The Infrastructure Platform for Teams Without Ops.

ORC8R is ZeroDevOps infrastructure for AI agent sandboxes, CI/CD and apps. Choose on-prem compute, cloud capacity, or both — with one control plane for provisioning, private networking and node replacement.

Linux Windows macOS — soon Bare metal — soon

This page and our CI runners run on ORC8R, in our own colocation racks.

  • Automatic TLS
  • Encrypted backups
  • WireGuard mesh
  • Live logs & metrics
  • MCP built in

The console

What you see is what you get.

These are the screens you get when you sign in — same tabs, same controls, same kind of data. Every node has them from its first boot, with nothing to install.

Metrics

Every node, measured

CPU, memory, disk I/O, network, pressure, filesystems and top processes, per node and per pool. Look back an hour or a year; the data is stored in the control plane itself.

Logs

Live logs, tagged by app

Tail every app's output as it happens, or replay the last hour to three days. Each line says which app wrote it, and the history survives node replacement.

Terminal

A root shell in the browser

Open a shell on any node, from any server; it reconnects to the same session. It's for looking around — fixes go into the app, and the node gets rebuilt.

App catalog

Pick apps, not packages

Choose what a pool runs from your registry's catalog, pin a version, and fill in the form the app's manifest generates. Runners, agents, CLIs — or your own.

Drawn from the shipped console. Org, project and pool names are examples.

Cattle, not pets

No node is special. That's the point.

Every node in a pool boots from the same image and runs the same app. Nobody logs in to fix one — ORC8R throws it away and brings up another. The same move handles failures, traffic and updates.

When a node fails

It's replaced, not repaired

A lost node leaves the load balancer and a fresh one takes its slot. No pager, no SSH, no 3 a.m. snowflake surgery.

When load climbs

Change one number

Pool size is the only knob. Raise it from the dashboard, the CLI, the API or an AI agent — lower it when the rush is over and stop paying.

When you ship

Rebuilt, never patched

A new version bakes a fresh pool image and nodes are rebuilt from it. Idempotent installs, ephemeral nodes — nothing drifts.

Stateful when you need it. App data lives on its own partition, is backed up with node-side encryption, and follows the app onto the replacement node. Databases are cattle too.

AI agent sandboxes

Give every agent its own sandbox.

Run coding agents and the code they generate on disposable virtual machines. Give each agent its own project, a repeatable toolchain and the services it needs — in your data center or in the cloud.

Disposable VMs, repeatable environments

Start from a prepared image with your tools installed. Run builds and experiments, then remove the nodes when the task is done.

A project for each agent

Use a dedicated project and an account with only the roles that agent needs. Each project has its own network; share services with other projects only when you choose.

Provision through MCP

Agents can request nodes, create backing services and deploy apps through MCP, using their signed-in user's permissions. Databases and helper services get private names inside the project.

agent session · MCP server: orc8r
Put the feedback app I just built on a URL the team can open. It needs its own Postgres.
search_operations query: "pool create"
✓ create_pool · POST /api/orgs/{org}/projects/{proj}/pools/
call_write_operation create_pool · acme/feedback
  { pool: "db", provider: "virt", size: 1,
    app_data_gib: 10, apps: [{ name: "postgres" }] }
✓ 201 Created
call_write_operation create_pool · acme/feedback
  { pool: "web", provider: "virt", size: 2,
    apps: [{ name: "feedback-web",
      params: { database_host: "db.feedback.internal" } }] }
✓ 201 Created
call_read_operation list_pool_endpoints · web
✓ http · access https://feedback--web.acme.orc8r.com
Done. The team can open https://feedback--web.acme.orc8r.com — ORC8R asks them to sign in and checks they're in the project first.
projectorganizationpublic

Works with any MCP client — tested with Claude, Claude Code, ChatGPT and Codex. Clients sign in with OAuth and every call runs as that user, with that user's roles. They can never mint API keys, enroll agents or open terminals.

Apps, not VMs

Other hosts rent you a machine. We run your app.

Package an app once and ORC8R runs it on every node of a pool — installed, started, health-checked, replaced and cleaned up for you.

Package

Describe it once

An app is a small package: what it needs, and how it installs, starts and stops. Write it yourself, or let your AI agent write it.

Publish

One push, four front doors

orc push it to your registry and it's a catalog card, a deploy form, an API call and an MCP tool — all at once.

Bake

Nodes boot ready

Install runs once into the pool image, so every new node starts with the app already in place.

Run

Behaves like it belongs

It runs as a real system service, finishes its work before a node is replaced, and cleans up when the node is gone for good.

Starting from zero? The catalog ships ready apps — github-runner, jenkins-agent, docker, vault, terraform, aws, gcloud, and AI coding agents claude, codex and cursor. Stack several on one pool.

Production-ready on day 0

The checklist a sysadmin would spend a month on. Already done.

Automatic TLS

Public names get certificates issued and renewed for you. Every project has its own CA for internal TLS.

Load balancing & DNS

Every exposed endpoint spreads across the pool's healthy nodes and gets a name. Nodes join and leave on their own.

Private hybrid networking

WireGuard links cloud nodes and supported on-prem hosts. Project networks stay separate; explicitly exposed services can be shared across projects.

Encrypted backups

App data is sealed on the node before it leaves. The store never sees plaintext. Restore any point.

