EXTENSIONS
Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.
Filter by what you need and pull what fits.
Observability Agent
Install and configure a host-native metrics + logs agent on a remote
Aws Ops
AWS Operations Toolkit - Unified incident investigation and daily operational visibility.
Hashicorp Vault
HashiCorp Vault secrets management via REST API (KV v1 and v2). Emits OpenTelemetry spans for get, put, and list, with one child span per request in the recursive list walk, so vault reads are visible in traces including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and KV version only — never secret values, tokens, or error messages.
Aws/logs
Query and analyze CloudWatch Logs for operational visibility and incident investigation.
Macos Keychain
macOS Keychain vault using the security CLI. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and keychain service only — never secret values, argv, or error messages.
Aws/alarms
Query and analyze CloudWatch Alarms for operational visibility and incident response.
Aws/traces
Query and analyze X-Ray distributed traces for incident investigation and performance analysis.
Aws/alarm Investigation
CloudWatch alarm investigation and triage model.
Aws/dns Observation
Observe Route53 hosted zones, record sets, and detect orphaned DNS records
Aws/metrics
Query and analyze CloudWatch Metrics for operational visibility and performance monitoring.
Aws/config Compliance
Observe AWS Config compliance evaluations as typed queryable data.
Honeycomb
Manage Honeycomb SLOs, SLI derived columns, burn alerts, queries, query annotations, and triggers via the v1 Configuration API
Gcp/observability
Google Cloud observability infrastructure models
Aws/drift State
Unified drift detection surface that composes observations from existing
Software Factory Flow Metrics
Deterministic quality, reliability, and flow metrics for a @swamp/software-factory work item — time-to-terminal, per-stage durations, entry counts and time-to-gate, dispatch attempts, failed/parked stage, human touches, per-gate rejection counts, human cycle-limit overrides and the stages they unblocked, patch cycles, delivery mode, and terminal outcome — with a cross-run aggregate, every number traceable to the journal or artifact record it came from, rendered statically from recorded run data with no LLM involved.
Gopass
gopass password manager (gopass.pw) - pass compatible with extra features. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and backend only — never secret values or error messages.
Pass
GPG-encrypted password store using the pass CLI (passwordstore.org). Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and backend only — never secret values or error messages.
Cloudflare/logpush
Cloudflare Logpush — log jobs, destinations, field configurations
Datadog/traces
Datadog APM Traces — search and aggregate APM trace spans via the Datadog Spans API (v2). Supports all Datadog sites (us1, us3, us5, eu1, ap1, us1-fed).
Zabbix
Zabbix Monitoring — read-only integration for troubleshooting and observing monitored infrastructure via the Zabbix JSON-RPC 2.0 API. Retrieves hosts, problems, triggers, items, history, host groups, maintenance windows, events, and network maps.
Quest Tracker
Tracks progress through the swamp Genesis quest campaign. Parses `swamp quest --json`, persists each progress snapshot as swamp data, and guards against XP regression — since the anti-abuse penalty zeroes a score, a backward slide in passXp, tier, or challenge progress is the tell-tale signal and is surfaced as `regressed`. `check` records a snapshot and diffs it against the previous one; `advise` ranks the closest incomplete challenges toward a target tier so an operator (or workflow) knows the cheapest next move.
Datadog/metrics
Datadog Metrics — metric queries, submissions, tag configurations, and metadata
Datadog/events
Datadog Events — event search and submission
Datadog/slos
Datadog SLOs — service level objective definitions, status, and history