Open source · Written in Rust

Describe your infrastructure.
Kōl builds it — securely.

Turn plain-English prompts into role-checked, audited cloud actions across AWS, Azure and GCP. Run it from your terminal, on Lambda, or at the edge.

~/infra — kol

How it works

From intent to audited action in five steps

Every request — from the CLI, an API call or an AI assistant over MCP — runs through the same pipeline. Nothing executes until your identity says it can.

  1. 01

    Prompt

    CLI, REST, GraphQL or MCP

  2. 02

    Interpret

    LLM → structured action

  3. 03

    Authorize

    IAM role + sudo token

  4. 04

    Execute

    CLI · Lambda · Edge

  5. 05

    Audit

    Log + SNS alerts

Natural-language infrastructure

Prompts like “set up a 3-node GPU cluster for inference” become structured { action, params } plans, previewed with --dry-run before anything runs.

Zero-trust access

Your role is inferred from IAM groups — owner, admin or user. Every action is checked against it before execution. Unauthorized means rejected.

Cross-cloud cohorts

Group people, permissions and resources into cohorts that span AWS, Azure and GCP. Operate on teams and projects, not account boundaries.

Run anywhere

Execute locally from the CLI, on AWS Lambda, in Docker/Kubernetes, or at the edge on Deno Deploy, Cloudflare Workers and Vercel.

Audit by default

Executions, permission denials and sudo usage are logged and can fan out to SNS, email or SMS — compliance without extra wiring.

Workflow engine

Multi-step workflows with smart routing: fast validation at the edge, long-running orchestration on traditional compute.

Security model

Least privilege, inferred — not configured

Kōl reads your role from IAM group membership via STS. Owners can grant temporary, action-scoped escalation with signed sudo tokens — and every use is audited.

RolePermissions

Owner

llm-owners

  • ✓Full access
  • ✓Create & manage cohorts
  • ✓Issue sudo tokens

Admin

llm-admins

  • ✓Manage resources within delegated scope
  • ✓Use granted sudo tokens

User

llm-users

  • ✓Perform explicitly allowed actions
  • ✓Read within assigned cohorts
sudo tokens
# Owner issues a scoped, time-limited token
kol sudo issue user123 "create_gpu_instance" \
  --duration 24 --reason "ML training project"

# User runs a single escalated action with it
kol --token "eyJ0eXAiOiJKV1Qi…" --prompt "Create GPU instance"
  • Scoped

    Only the listed actions

  • Time-bound

    Expires automatically

  • Audited

    Every use triggers alerts

Deploy anywhere

Edge for speed, regional for power

Kōl’s hybrid router sends quick validation and cost estimates to the edge, and long-running, multi-step workflows to traditional compute.

Status
Stable
Latency
Local
Best for
Interactive use, dry runs, scripting
shell
cargo install --git https://github.com/Nuvai/Kol kol-cli
kol identity
kol --dry-run --prompt "Set up a GPU cluster"

Integrations

Plugs into the stack you already run

Clouds

AWSAzureBetaGCPBeta

LLM providers

AnthropicOpenAIGeminiMistralBedrock

Protocols

RESTMCPGraphQLgRPCWebSocketComing soon

Data sources & sinks

NotionAirtableGoogle SheetsSupabaseDynamoDBSQLiteCSV

Try it

Things you can ask Kōl

Create

  • “Create a VPC with public and private subnets”
  • “Set up a 3-node Kubernetes cluster”
  • “Launch a GPU instance for deep learning”

Manage

  • “List all running EC2 instances”
  • “Show S3 buckets with public access”
  • “Terminate instances older than 7 days”

Optimize

  • “Find unused EBS volumes”
  • “Recommend an instance type for my ML workload”
  • “Show monthly cost breakdown by service”

Getting started

Up and running in four steps

  1. 1

    Install

    Build from source with Cargo (Rust 1.70+).

    shell
    cargo install --git https://github.com/Nuvai/Kol kol-cli
  2. 2

    Configure

    Point Kōl at your AWS account and LLM provider.

    shell
    aws configure && cp config.example.toml config.toml
  3. 3

    Check identity

    See the role Kōl inferred from your IAM groups.

    shell
    kol identity
  4. 4

    Prompt

    Describe what you need. Preview first.

    shell
    kol --dry-run --prompt "Launch a training instance"

Ready to talk to your cloud?

Kōl is open source and MIT licensed. Read the docs, star the repo, or open an issue.