Every device you run.
One governed shell.

Hypervisors, GPU nodes, switches, PDUs, databases and services across every
site — reachable from one list, with the infrastructure context already on
screen and Lumi proposing the next command.
No jump box hunt, no
spreadsheet of IPs, no shared root password.

>_Terminal16
⌕
Site
Type
>_api-prod-7 — Hypervisors
no IP · ssh:22 (default)
✎
>_checkout-api — Service
no IP · ssh:22 (default)
✎
>_db-main-1 — Hypervisors
no IP · ssh:22 (default)
✎
>_edge-gateway — Load Balancers
no IP · ssh:22 (default)
✎
>_eval-mistral-large — Job
no IP · ssh:22 (default)
✎
>_h100-node-1 — Hypervisors
no IP · ssh:22 (default)
✎
>_h100-node-1 · GPU3 — Gpu
no IP · ssh:22 (default)
✎
>_h100-node-2 — Hypervisors
no IP · ssh:22 (default)
✎
>_ib-spine-1 — Switches
no IP · ssh:22 (default)
✎
>_lb-tor-1 — Switches
no IP · ssh:22 (default)
✎
>_pdu-A1 — PDUs
no IP · ssh:22 (default)
✎
>_postgres-main — Database
no IP · ssh:22 (default)
✎
>_payments — Service
no IP · ssh:22 (default)
✎
>_train-llama-70b — Job
no IP · ssh:22 (default)
✎
>_maestro-deploy-role — Iam Role
no IP · ssh:22 (default)
✎
>_legacy-circleci-role — Iam Role
no IP · ssh:22 (default)
✎
checkout-api×h100-node-1×lb-tor-1×postgres-main×
postgres-main · site_us_east_1 · Databaserecorded
postgres 15.61,392 qpssite site_us_east_1
› resolving postgres-main in site_us_east_1…
› issuing just-in-time credential · expires 60m
› session recording started
✓ connected · RDS
 
ops@postgres-main:~$ psql -c "select count(*) from pg_stat_activity"
count
-------
187
psql -c "select count(*) from pg_stat_activity"uptimedf -hcontextlumi ask "is this host healthy?"
ops@postgres-main:~$

Click a device · open up to 4 sessions as tabs · type commands · ↑ for history

REACHES EVERYTHING DISCOVERED IN YOUR ESTATE

THE PROBLEM
Getting a shell takes longer than using it.

At 2am the fix is usually one command. The ten minutes before it are spent working out where the box is, how to reach it, and which credential still works. Race the two and see

02:14
Which host is it on?
Search the CMDB, then Slack, then the wiki page from 2023.

02:18

What’s the IP now?
It moved during the last migration. Nobody updated the sheet.
02:21
Which jump box, which key?
The bastion for dc-west, a key in someone’s home directory.
TIME TO FIRST COMMAND · checkout-api
The old way10:14
✓search CMDB, Slack and the wiki2:10
✓find the current IP — it moved2:40
✕ssh via bastion-dcw → no route to host3:30
✕ssh via bastion-use1 → permission denied4:50
✓ask #infra which key is current9:40
✓connected — with no context10:14
With Lumi Terminal0:02
✓click checkout-api0:00
✓just-in-time credential issued0:01
✓connected · context loaded · recorded0:02
Lumi reached a shell 307× faster — with context loaded and the session already on the record.
AI + TERMINAL WORKFLOW
You bring the question. Lumi brings the command.

Ask in plain language inside the session. Lumi reads the host, proposes the exact command, tells you whether it’s safe before it runs, and explains the output. Pick a question and press the buttons yourself.

1

Proposed, never assumed
Every command is shown before it executes. You run it, edit it, or skip it.

2

Classified before it runs
Read-only goes straight through. Anything that writes is flagged and gated.

3

Output, interpreted
The line that matters, and what it means for this incident.

