Open source · Written in Rust
Describe your infrastructure.
Kōl builds it — securely.
Turn plain-English prompts into role-checked, audited cloud actions across AWS, Azure and GCP. Run it from your terminal, on Lambda, or at the edge.
$
How it works
From intent to audited action in five steps
Every request — from the CLI, an API call or an AI assistant over MCP — runs through the same pipeline. Nothing executes until your identity says it can.
- 01
Prompt
CLI, REST, GraphQL or MCP
- 02
Interpret
LLM → structured action
- 03
Authorize
IAM role + sudo token
- 04
Execute
CLI · Lambda · Edge
- 05
Audit
Log + SNS alerts
Natural-language infrastructure
Prompts like “set up a 3-node GPU cluster for inference” become structured { action, params } plans, previewed with --dry-run before anything runs.
Zero-trust access
Your role is inferred from IAM groups — owner, admin or user. Every action is checked against it before execution. Unauthorized means rejected.
Cross-cloud cohorts
Group people, permissions and resources into cohorts that span AWS, Azure and GCP. Operate on teams and projects, not account boundaries.
Run anywhere
Execute locally from the CLI, on AWS Lambda, in Docker/Kubernetes, or at the edge on Deno Deploy, Cloudflare Workers and Vercel.
Audit by default
Executions, permission denials and sudo usage are logged and can fan out to SNS, email or SMS — compliance without extra wiring.
Workflow engine
Multi-step workflows with smart routing: fast validation at the edge, long-running orchestration on traditional compute.
Security model
Least privilege, inferred — not configured
Kōl reads your role from IAM group membership via STS. Owners can grant temporary, action-scoped escalation with signed sudo tokens — and every use is audited.
| Role | Permissions |
|---|---|
Owner llm-owners |
|
Admin llm-admins |
|
User llm-users |
|
# Owner issues a scoped, time-limited token
kol sudo issue user123 "create_gpu_instance" \
--duration 24 --reason "ML training project"
# User runs a single escalated action with it
kol --token "eyJ0eXAiOiJKV1Qi…" --prompt "Create GPU instance"Scoped
Only the listed actions
Time-bound
Expires automatically
Audited
Every use triggers alerts
Deploy anywhere
Edge for speed, regional for power
Kōl’s hybrid router sends quick validation and cost estimates to the edge, and long-running, multi-step workflows to traditional compute.
- Status
- Stable
- Latency
- Local
- Best for
- Interactive use, dry runs, scripting
cargo install --git https://github.com/Nuvai/Kol kol-cli
kol identity
kol --dry-run --prompt "Set up a GPU cluster"Integrations
Plugs into the stack you already run
Clouds
LLM providers
Protocols
Data sources & sinks
Try it
Things you can ask Kōl
Create
- “Create a VPC with public and private subnets”
- “Set up a 3-node Kubernetes cluster”
- “Launch a GPU instance for deep learning”
Manage
- “List all running EC2 instances”
- “Show S3 buckets with public access”
- “Terminate instances older than 7 days”
Optimize
- “Find unused EBS volumes”
- “Recommend an instance type for my ML workload”
- “Show monthly cost breakdown by service”
Getting started
Up and running in four steps
- 1
Install
Build from source with Cargo (Rust 1.70+).
shellcargo install --git https://github.com/Nuvai/Kol kol-cli - 2
Configure
Point Kōl at your AWS account and LLM provider.
shellaws configure && cp config.example.toml config.toml - 3
Check identity
See the role Kōl inferred from your IAM groups.
shellkol identity - 4
Prompt
Describe what you need. Preview first.
shellkol --dry-run --prompt "Launch a training instance"
Ready to talk to your cloud?
Kōl is open source and MIT licensed. Read the docs, star the repo, or open an issue.