clarchy serve