4

Hands off to a Coworker
When it’s bigger than one host, the SRE Orchestrator takes it wider.
AI + Terminal Workflow
checkout-api· site_us_east_1 · Servicerecorded
?why does this pod keep restarting?
LLUMI · PROPOSED
Four OOMKills in the last hour on this deployment. Let me check memory usage against the limit.
kubectl top pod -n payments -l app=checkout-apiread-only · safeRunEdit
ops@checkout-api:~$ kubectl top pod -n payments -l app=checkout-api
NAME CPU MEMORY
checkout-api-7f9c-x2k 412m 251Mi
checkout-api-7f9c-q8m 398m 256Mi
LLUMI · EXPLAINED
Both pods are pinned at the 256Mi limit. It started with v2.14.3 — the pricing-engine integration loads the full catalog into memory. Raising the limit is the fast fix; paginating the fetch is the real one.
kubectl set resources deploy/checkout-api --limits=memory=512Miwrites · prod · needs approvalRequest approvalEdit
› approval requested · service owner notified · SRE Orchestrator informed
Ssara.lee approved · recorded
✓ deployment/checkout-api resources updated
✓ rollout complete · 0 OOMKills in 5m
>_h100-node-1HYPERVISORSsite_dc_west⚠ 1 issue
GPU UTIL · LIVE80.8%
TEMP82°C
ECC 24H14
MODELPowerEdge XE9680
GPUS8× H100 SXM5 80GB
RUNNINGtrain-llama-70b
CABINET · PDUrack-A1 · pdu-A1
OPEN INVESTIGATIONGPU thermal throttling
LAST CHANGEBIOS 2.4.1 · 12d ago
A REBOOT WOULD TOUCHtrain-llama-70b · 16 GPUml-platform serviceGPU0–GPU7rack-A1 power budget
Loaded before your first keystroke — from the estate model, telemetry and investigations.
INFRASTRUCTURE CONTEXT
Know what you’re logged into before you type.

Every session opens with the device’s facts, live metrics, what’s running on it, and whether there’s already an open investigation. You stop being the engineer who didn’t know the node was mid-training-run.

1

Facts from the estate model
Model, firmware, cabinet, power — normalised from every discovery source.

2

Live health, not a snapshot
Utilization, temperature and error counts streaming while you work.

3

What a reboot would touch
The jobs, services and neighbours that depend on this box.
MULTI-ENVIRONMENT VISIBILITY
Datacenter and cloud in the same
list.
One session plane, three ways in. Click an environment to trace how the connection
actually reaches it.
youbrowser · SSO Lumi session planeJIT creds · RBAC · record site collectoroutbound only site_dc_westh100 · ib-spine · pdu cloud APIscoped IAM site_us_east_1checkout · payments CERNE relaybrokered · audited isolated siteno direct exposure
site_us_east_1 · via cloud API — scoped IAM credentialsno inbound firewall holes on any site
site_dc_west

Your datacenter

Hypervisors, GPU nodes, switches and PDUs reached through the site collector — outbound only.

h100-node-1 · ib-spine-1
pdu-A1 · db-main-1
site_us_east_1

Your cloud

Services, load balancers, databases and IAM roles through the provider API with scoped credentials.

checkout-api · edge-gateway
postgres-main · payments
via CERNE

Isolated sites

Boundary-restricted environments brokered through the control plane on an audited path.

