Orcastra — one control plane for LXD, Incus and MicroCloud
Orcastra Orcastra
EN ID
GitHub Get started
Open Source Cloud Management Platform GPLv3

One dashboard.
One API.
Multiple clusters.

One browser session manages containers and virtual machines, projects, networking, storage and identities across every LXD, Incus and MicroCloud cluster you run.

Singapore
Jakarta
Kuala Lumpur
Bangkok
Ho Chi Minh City
Manila
Powered by proven open-source infrastructure
LXD CANONICAL
MicroCloud CANONICAL
Incus LINUX CONTAINERS
01 — Distributed by design

Your infrastructure stays distributed.
Your experience doesn't have to be.

01
Regions and inventory

One inventory of every region you run, and of the hardware inside each one.

02
Projects everywhere

Boundaries that follow teams across clusters, not the other way round.

03
Unified operations

The same screens and the same actions, whichever platform is underneath.

04
One API

Every feature in the console is an API call, reachable with a scoped key.

02 — Create an instance

One dense page, not a multi-step wizard.

Deploy a VM or a container,
as easily as on public cloud.

Type, source image, project, resources, storage, network, GPU passthrough, cloud-init, snapshots, security policies, migration settings and boot order are all visible on one page, rather than discovered three screens later.

WHAT THE FORM ASKS FOR
Container
Lightweight, fast startup
Virtual machine
Full isolation, own kernel

The first decision on the page, and the only one that changes what follows.

Configuration 6 FIELDS
instance namedescriptiontagsnodeprojectbase image

Choose the node first and the page inherits its networks and pools.

Resources 5 FIELDS
cpu coresmemorymemory swapdisk prioritymax processes
Storage 3 FIELDS
storage sizestorage pooladditional disks
Network 1 FIELD
network interfaces
GPU passthrough 1 FIELD
custom gpu devices

By device on the target node, or by PCI address.

Advanced options 5 FIELDS
security policiesmigration settingsboot ordercloud-initsnapshots

Collapsed by default, on the same page rather than a later step.

Provisioning progress arrives on this same page
Node selection filters the page

Networks, storage pools and GPU devices are read from the node you picked, so the page offers only what that node can honour.

Three image sources, one field

Images already on the cluster, images from a remote image server, and images pulled on creation, all resolved by distribution, release, variant and alias.

Progress over a WebSocket

The browser subscribes to the cluster event stream while the instance is built, so each step appears as the cluster reports it. Once it exists, the instance opens into a detail view with tabs for overview, configuration, devices and metrics.

03 — Then reach it

A shell inside a machine
with no network.

Console and terminal reach an instance that has no SSH daemon, no open port and no public address, because they run over the cluster’s own WebSocket channel rather than over the guest’s network.

Both open as windows over the dashboard rather than as a page you navigate to, so several instances stay reachable at once while you keep working elsewhere.

TERMINAL
CONSOLE
A workspace, not a page

Open a terminal on one instance, a console on another, and both stay on screen together as separate cards.

Several at once

Each session opens as its own card. Compare two instances side by side, or watch one boot while you work in another.

Drag to arrange

Move a card anywhere on screen and place the ones you are watching where you want them.

Survives navigation

Change pages and the open cards stay with you. Reading a warning or a metric does not close the shell you are in the middle of.

Minimize and restore

Send a card to the bottom right corner to clear the view, and bring it back with the session still connected.

Terminal

A real shell inside the instance, streamed straight to the browser. It is not SSH, so the guest needs no key and no open port.

Console

A graphical console for virtual machines, right in the browser. Switch between text and graphics, or mount an ISO, from the tabs on the same window.

File transfer

Drag a file onto the terminal window and it is pushed into the instance.

Sessions

Every open session is tracked with its protocol, node, instance, duration and transfer rate, and kept in a searchable history after it ends.

04 — Explore the platform

The rest of the product, a page at a time.

Every part of Orcastra,
explained in full.

Each page carries one part of the product in full. Read them in order or jump to the one you came for; every page names the next at its foot.

Instances

Everything an instance depends on: virtual networks, storage pools and volumes, images, and the projects that hold them.

NETWORKS · ACLS · IPAM · POOLS · VOLUMES · IMAGES · PROJECTS
Multi-cluster

Register a cluster and watch its health, then see the whole estate by geography and aggregate capacity.

CLUSTERS · MEMBERS · OPERATIONS · WARNINGS · REGIONS · TECHNOLOGIES
Security

Roles from your identity provider, policies scoped to the resource, break-glass, and certificate lifecycle.

ROLES · POLICIES · IDENTITIES · BREAK-GLASS · MY KEYS · CERTIFICATES
Observability

Live telemetry from the clusters themselves, and the durable record behind it.

MONITORING · ALARMS · OPERATIONS · AUDIT · LOG ARCHIVE
Branding

Rebrand the console for the customers you put in front of it, and preview it before it applies.

LOGOS · THEME · ACCENT · TAGLINE · PREVIEW
Platform

The request path as it actually runs, the stack behind it, and what you need before installing.

FRONTEND · BACKEND · DATABASE · CACHE · IDENTITY · SECRETS · LOGGING
05 — Who runs this

Five situations, each mapping to features that exist.

Built for infrastructure
that stays entirely yours.

06 — No black box

Abstraction that explains itself instead of hiding the machine.

LXD, Incus and MicroCloud,
di-orchestrate, bukan jadi rahasia dapur.

Orcastra turns independent clusters into a single managed estate. Every project, container and virtual machine is reachable from one place, governed by one policy and exposed through one API.

