Manifest No. 0001 — Origin: your repository
Forge it. Ship it. Run it.
CargoForge runs the docker-compose.yml already in your repo — every container sealed with its own real virtual machine kernel, not a shared kernel namespace. No proprietary manifest to learn. No Docker socket handed to a stranger's container. No inbound door left open into your fleet.
Deployment
- Build
- Push
- Sealing container…
ds-7f2e1a-web
Healthy · 3 services
- Vessel
- dock-host-04
The manifest
Every shipment, fully declared.
Five layers, in order, from the fleet you own down to the compose file you already wrote. Nothing hidden below the waterline.
Fleet
Every physical host you own, orchestrated from one control plane you run yourself.
Physical host
Real hardware — a dedicated box you already rent, or bring your own bare metal.
Worker agent
Runs directly on the host, calls out to the control plane, and never listens for a connection in.
Sealed container
Every container it starts gets its own real guest kernel in a lightweight virtual machine. Not a namespace. Not a chroot. Its own kernel.
Your compose file
The exact docker-compose.yml already in your repo. We don't invent a format.
Why devs switch
Built for people who read the changelog.
Real docker-compose, not a dialect
No YAML to relearn and no lock-in format — the file you already have is the deploy.
A real guest kernel, not a namespace
Every container runs inside its own lightweight virtual machine. A container breakout still can't reach anything outside the guest kernel it started in — no shared kernel namespace to climb through.
Outbound-only agents
Nothing in your fleet accepts an inbound connection from the control plane. No standing SSH.
Per-account quotas
Container and project ceilings enforced account-wide, closing the "many small projects" gap.
A fleet you can see
Every host and worker's health in one console — the Crane, at crane.cargoforge.dev.
Bring your own hardware
Point it at a dedicated box you already rent. No lock-in to anyone else's metal.
The tariff
What a dyno used to cost.
Heroku called it a dyno — a slice of a shared process. We call it a container, because it isn't a slice of anything: it's sealed with its own guest kernel in a real virtual machine, billed the way a shipping line bills a container — by what you actually put on the vessel.
One project, for finding out if this is for you.
- 10 containers
- 1 project
- Community support
For the projects that pay their own way.
- 50 containers account-wide
- 20 projects
- Admin console access
- Per-service ingress
Bring your own bare metal. We just run the containers.
- Unlimited projects and hosts
- Your own hardware fleet
- Dedicated ingress + support
- Custom account quotas
Cast off in one push
The whole deploy, in one session.
Cast off.
Point CargoForge at your compose file. We'll forge the container.