relayed sessions
no direct exposure
ONE SEARCH · EVERY SITE ⌕ payments 1 match · 1 site
>_payments— Servicesite_us_east_1
OPERATIONAL ACCESS
Root access, without a shared root
password.
Every command is classified and checked against your role and policy before it
touches the box. Try it — pick a role, then a command.
1 · YOUR ROLE
vieweroperatoradmin
2 · TRY A COMMAND ON checkout-api · prod
kubectl get pods -n paymentsread-only
tail -f /var/log/checkout.logread-only
kubectl scale deploy/checkout-api --replicas=8write
systemctl restart nginxwrite
kubectl delete ns paymentsdestructive
rm -rf /var/lib/dockerdestructive
policy engine · evaluationheld for approval
1parsetokens ok
2classifywrite · service
3RBACoperator · allowed
4guardrail policyprod write → approval
5auditrequest logged
Held for approvalWrites on production need the service owner. Request sent; runs the moment it's approved.
Just-in-time credentials
Issued when the session opens, revoked when it closes. Nothing lives in a home directory.
RBAC per device
Your role decides which hosts you can reach and whether you get a read-only shell.
Session recording
Every session recorded and replayable — the answer to “who ran that?”
Gated destructive commands
Writes on production pause for approval, under the same guardrails as agents.
SESSION REPLAY
“Who ran that?” now has an answer.
Every session is recorded against a named person and replayable keystroke by
keystroke. Scrub to any moment — amber markers are the commands that changed
something, with who approved them.
replay · s_4f21· priya@acme.com · db-main-1 · 02:31 UTCrecorded
› session opened · priya@acme.com · just-in-time credential · expires 60m
priya@db-main-1:~$ uptime
02:31:06 up 42 days, load average: 7.82, 6.10, 4.02
priya@db-main-1:~$ iostat -x 1 1 | grep nvme
nvme1n1 r/s 812 w/s 2,104 util 97.4%
priya@db-main-1:~$ psql -c "select pid,state,wait_event from pg_stat_activity where state='active'"
pid | state | wait_event
88213 | active | DataFileRead
88240 | active | DataFileRead
LUMI · SUGGESTEDAutovacuum on orders is running during peak and saturating IO. Throttle its cost delay rather than killing it.
priya@db-main-1:~$ psql -c "alter table orders set (autovacuum_vacuum_cost_delay = 20)"
◷ writes to production · approval requested from service owner
✓ approved by sara.lee · 02:33:12
ALTER TABLE
priya@db-main-1:~$ iostat -x 1 1 | grep nvme
nvme1n1 util 41.8%
priya@db-main-1:~$ systemctl reload pgbouncer
✓ approved by sara.lee
priya@db-main-1:~$ exit
› session closed · 4m12s · 7 commands · 2 changes approved · archived
04:12 / 04:12
read-only commandchange · approveddrag the bar to scrub
BY THE NUMBERS
What changes the day you switch
it on.
0 s
from click to an authenticated, recorded shell
0
shared SSH keys left lying in home directories
0 %
of sessions recorded and replayable by name
0 types
of device, across every site, in one list
CAPABILITIES
What the Terminal gives you.
>_
Unified device access
Every host, hypervisor, GPU, switch, PDU and service — one click from a shell.
🌐
Multi-environment visibility
Datacenter, cloud and isolated sites in one list, one login.
⌕
Smart search & filtering
Find by name, type or site in a keystroke across every device type.
◈
Infrastructure context
Facts, live health, dependencies and open investigations on every session.
🔑
Operational access
JIT credentials, RBAC, command-level policy, recording and replay.
✦
AI + terminal workflow
Lumi proposes, classifies and explains commands — and hands off when it’s bigger.
WHY IT MATTERS
The shell is where incidents actually
get fixed.
Every dashboard ends with someone logging into a box. Make that step instant,
informed and accountable, and the whole incident gets shorter.
TIME TO FIRST COMMAND
10 minutes
1 click
From device list straight to a live, authenticated session.
SHARED CREDENTIALS
in home dirs
collapsed
Just-in-time access replaces keys that outlive their owners.
“WHO RAN THAT?”
unknowable
replayable
Every session recorded against a named person.
WRONG-BOX MISTAKES
common
prevented
Context and issue flags on screen before you type.
Get started
Stop hunting for the box.
Connect one datacenter site and one cloud account. Every
discovered device is one click from a governed shell.
Autonomous ITOps platform powered by an AI Coworker, SRE Orchestrator, and Agent Builder
© 2026 – 2027 LumiOps.AI. All rights reserved.

© 2026 – 2027 LumiOps.AI. All rights reserved.