Orcastra Orcastra
Open Source Cloud Management Platform GPLv3

One dashboard.
One API.
Multiple clusters.

One browser session manages containers and virtual machines, projects, networking, storage and identities across every LXD, Incus and MicroCloud cluster you run.

Singapore
Jakarta
Kuala Lumpur
Bangkok
Ho Chi Minh City
Manila
Powered by proven open-source infrastructure
LXD CANONICAL
MicroCloud CANONICAL
Incus LINUX CONTAINERS
01 — Distributed by design

Your infrastructure stays distributed.
Your experience doesn't have to be.

01
Regions and inventory

One inventory of every region you run, and of the hardware inside each one.

02
Projects everywhere

Boundaries that follow teams across clusters, not the other way round.

03
Unified operations

The same screens and the same actions, whichever platform is underneath.

04
One API

Every feature in the console is an API call, reachable with a scoped key.

02 — Create an instance

One dense page, not a multi-step wizard.

Deploy a VM or a container,
as easily as on public cloud.

Type, source image, project, resources, storage, network, GPU passthrough, cloud-init, snapshots, security policies, migration settings and boot order are all visible on one page, rather than discovered three screens later.

WHAT THE FORM ASKS FOR
Container
Lightweight, fast startup
Virtual machine
Full isolation, own kernel

The first decision on the page, and the only one that changes what follows.

Configuration 6 FIELDS
instance namedescriptiontagsnodeprojectbase image

Choose the node first and the page inherits its networks and pools.

Resources 5 FIELDS
cpu coresmemorymemory swapdisk prioritymax processes
Storage 3 FIELDS
storage sizestorage pooladditional disks
Network 1 FIELD
network interfaces
GPU passthrough 1 FIELD
custom gpu devices

By device on the target node, or by PCI address.

Advanced options 5 FIELDS
security policiesmigration settingsboot ordercloud-initsnapshots

Collapsed by default, on the same page rather than a later step.

Provisioning progress arrives on this same page
Node selection filters the page

Networks, storage pools and GPU devices are read from the node you picked, so the page offers only what that node can honour.

Three image sources, one field

Images already on the cluster, images from a remote image server, and images pulled on creation, all resolved by distribution, release, variant and alias.

Progress over a WebSocket

The browser subscribes to the cluster event stream while the instance is built, so each step appears as the cluster reports it. Once it exists, the instance opens into a detail view with tabs for overview, configuration, devices and metrics.

03 — Then reach it

A shell inside a machine
with no network.

Console and terminal reach an instance that has no SSH daemon, no open port and no public address, because they run over the cluster’s own WebSocket channel rather than over the guest’s network.

Both open as windows over the dashboard rather than as a page you navigate to, so several instances stay reachable at once while you keep working elsewhere.

TERMINAL
CONSOLE
A workspace, not a page

Open a terminal on one instance, a console on another, and both stay on screen together as separate cards.

Several at once

Each session opens as its own card. Compare two instances side by side, or watch one boot while you work in another.

Drag to arrange

Move a card anywhere on screen and place the ones you are watching where you want them.

Survives navigation

Change pages and the open cards stay with you. Reading a warning or a metric does not close the shell you are in the middle of.

Minimize and restore

Send a card to the bottom right corner to clear the view, and bring it back with the session still connected.

Terminal

A real shell inside the instance, streamed straight to the browser. It is not SSH, so the guest needs no key and no open port.

Console

A graphical console for virtual machines, right in the browser. Switch between text and graphics, or mount an ISO, from the tabs on the same window.

File transfer

Drag a file onto the terminal window and it is pushed into the instance.

Sessions

Every open session is tracked with its protocol, node, instance, duration and transfer rate, and kept in a searchable history after it ends.

04 — Explore the platform

The rest of the product, a page at a time.

Every part of Orcastra,
explained in full.

Each page carries one part of the product in full. Read them in order or jump to the one you came for; every page names the next at its foot.

Instances

Everything an instance depends on: virtual networks, storage pools and volumes, images, and the projects that hold them.

NETWORKS · ACLS · IPAM · POOLS · VOLUMES · IMAGES · PROJECTS
Multi-cluster

Register a cluster and watch its health, then see the whole estate by geography and aggregate capacity.

CLUSTERS · MEMBERS · OPERATIONS · WARNINGS · REGIONS · TECHNOLOGIES
Security

Roles from your identity provider, policies scoped to the resource, break-glass, and certificate lifecycle.

ROLES · POLICIES · IDENTITIES · BREAK-GLASS · MY KEYS · CERTIFICATES
Observability

Live telemetry from the clusters themselves, and the durable record behind it.

MONITORING · ALARMS · OPERATIONS · AUDIT · LOG ARCHIVE
Branding

Rebrand the console for the customers you put in front of it, and preview it before it applies.

LOGOS · THEME · ACCENT · TAGLINE · PREVIEW
Platform

The request path as it actually runs, the stack behind it, and what you need before installing.

FRONTEND · BACKEND · DATABASE · CACHE · IDENTITY · SECRETS · LOGGING
05 — Who runs this

Five situations, each mapping to features that exist.

