Self-hosted DevOps control plane

Your infrastructure
has a guardian now.

Servers, Frappe sites, Docker stacks, Kubernetes clusters, databases, four public clouds and your own hypervisors — provisioned, deployed and watched from a single self-hosted control plane.

Docker·ERPNext·Terraform·Kubernetes·Ansible
SCROLL

THE GUARDIAN

One guardian.
Every server.

A single control plane stands watch over your whole fleet — Frappe sites, Docker stacks, and cloud servers — connected to one tireless guardian.

see all ten capabilities →

WATCHFUL

See everything.

Real-time monitoring across servers, containers, and sites. Health checks, alerts, and live-streaming logs — the watch never blinks.

acme.erp
cpu 18% · mem 41% · disk 62%
HEALTHY
web · 3 replicas
ghcr.io/acme/web:2.9.1
ACTIVE
what the watch actually checks →

TIRELESS

Every action becomes
a tracked job.

Provisioning, backups, deploys, migrations — each runs as a retryable background job with live logs, flowing Request → Queue → Worker → Server. Thousands at once, without rest.

how the job model works →

PIPELINES

Deployment pipelines
with control.

Multi-stage pipelines that pause at the Gates until a human approves. Two-person verification on anything that matters.

BuildApproveDeploy
how gates work →

PROTECTIVE

Protection built into
every action.

Self-hosted and encrypted at rest. The guardian forms a shield around your fleet — threats never reach it.

RBAC · 352 permissionsAudit ledgerEncrypted secretsApproval gates
read the threat model →

ONE CONTROL PLANE

Manage everything
from one place.

Servers, Docker stacks, Frappe sites, and cloud resources — every layer of your infrastructure, governed through the single guardian.

install it in one command →
talos · fleet overview
Servers
Kubernetes
Frappe
Docker
Deployments
Databases
Cloud
Pipelines
Monitoring
Fleet14 servers · 0 alerts
eu-west · lb-01
acme.erp
worker · q1
cache · redis
live · the Sentinel
✓ job #4821 backup acme.erp
→ snapshot db 1.2 GB
✓ uploaded s3://backups
⏸ deploy web · awaiting approval
✓ approved by k.minos
→ rolling update 2/3

EVERYTHING IT MANAGES

Ten capabilities. One job model.

The difference between managing an ERPNext bench and an EKS cluster is the adapter at the end, not the model in front of it.

AI ENGINE

BETA

An engineer that reads your fleet, and asks before it acts.

Bring your own model key. It has the whole context of your infrastructure and none of the authority to change it — every action becomes a proposal a human reviews before it enters the same job queue as everything else.

how the gate works →

Self-hosted. Free, forever.

Every project type, unlimited servers, the full permission model. There is no paid tier holding anything back — see the pricing page for why.

Self-hosted

The whole control plane, on your own infrastructure.

$0free, forever
  • Every project type — Frappe, Docker, Kubernetes, databases, four clouds, hypervisors
  • Unlimited servers, sites, stacks and clusters
  • Approval-gated pipelines and two-person verification
  • Full RBAC — 352 permissions, scoped per resource
  • Audit ledger, monitoring, alerts and live log streaming
  • Backups with point-in-time recovery and restore verification
  • The AI Engine, with your own provider key
Install it

⌖ ON PATROL

Forged to guard
your fleet.

Stand up the guardian on your own infrastructure in minutes.