Skip to content

Marolum

Coming soon

Your infrastructure state, easier to understand.

A self-hosted console for Pulumi, Terraform, and OpenTofu state in S3 and S3-compatible backends. See resources and supported operational context without moving your state or replacing the tools that deploy it.

Free editions and trials

Marolum is in development. No release date has been announced.

See the workflow

Marolum demo video placeholder. No recording is available yet.

Planned walkthrough: Find a stack, investigate an operation, and see which evidence supports the result.

Video not published yet. This placeholder is not a product screenshot or a playable demo.

Less time opening state files. More time understanding your infrastructure.

Keep your existing backends and deployment workflow. Add a place to inspect the state and context they produce.

Find the state you need

Inspect infrastructure state and resources across the self-managed backends you connect, instead of opening individual state files to find the information you need.

Investigate with context

Use supported timelines, resource history, and diagnostics to investigate changes. Coverage and gaps remain visible, so missing context is not mistaken for a complete record.

Give your team a readable view

Give teammates a browser view of resources and redacted outputs with explicit access controls. Review the same information without passing state files around.

Keep deployment under your control

Your existing CLI and deployment pipeline still make infrastructure changes. Marolum observes with read-only access; it does not apply, destroy, import, or refresh infrastructure.

Three engines. Your S3 backends.

Marolum supports Pulumi, Terraform, and OpenTofu state observation in self-managed S3 and S3-compatible backends. Available history and lock information depend on the engine and the evidence recorded; state support does not imply identical history coverage across engines.

Pulumi backends can supply native update history and active lock information. Terraform and OpenTofu state observation is verified against Terraform 1.15.9 and OpenTofu 1.12.6. Terraform and OpenTofu can write native S3 lock files when locking is enabled, but Marolum does not currently observe them. Backend-native update history remains unavailable for those engines.

Planned: More backend types. Current backend support is S3 and S3-compatible storage.

Review compatibility and known limitations

Free editions, trials, and paid plans

Best for teams that deliberately keep their own IaC backends and want shared visibility. If your existing tools already answer these questions, you may not need another console. The current product observes infrastructure; it does not execute changes.

Community: free, not a trial

The full observation core, with unlimited users, backends, stacks, and resources. No trial clock and no one-backend cap. You operate the application and its storage; documented engine and retention limits still apply.

Business trial: check availability

Marolum pricing shows the current trial availability, duration, and eligibility. When enabled, the Business trial requires a card for eligibility checks but does not charge automatically. Continuing with paid access requires a separate purchase.

Paid editions: additional capabilities

Choose Business or Enterprise when their published capabilities meet a need beyond Community. Review the edition details and current offer before purchasing. A license does not make an unreleased feature available.

Start with one useful result

Use the documentation to assess setup and permissions, then use an approved evaluation build with sample data. The useful result is answering a real state or history question, not just opening a dashboard.

Why early feedback matters

Early-adopter rates, when offered, are a way to learn from real workflows. We want useful feedback and hope to earn paying customers as the products prove their value.

A free edition is a valid long-term choice where one is offered. Feedback is welcome, including what did not work; it is not a commitment to buy or provide a testimonial.

Any early-adopter offer will state its price, duration, and renewal terms before you choose it. No future discount or price lock is implied by sending feedback.

Share feedback or ask a question

No sales call required. Please leave credentials and confidential customer data out of your message.

Community is the complete core

Start with Community for the full observation core, not a limited preview of a paid product. Choose a paid edition for the additional operational and organizational capabilities you need.

Community

$0

For individuals and teams that need the full observation core, local accounts, SQLite, and up to one year of operation and resource history.

Full Community details

The complete core. Unlimited users, backends, stacks and resources — no trial clock, no separate image, no provider-limited demo.

