Integrations

Every system Identrail watches today.

Each connector is read-only by default. New integrations land in the open-source repo first, then in the hosted product. Need a stack we don't list yet? Open an issue or talk to us — we prioritise based on real demand.
AWS IAM
Cloud IAM
GA

IAM roles, policies, trust relationships, AssumeRole chains, Identity Center, federated principals.

Kubernetes
Container & orchestration
GA

Service accounts, role/clusterrole bindings, pod-to-SA mapping, workload identity federation (EKS/GKE).

GitHub Actions
CI/CD & SCM
GA

GitHub Actions OIDC stitching, environment trust policies, repo-level permission graphs.

OpenID Connect
Identity provider
GA

Generic OIDC issuer ingestion. JWT claim resolution into target trust policies.

Terraform
Infrastructure-as-code
Beta

Plan-time analysis: identifies trust-policy diffs against the live graph before apply.

Docker
Container & orchestration
GA

Image registry credentials, build-time identity resolution, Docker Hub OIDC.

PostgreSQL
Data store
GA

Resource-side reachability: catalogs tables/schemas reachable through resolved identity paths.

Prometheus
Observability
GA

Emits scan timing, finding counts, severity distribution, and connector health metrics.

Google Cloud IAM
Cloud IAM
Roadmap

Service accounts, workload identity federation, organisation policy resolution. Tracking issue in repo.

Azure AD / Entra
Cloud IAM
Roadmap

Managed identities, federated credentials, role assignments, conditional access for service principals.

HashiCorp Vault
Identity provider
Roadmap

AWS auth backend mapping, Kubernetes auth backend mapping, dynamic credential issuance into the graph.

Don't see your stack?

Tell us what to build next.

Connector priority is set publicly in the repo. Upvote what you need or open a new issue with your use case.

See the connector graph for your environment.

A free read-only scan returns the trust paths your stack actually exposes today, not what a brochure claims.