Manifest No. 0001 — Origin: your repository

Forge it. Ship it. Run it.

CargoForge runs the docker-compose.yml already in your repo — every container sealed with its own real virtual machine kernel, not a shared kernel namespace. No proprietary manifest to learn. No Docker socket handed to a stranger's container. No inbound door left open into your fleet.

$ git push crane main Sealing container ds-7f2e1a-web... ✓ ds-7f2e1a-web healthy

Deployment

  • Build
  • Push
  • Sealing container…

ds-7f2e1a-web

Healthy · 3 services

Bill of Lading CF-8834-A
Vessel
dock-host-04
CLEARED ✓

The manifest

Every shipment, fully declared.

Five layers, in order, from the fleet you own down to the compose file you already wrote. Nothing hidden below the waterline.

Layer 01

Fleet

Every physical host you own, orchestrated from one control plane you run yourself.

Layer 02

Physical host

Real hardware — a dedicated box you already rent, or bring your own bare metal.

Layer 03

Worker agent

Runs directly on the host, calls out to the control plane, and never listens for a connection in.

Layer 04

Sealed container

Every container it starts gets its own real guest kernel in a lightweight virtual machine. Not a namespace. Not a chroot. Its own kernel.

Layer 05

Your compose file

The exact docker-compose.yml already in your repo. We don't invent a format.

Why devs switch

Built for people who read the changelog.

Item 4471

Real docker-compose, not a dialect

No YAML to relearn and no lock-in format — the file you already have is the deploy.

Item 4472

A real guest kernel, not a namespace

Every container runs inside its own lightweight virtual machine. A container breakout still can't reach anything outside the guest kernel it started in — no shared kernel namespace to climb through.

Item 4473

Outbound-only agents

Nothing in your fleet accepts an inbound connection from the control plane. No standing SSH.

Item 4474

Per-account quotas

Container and project ceilings enforced account-wide, closing the "many small projects" gap.

Item 4475

A fleet you can see

Every host and worker's health in one console — the Crane, at crane.cargoforge.dev.

Item 4476

Bring your own hardware

Point it at a dedicated box you already rent. No lock-in to anyone else's metal.

The tariff

What a dyno used to cost.

Heroku called it a dyno — a slice of a shared process. We call it a container, because it isn't a slice of anything: it's sealed with its own guest kernel in a real virtual machine, billed the way a shipping line bills a container — by what you actually put on the vessel.

Freight $0/mo

One project, for finding out if this is for you.

  • 10 containers
  • 1 project
  • Community support
Open the Crane console ↗
Fleet Custom

Bring your own bare metal. We just run the containers.

  • Unlimited projects and hosts
  • Your own hardware fleet
  • Dedicated ingress + support
  • Custom account quotas
Talk to us ↗

Cast off in one push

The whole deploy, in one session.

$ git push crane main Parsing docker-compose.yml... Resolving worker on dock-host-04... Building web, api, worker (3/3)... Sealing each container with its own guest kernel... ✓ web running :3000 ✓ api running :8000 ✓ worker running ✓ project ds-7f2e1a healthy
Active containers2,481
Avg. container boot41s
Fleet uptime99.97%

Cast off.

Point CargoForge at your compose file. We'll forge the container.