  • Read-only S3 and S3-compatible observation
  • Local authentication with administered local accounts
  • Three fixed roles — administrator, viewer, and transcript-reader
  • SQLite single-replica operation
  • Backend diagnostics, inventory, resources, redacted outputs
  • Durable per-stack timeline and cross-stack operations inbox
  • Stable permission-checked links, URL and time state
  • Coverage and gap explanations
  • Strongly correlated preview / update comparison
  • Resource history
  • Guided first-run readiness
  • In-app attention state
  • Active locks and live invalidation
  • Generic runner and developer ingestion
  • Baseline versioned export
  • Attributable retention policy changes and deletion audit
  • Unconditional preservation interlock
  • Up to 1 year of operation and resource history
  • Dino evaluation
  • Baseline security, in full
  • Email notifications through customer-hosted SMTP
  • Basic customer-local reliability summaries

Business

$199/mo · $1,990/yr

For teams that need longer retention, saved views, notifications, custom roles, resource-scoped access, one OIDC or SAML sign-in connection, and customer-operated PostgreSQL alongside the Community core.

Full Business details

Everything in Community, plus wider retention. Further Business capability is under development and is listed here only when it ships.

  • Custom roles composed from the permission catalogue
  • Resource-scoped authorization
  • One standard OIDC or SAML sign-in connection
  • Saved views
  • Outbound notification delivery
  • Advanced historical reliability segmentation
  • Customer-operated PostgreSQL, single replica
  • Wider retention, maximum 3,650 days

Enterprise

$499/mo · $4,990/yr

For organizations that need multiple OIDC or SAML connections, SCIM provisioning, trusted-proxy sign-in, and legal-hold placement in addition to Business capabilities.

Full Enterprise details

Everything in Business, plus legal-hold placement and best-effort support from the maintainer. Further Enterprise capability is under development and is listed here only when it ships.

  • Federated identity — multiple OIDC or SAML connections, SCIM, trusted-proxy
  • Ability to place a legal hold

Enterprise Advanced Security

from $9,999/yr

Enterprise capabilities through an organization-wide offline license for restricted or air-gapped environments. This changes licensing and connectivity, not application security.

Full Enterprise Advanced Security details

For air-gapped, restricted, and regulated environments: the exact Enterprise capability set through an organization-wide offline-site licence. No additional runtime capability and no additional limit, ever — every offering receives identical application security controls and fixes.

Connected plans include one installation. Additional installations cost 50% of the base price each and share the same key. Business Unlimited is $1,000/month or $10,000/year; Enterprise Unlimited is $5,000/month or $50,000/year, within one customer organization. Existing customers can add capacity through an account quote when plan changes are enabled.

Email notifications through your own SMTP server are available in every edition. Business and Enterprise also support signed webhook notifications. Dekglas-managed email delivery is not yet available.

Across editions, the core never shrinks, security is never paid, and no downgrade ever deletes data. Engine and evidence limits apply regardless of edition. Published prices do not by themselves establish release or purchase availability.

Run it alongside the tools you already use

Run Marolum in your environment, connect the backends you manage, and give it credentials scoped for observation. There is no state migration and no replacement CI/CD pipeline. You remain responsible for hosting, access, backups, and upgrades.

Whole-state capture is off by default. Retained state downloads require separate recovery permission and an audit. Marked Pulumi secrets stay encrypted and appear redacted in normalized inventory; whole-state recovery artifacts can contain sensitive values and need separate handling.

Dino provides an isolated local evaluation environment with sample infrastructure evidence. It is not a production deployment.

Documentation and availability

Documentation is published for evaluating setup, operation, and product fit. No supported public release or image is currently published. Visit Marolum pricing for purchasing availability; release downloads will appear here when they are published.

Marolum is an independent product by Dekglas. It is not affiliated with, sponsored by, or endorsed by Pulumi Corporation; IBM or HashiCorp; The Linux Foundation or the OpenTofu project; Amazon Web Services; Microsoft; Google; or the PostgreSQL project or PostgreSQL Community Association of Canada. Product names and trademarks belong to their respective owners.