Anywhere
Alaf Server Cloud, your own VPS, a homelab - same workflow, your servers, your rules. Add more as you grow.
Alaf Server is the open-source platform that turns your servers into an automated cloud. Push code, deploy containers, and manage infrastructure.
Designed for your favorite stack

Platform
We handle the configuration, the builds, the certificates, the routing. You write the application.
Alaf Server Cloud, your own VPS, a homelab - same workflow, your servers, your rules. Add more as you grow.
Postgres, Redis, MongoDB, workers, mail, object storage - auto-provisioned, privately networked, observable.
Connect a repo. Every push builds, runs your tests, and ships. Preview deployments per pull request.
Every deployment is an immutable snapshot. Revert to any previous version in one click, zero downtime.
Node, Python, Go, Rust, PHP, Ruby, Java, .NET, Elixir, Docker, monorepos - auto-detected and configured.
Unlimited custom domains, wildcard certificates, automatic renewal. No add-ons, no caps, no metering.
How it works
No agent on your servers, no black box. Here's the exact path your code takes — and why your production machines never build.
Link a Git repo and pick a target — Alaf Server Cloud or your own server over SSH. Nothing is installed on your box: no agent, no daemon, no dashboard.
On every push the image builds on your machine (or in the cloud), runs your tests, and is tagged as an immutable, versioned artifact. Your production servers stay focused on serving.
The built image streams to the target over SSH and starts as a fresh container on an isolated private network — no exposed ports, no hand-written Docker or Compose.
Your domains are wired through OpenResty with automatic Let's Encrypt SSL, then traffic swaps to the new container with zero downtime. The previous version stays ready for rollback.
Stream logs, watch metrics, and roll back to any previous version in one click — from the CLI, the web dashboard, the desktop app, or an AI agent over MCP.
Where it runs
Same platform, three deployment shapes - and you can switch any day.
Sign up, point at a repository, ship. Zero infrastructure decisions. Multi-region by default. Auto-scaling per service.
Run the entire platform on machines you own. Any Linux box, any provider, any region. Add nodes as you grow.
Cloud for the burst, your servers for sensitive data. One control plane. Move workloads without rebuilding.
Your apps are plain containers and your services are standard images. Move workloads between Alaf Server Cloud and your own servers without rebuilding, rewriting, or paying an exit tax. Click, confirm, done.
The full platform
No add-on stores, no plugin marketplaces, no "requires an integration with...".
Every commit builds and ships. Branch environments included.
Every pull request gets its own URL. Auto-torn down on merge.
Builds run on your machine. Production servers stay focused.
Framework, language, package manager, commands - figured out.
Common failures (missing imports, version drift) diagnosed and patched.
Every deploy is immutable. Revert to any version in one click.
Horizontal scaling per service. Up on traffic, down when idle.
Health checks, weighted routing, sticky sessions - built in.
CPU, memory, network, disk - real-time charts and alerts.
Live tail across services and replicas. Search, filter, persist.
Cron-like jobs with retries, visibility, per-run logs.
Rolling restarts, blue-green, draining connections - automatic.
Unlimited apex and subdomains. Wildcards supported.
Let's Encrypt by default. Auto-renewing wildcard certificates.
Visual records and propagation. Verify domains in seconds.
Global edge, anycast IPs, low-latency routing.
Services talk over an isolated network, no exposed ports.
First-class support, persistent connections, sticky routing.
Versions 14–17. Daily backups, PITR, scheduled upgrades.
Cache or persistent. Cluster mode. Pub/sub and streams.
Replica sets, sharding, automated upgrades, migration tools.
S3-compatible buckets. Signed URLs, lifecycle rules, replication.
Transactional from your domain. Authentication chain auto-configured.
Static asset acceleration. Cache invalidation on deploy.
A single binary covering deploy, logs, secrets, domains, rollbacks.
Visual deploys, metrics, billing, team access.
Native Mac and Windows. Push from local, stream logs natively.
Drive deploys from AI agents — Claude, Cursor, any MCP client. Standard tools, authenticated.
Encrypted at rest. Environment-scoped. Rotated without redeploying.
Every action, exportable, retained for compliance.
Default-deny inbound. Per-service policies.
Per-route limits, IP or token based. Burst and sustained.
HSTS, CSP, COOP, COEP - production defaults.
Edge-level mitigation, automatic challenge.
TLS everywhere, encrypted backups, encrypted secrets.
Logs and config suitable for SOC 2, ISO 27001.
Multiple organizations per account — isolated projects, servers, and members. Switch in a click.
Owner, admin, member, and a restricted role. Assigned per teammate.
Grant access down to individual projects and resources - not just broad roles.
The restricted role starts with zero access. Every permission is explicit - least privilege.
Invite teammates by email. Expiring links, accept flow, per-inviter rate limits.
Every join, role change, and removal recorded and exportable.
Built-in mail server
Send password resets, receipts, magic links, marketing - from any domain you own. No Sendgrid bill. No DNS rabbit hole. One click and the records, certificates, and authentication chain are in place.
Start in our cloud or on a server you own.
No credit card, no lock-in, no configuration files.