01 · CATALOG

The map every module uses as its address.

Domain, System, Component and environment. Releases, incidents, network access and infrastructure all point to the same Component — not to four records someone has to reconcile.

Opens a WhatsApp chat. Prefer email? heimdall@yops.cloud

What it does

What belongs to what

A Domain is a business area, such as payments. A System is a product inside it, such as checkout. A Component is what gets deployed: an API, a worker. Infrastructure is a Resource, owned by a System. The environment cuts across every level.

What goes down together

Every dependency between Components has a type — runtime, build, test or data — and a circular dependency is refused. heimdall component blast-radius lists every Component that goes down if this one does, directly or indirectly, with the distance of each. Before a maintenance window, that is the list of who to tell.

What isn't deleted by accident

A Component that another depends on cannot be deleted. Neither can a System with Components or Resources inside it, nor a Domain with Systems. Deleting never takes anything with it.

What is recorded

Creating, changing and deleting a Domain, System or Component, and adding or removing a dependency, go into the organization's audit trail, with who did it.

How it works

The catalog is written through the CLI or the API, or imported from another Heimdall installation. The other modules don't store a service's name as text: they store a reference to a Component, System or environment in the same organization, and the database refuses a reference that doesn't exist.

TERMINALheimdall component
heimdall component blast-radius 218d2d21-d628-40fc-8bd8-8cd2de4528ab
SERVICE_ID                            SERVICE_NAME     DEPTH
2a5e9fa9-e606-4306-883e-842f4082901d  checkout-api     1
56dd2bfa-0988-448e-9057-e2e54fa6b3f7  payments-worker  1

heimdall graph critical
COMPONENT             TIER      DIRECT_DEPENDENTS  TRANSITIVE_DEPENDENTS
Auth Service          critical  4                  6
User Profile          high      3                  3
Notification Service  medium    1                  3
Billing Service       high      2                  2
ledger                high      2                  2

heimdall dependency add --component 218d2d21-d628-40fc-8bd8-8cd2de4528ab --depends-on 2a5e9fa9-e606-4306-883e-842f4082901d --type runtime
Error: CYCLIC_DEPENDENCY: adding this dependency would create a cycle

heimdall component delete 218d2d21-d628-40fc-8bd8-8cd2de4528ab --yes
Error: HAS_DEPENDENTS: component has dependents and cannot be deleted
Real output of heimdall component blast-radius and heimdall graph critical.

Where the data lives

Everything runs in your infrastructure. The split below matters inside your company: it says who on your team can reach what.

Catalog: where the data lives
IN THE API, WHICH IS YOURSIN THE AGENT

Domains, Systems, Components, Resources, environments and dependencies. It is governance metadata: name, tier, language, tags, links, the owning group.

Nothing from the catalog. What is sensitive and tied to it stays in the Agent and in your cloud account: secret values, Terraform state.

Each organization sees only its own catalog: the isolation is enforced by the database, not by the screen.

See security

Who approves what

Catalog: who approves what
ACTIONWHO
Read the catalog every member
Create, change and delete owner and admin, by default. An organization policy changes that

With the other modules

  • 02

    Infrastructure Manager

    Every Resource belongs to a System, and the cloud account it comes from is the System's, the Domain's or the organization's — whichever is closest.

  • 03

    Secret Manager

    A secret can be linked to the Components that use it.

  • 05

    Internal app access

    No service is reachable through the edge unless it is in the catalog, with a Component and an environment.

  • 06

    Release Manager

    Target, approvers, window and freeze are set per Component and per environment.

  • 07

    Incident Manager

    An incident is about a Component, a System, a database or a Resource, and a rollback opens the incident on the Component it rolled back.

Talk to the people who build Heimdall.

Tell us how your engineers store secrets and reach the database today. We'll answer with what Heimdall would put under rules first, and how the deployment would get there.

Talk to engineering

Opens a WhatsApp chat. Prefer email? heimdall@yops.cloud