Built for infrastructure
that stays entirely yours.

05

AI integrated IT operations

Let the assistant read the fleet.

Orcastra publishes an MCP server, so the assistant your team already uses can query the estate through a key you scoped and revoke, recorded in the same audit trail as a person. No model runs here.

MCP SERVER SCOPED CAPABILITIES API KEYS ACTIVITY AUDIT
06 — No black box

Abstraction that explains itself instead of hiding the machine.

LXD, Incus and MicroCloud,
di-orchestrate, bukan jadi rahasia dapur.

Orcastra turns independent clusters into a single managed estate. Every project, container and virtual machine is reachable from one place, governed by one policy and exposed through one API.

Projects and instances
ACROSS EVERY CLUSTER
Fine-grained RBAC
AUTHENTIK OAUTH2 + OIDC
Full API access
EVERY FEATURE
Organizations
TENANTS, ISOLATED
Orcastra control plane ONE PANE · ANY CLUSTER
LXD
CANONICAL
MicroCloud
CANONICAL
Incus
LINUX CONTAINERS
Why this stack

LXD, Incus and MicroCloud are the easiest virtualization platforms to install, operate and hand over. A few commands get you a working cluster, with no hypervisor licensing in the way.

SHARED RESOURCES FOR ORGANISATIONS CAMPUS & RESEARCH COMPUTE CLIENT-FACING TENANCY
Strengths

Three platforms, one operating model. Pick per site, manage as one.

LIVE MIGRATION BETWEEN NODES

LXD

CANONICAL

KVM virtual machines and full-OS containers in a single platform, with no separate hypervisor stack to run.

Scheduled snapshots with automatic expiry, projects and profiles, and hardware passthrough for GPU, USB and NIC.

Unprivileged containers by default, plus UEFI SecureBoot and vTPM for virtual machines.

Image-based, with built-in stores for most Linux distributions and for Windows virtual machines.

LTS every two years, supported for five, with commercial support available through Ubuntu Pro.

COMPUTE · STORAGE · NETWORK, CLUSTERED

MicroCloud

CANONICAL

A working cluster from four commands, with LXD, MicroCeph and MicroOVN wired together automatically.

Compute, distributed storage and software-defined networking without hand-assembling any of it.

Starts at a single node and scales to roughly 50, with high availability from three members up.

Snap packaging keeps components isolated and security updates streamlined.

Runs on production servers or lightweight edge hardware, on Ubuntu Server or Ubuntu Core.

ONE API, LAPTOP TO FULL RACK

Incus

LINUX CONTAINERS

Community-governed fork of LXD, Apache 2.0 and free of any CLA.

Maintained by the same engineers who originally built LXD.

A complete REST API, so anything the client does an application can do too.

Scales from one laptop instance to a full rack, containers and virtual machines on the same storage and network.

Migration path from an existing LXD estate via lxd-to-incus.

Legible by default

Every layer named, from the click to the kernel.

Every action in the console names the cluster it touches and the API call it makes. Engineers learn the platform by using it, and can still drop to lxc or incus on the node at any moment.

Every console action shows the API request it sends and the underlying lxc/incus command it maps to.

The audit trail names the operator, the target cluster and the exact payload.

YOU SEE EVERY LAYER
Orcastra console WHAT YOU CLICK
REST API call POST /1.0/instances
Cluster daemon LXD · MICROCLOUD · INCUS
Node kernel CGROUPS · KVM · ZFS
TRACEABLE END TO END
NOTHING TO TAKE OVER

We don't want to take over
your backend.

Orcastra sits on top of LXD, MicroCloud and Incus. Nothing is forked, nothing is hidden, and every cluster keeps working the day you turn Orcastra off.

verifying the control plane
$ curl -s http://<host>:8765/health          200 OK

$ docker compose -f docker-compose.prod.yml ps
NAME                            STATUS         PORTS
orcastra-dashboard-backend      Up (healthy)   8765->4050/tcp
orcastra-dashboard-frontend     Up (healthy)   4321->2025/tcp
orcastra-dashboard-postgres     Up (healthy)   5432->5432/tcp
orcastra-dashboard-redis        Up (healthy)   6381->6379/tcp
orcastra-dashboard-fluent-bit   Up (healthy)

# stop all five and your clusters carry on without them
$ lxc list --project platform
Five containers on your own host

Backend, frontend, PostgreSQL, Redis and a log shipper. Each reports its own health, and the backend answers a plain HTTP health check.

Your credentials, your client

Generate a TLS certificate for yourself and drive the cluster with the native client, with no operator in the loop.

Reversible by design

Registering a cluster adds a reader, not a rewrite. Stop the stack and every instance, network and volume keeps running exactly as it was.

07 — Self-host it

Keep the infrastructure.
Run the control plane yourself.

Orcastra is self-hosted and deployed with Docker, licensed GPLv3 with a public repository. There is no hosted service to sign up for.

before you install GPLv3 · SELF-HOSTED
  docker                            required
  lxd / incus / microcloud nodes    api enabled
  client certificate                one per node
  hashicorp vault                   required
  authentik                         required
  opensearch                        optional