Live logs

Stream every node's app output in real time, from the browser, the CLI or your agent.

Metrics

CPU, memory, disk, network and top processes per node and pool. Nothing extra to install.

Private service access

Reach an internal database or dashboard from your laptop through an authenticated tunnel. No VPN, no open ports.

Alerts SOON

Rules on the metrics you already have, delivered where your team already is.

No sysadmin required. Roles, projects and organizations decide who sees what.Browser terminal on every node, for when you really want to look.

Performance

Your database writes to a disk. Not to a network.

Most clouds put your volume at the far end of a network hop. ORC8R gives app data its own partition on the node's local NVMe — read- and write-heavy workloads stop waiting on the wire.

  • Dedicated partition by default, not a loop file
  • Survives node replacement through encrypted backups
  • One node shape per pool — no instance-type roulette
Typical cloud VMnetwork block storage
app→guest kernel→network→storage cluster→disk
ORC8R nodelocal app-data partition
app→guest kernel→local NVMe
fsync-heavy PostgresCI build cachesHPC scratchartifact stores

Hybrid cloud

Your compute. Your choice of where it runs.

Keep workloads on-prem, place pools in the cloud, or use both under one control plane. Choose where each pool runs based on cost, capacity and where your data belongs.

Cloud compute

Use ORC8R cloud capacity or connect a cloud provider. Provision nodes for agents, builds and applications.

On-prem compute

Run virtual machines on your own supported hosts. Keep compute close to internal data and services.

Mix both

Put different pools on different providers in the same project. Use one app catalog, permission model and operational view.

WireGuard mesh networking

One private project network, across locations.

Encrypted WireGuard links connect cloud nodes with supported on-prem hosts. ORC8R manages peer membership and private service discovery, so your apps can talk across locations without exposing their internal ports to the internet.

Projects remain separate. Share a service across your organization by explicitly exposing its port.

Explore project networking

Linux and Windows nodes support the mesh. VM networks use VXLAN and join the mesh through supported hosts. Existing machines join after connectivity is verified, with gateway relays where available.

available

Linux

amd64 and arm64, on our hosts or yours.

available

Windows

Images built from your own ISO with a recipe. Same pools, same apps.

coming soon

macOS

Apple Silicon hosts for iOS and macOS build pipelines.

coming soon

Bare metal

Whole machines as nodes, in the same pool model.

Who it's for

From a rack in the garage to a factory floor.

Home labs

Your hardware, a real cloud on top

Turn the machines under your desk into pools with TLS, backups and a dashboard.

  • Free on your own hosts
  • Git, CI, media, home automation
cloud · free tier
Industrial & medical

24/7 without a cloud in the loop

Keep robotics, CNC and 3D-printing control software running on-site, even when the internet isn't.

  • On-prem control plane, flat cost
  • Keeps running when the internet drops
on-prem
AI agent sandboxes

Run the code your agents write

Give coding agents disposable VMs for builds, tests and experiments, with databases and runners in the same project.

  • VM isolation and project networks
  • Cloud or on-prem compute
cloud · on-prem
HPC & batch

Scale to the job, then to zero

Grow a compute pool for the run on local-disk nodes, shrink it when the queue drains.

  • One-number scaling
  • Local NVMe scratch
cloud · on-prem

Two ways to run it

Rent our cloud, or run your own.

Same product, same apps, same MCP. Pick where the nodes and the control plane live.

Cloud

Nodes on our racks, managed by us. Start in minutes.

Pay per useHourly rates, no monthly fee
  • No reserved instances, no egress fees, no support tiers
  • Budgets per project so an agent can't run up a bill
  • Bring your own hosts free — only backups are billed

On-prem

Your hardware, your network, managed by ORC8R.

Flat costMonthly plans by node count · no metering
  • More privacy — data and control plane stay on-site
  • More performance — your NVMe, your network
  • A licence lapse never stops running workloads

Home lab? Free to use on your own hardware.

Price estimator

Build your node

Node pool

App data

Storage your apps keep across node replacements.

Estimated cost

Updating...

Hourly

per node

Monthly

730 hours

Estimates come from the pool you picked — a provider that publishes its own rates is asked for them, so what you see here is what a node of that shape is charged at. Multi-region and on-premises options available.

Minimum dependencies

Still up when the big clouds aren't.

ORC8R is self-contained: its own scheduler, registry, storage, networking and certificate authority, running in our own colocation data center. We list every outside dependency we still have — and we keep shrinking the list.

We run on it, every day

Our CI runners, build pipelines, image bakes and this website are ORC8R apps on ORC8R pools. If something breaks, we feel it first.

What it takes to run ORC8RWho runs it
Compute, storage, networking● ours
Image registry & app catalog● ours
Certificates & internal DNS● ours
Control plane, logs, metrics, backups● ours
Public DNSon the list to replace○ Cloudflare
Outbound emailon the list to replace○ AWS
Short-term spike capacityuntil our own racks catch up○ third-party clouds

Careers

We're hiring

Help us build the compute platform for development teams.

View open positions

Stop babysitting servers.

Deploy your first app on a pool in minutes — on our cloud, or free on your own hardware.

Start a free demo and spin up 2 real nodes in under 3 minutes.
Free demo · 2 nodes · 24 hours · No credit card required