Kestra
Declarative YAML-based orchestration platform with 1500+ plugins for automating data, AI, and infrastructure workflows.
Kestra
Kestra is an open-source, event-driven orchestration platform that unifies scheduled and event-driven automation behind a declarative, language-agnostic YAML interface. With 1500+ plugins it can orchestrate anything — data pipelines, AI workflows, microservices, and infrastructure tasks.
Key Features
- Declarative YAML flows: Define workflows without boilerplate code; version-controlled as Infrastructure as Code
- 1500+ plugins: Native connectors for databases, cloud providers, messaging, ML platforms, and APIs
- Built-in UI: Visual flow editor, real-time execution monitoring, and replay capabilities
- Event-driven triggers: Webhooks, file arrival, schedule, API calls, or custom conditions
- Namespace isolation: Multi-tenant logical grouping for organization and access control
- Scalable: Kafka-backed distributed execution for high-throughput workloads
Quick Start
# Start Kestra with Docker
docker run --pull=always --rm -it \
-p 8080:8080 --user=root \
-v /var/run/docker.sock:/var/run/docker.sock \
-v /tmp:/tmp kestra/kestra:latest server local
id: hello-world
namespace: dev
tasks:
- id: log
type: io.kestra.plugin.core.log.Log
message: "Hello from Kestra!"
Add to ai-supply
npx ai-supply add kestra-declarative-orchestration
Curated mirror of the open-source Kestra (Apache-2.0). Get it from the source.
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
The same gate an agent runs before installing (POST /api/v1/trust/kestra-declarative-orchestration/check). Click a policy:
Consume Kestra programmatically. Authenticate with an API key or session — see Authorize an agent.
# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/kestra-declarative-orchestration
# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/kestra-declarative-orchestration/check \
-H "Content-Type: application/json" \
-d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'
# CLI
npx ai-supply add kestra-declarative-orchestration
# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/kestra-declarative-orchestration/install \
-H "Authorization: Bearer $AIM_KEY"
# MCP tool
install_listing({ "slug": "kestra-declarative-orchestration" })OpenAPI spec →Curated mirror — latest upstream source. See the repository for tagged releases.