We Shipped ragleap-terraform v0.1.0: How a Solo Dev is Building DevOps for ANY Software — Live-Verified, Not Hype A solo developer released ragleap-terraform v0.1.0, a Terraform module that provisions a local kind Kubernetes cluster and installs the ragleap-observability Helm chart, verified by applying and destroying it on a real Docker Desktop host with Terraform 1.9.8. The release is the ninth library in the RagLeap project, which the developer now describes as "DevOps for ANY software," and ships with acknowledged limitations including local-kind-only support, plain-text credentials in state and kubeconfig, and postgres-exporter disabled by default. I shipped ragleap-terraform v0.1.0 8 hours ago. It's our 9th library. And it changes what RagLeap is. RagLeap started as RAG. Now it's DevOps for ANY software . Here's the honest breakdown — what's live-verified, what's next, and what we won't claim. ragleap-terraform 0.1.0 — kind cluster + full observability stack via Terraform, verified on a real Docker host What it does: A Terraform module that creates a local kind cluster and installs ragleap-observability with helm release . hcl module "kind-cluster" { source = "your-registry/ragleap-terraform" cluster name = "ragleap-dev" grafana admin password = var.grafana password } Variables: cluster name, namespace, install observability, observability chart path, grafana admin password, install postgres exporter default false , helm timeout, kubeconfig path What's inside: examples/kind ships inside the wheel. pip install ragleap-terraform and you have it. Verified — Not Mocked: Applied and destroyed on a real Docker Desktop host with Terraform 1.9.8. All chart pods Ready. Your kubectl context untouched. This is why I say "live-verified". Known Limitations honest : Local kind only. No AWS/GCP/Azure modules yet — those need a real cloud account to verify, not just code. postgres-exporter off by default — needs ragleap-ops and a Secret no chart creates yet. State and kubeconfig hold credentials in plain text. Do not interrupt apply/destroy. This is v0.1.0 for a reason. It works, it's verified, and we're transparent about gaps. ✅ What's Done & Live-Verified So Far 1. ragleap-ops 0.4.1 Helm chart, SecurityContext, read-only root filesystem not neo4j , zero-permission ServiceAccounts, NetworkPolicies, Ingress + TLS, multi-env values, Postgres and neo4j backup/restore with RTO, runbooks drilled against broken clusters. This wasn't helm install and hope. We broke clusters on purpose and drilled restore. 2. ragleap-app-chart 0.2.1 Generic Helm chart for any developer's services. If you have a service, this deploys it with the same security standards as ragleap-ops. This is the "ANY software" part. 3. ragleap-observability 0.6.0 Prometheus v3, Grafana 12, Loki 3.6, Promtail, AlertManager, Slack and email receivers delivery proven against a stand-in , pods-only RBAC, configurable Grafana password, Trivy scans of all images. We started at 383 findings. Down to 14 on four images. postgres-exporter still at 48, Promtail at 86 — next bump cycle will fix. 4. Release Process PyPI keywords, TestPyPI → PyPI, tags, GitHub Releases, docs surfaces. Boring but critical. 🔜 What's Next — Ordered by Level I organize everything by solo → team → corporate. You only need what you need. SOLO DEVELOPER Next 2 weeks : Finish Loki retention → ship 0.6.1 Real Slack/email send — right now only stand-in is proven Automate postgres-exporter Secret + DB role — no chart does it today, it's manual ragleap-ansible for VPS bootstrap never started Image bumps TEAM Next month — needs your sign-off : HPA and PodDisruptionBudgets in ragleap-ops + app-chart Helm chart testing in CI ct + scheduled Trivy job — both edit CI files GitOps ArgoCD or Flux — this is the blocker for canary and blue-green SLO and SLI dashboards ServiceAccounts, RBAC and PDBs for app-chart CORPORATE Later — needs cloud accounts & audits : Cloud Terraform modules AWS, GCP, Azure — they'd be unverified without an account, so I won't fake it Multi-AZ, multi-node, cluster autoscaling blocked — kind is one node Ingress rate limiting + WAF, audit logging, image SBOM + provenance Tracing, SSO for Grafana, chaos testing Compliance SOC 2 — needs external audit, not just engineering Suggested Order: Loki retention → 0.6.1 → HPA/PDB → Ansible → Trivy/ct in CI → GitOps 🎯 The Honest Claim This is important. Even with every item done, the accurate claim is: "enterprise-grade foundations, live-verified" It is NOT "proven at global scale". Everything has run on one node, with single-fault tests. I'm a solo dev building in public from Chennai. I won't claim what I haven't tested. Many startups claim "enterprise-ready" after one Helm chart. I drilled backup/restore against broken clusters before claiming RTO. 📦 Where We Are 46 AI Employees — modular RAG & self-thinking intelligent agents 9 Libraries — 8 Python + 1 Java 45k+ Downloads MIT Licensed, Self-Hosted, BYOK — 17 LLMs + Ollama local 45+ Vector DBs Links: Core: github.com/antonyrag/ragleap-core 17 stars, help us reach 50? Docs: docs.ragleap.com Packages: packages.ragleap.com PyPI: pypi.org/project/ragleap-terraform If you want DevOps that doesn't hide behind marketing, try: pip install ragleap-terraform Feedback welcome. Issues welcome. Stars appreciated. Building in public. Shipping truth. — Antony