Projects and instances
ACROSS EVERY CLUSTER
Fine-grained RBAC
AUTHENTIK OAUTH2 + OIDC
Full API access
EVERY FEATURE
Organizations
TENANTS, ISOLATED
Orcastra control plane ONE PANE · ANY CLUSTER
LXD
CANONICAL
MicroCloud
CANONICAL
Incus
LINUX CONTAINERS
Why this stack

LXD, Incus and MicroCloud are the easiest virtualization platforms to install, operate and hand over. A few commands get you a working cluster, with no hypervisor licensing in the way.

SHARED RESOURCES FOR ORGANISATIONS CAMPUS & RESEARCH COMPUTE CLIENT-FACING TENANCY
Strengths

Three platforms, one operating model. Pick per site, manage as one.

LIVE MIGRATION BETWEEN NODES

LXD

CANONICAL

KVM virtual machines and full-OS containers in a single platform, with no separate hypervisor stack to run.

Scheduled snapshots with automatic expiry, projects and profiles, and hardware passthrough for GPU, USB and NIC.

Unprivileged containers by default, plus UEFI SecureBoot and vTPM for virtual machines.

Image-based, with built-in stores for most Linux distributions and for Windows virtual machines.

LTS every two years, supported for five, with commercial support available through Ubuntu Pro.

COMPUTE · STORAGE · NETWORK, CLUSTERED

MicroCloud

CANONICAL

A working cluster from four commands, with LXD, MicroCeph and MicroOVN wired together automatically.

Compute, distributed storage and software-defined networking without hand-assembling any of it.

Starts at a single node and scales to roughly 50, with high availability from three members up.

Snap packaging keeps components isolated and security updates streamlined.

Runs on production servers or lightweight edge hardware, on Ubuntu Server or Ubuntu Core.

ONE API, LAPTOP TO FULL RACK

Incus

LINUX CONTAINERS

Community-governed fork of LXD, Apache 2.0 and free of any CLA.

Maintained by the same engineers who originally built LXD.

A complete REST API, so anything the client does an application can do too.

Scales from one laptop instance to a full rack, containers and virtual machines on the same storage and network.

Migration path from an existing LXD estate via lxd-to-incus.

Legible by default

Every layer named, from the click to the kernel.

Every action in the console names the cluster it touches and the API call it makes. Engineers learn the platform by using it, and can still drop to lxc or incus on the node at any moment.

Every console action shows the API request it sends and the underlying lxc/incus command it maps to.

The audit trail names the operator, the target cluster and the exact payload.

YOU SEE EVERY LAYER
Orcastra console WHAT YOU CLICK
REST API call POST /1.0/instances
Cluster daemon LXD · MICROCLOUD · INCUS
Node kernel CGROUPS · KVM · ZFS
TRACEABLE END TO END
NOTHING TO TAKE OVER

We don't want to take over
your backend.

Orcastra sits on top of LXD, MicroCloud and Incus. Nothing is forked, nothing is hidden, and every cluster keeps working the day you turn Orcastra off.

verifying the control plane
$ curl -s http://<host>:8765/health          200 OK

$ docker compose -f docker-compose.prod.yml ps
NAME                            STATUS         PORTS
orcastra-dashboard-backend      Up (healthy)   8765->4050/tcp
orcastra-dashboard-frontend     Up (healthy)   4321->2025/tcp
orcastra-dashboard-postgres     Up (healthy)   5432->5432/tcp
orcastra-dashboard-redis        Up (healthy)   6381->6379/tcp
orcastra-dashboard-fluent-bit   Up (healthy)

# stop all five and your clusters carry on without them
$ lxc list --project platform
Five containers on your own host

Backend, frontend, PostgreSQL, Redis and a log shipper. Each reports its own health, and the backend answers a plain HTTP health check.

Your credentials, your client

Generate a TLS certificate for yourself and drive the cluster with the native client, with no operator in the loop.

Reversible by design

Registering a cluster adds a reader, not a rewrite. Stop the stack and every instance, network and volume keeps running exactly as it was.

07 — Self-host it

Keep the infrastructure.
Run the control plane yourself.

Orcastra is self-hosted and deployed with Docker, licensed GPLv3 with a public repository. There is no hosted service to sign up for.

before you install GPLv3 · SELF-HOSTED
  docker                            required
  lxd / incus / microcloud nodes    api enabled
  client certificate                one per node
  hashicorp vault                   required
  authentik                         required
  opensearch                        optional
Product

Every surface
in the console.

Grouped the way the console groups them, so this page is a map of what you will actually meet after you sign in rather than a second sales pitch.

The homepage argues the case for each of these. This page tells you where they live.

Read the case →
01

Inventory

The daily view. What exists, how it is doing, and what to do about it.

What it watches →
Overview

Aggregate counts across every node, a system alerts panel, node or project views, power actions and one-click terminal access.

Monitoring

Live CPU, memory, storage and network with minimum, average and maximum, top consumers and per-node status.

Clusters

Every registered cluster with its status, API endpoint, platform and assigned zone, plus its lifecycle actions.

Instances

Every container and virtual machine across all nodes and projects, with live addresses and assigned profiles.

02

Clustering

What the cluster itself reports, rather than what the dashboard remembers.

Many clusters, one plane →
Members

Cluster member state, architecture and failure domains, including which member currently holds the database role.

Server

Per-cluster server metadata and the hardware resources that cluster reports.

Operations

Asynchronous cluster tasks still running, with precise timestamps and execution state.

Warnings

Warnings raised by the cluster, categorised by severity and linked to the resource they name.

03

Access

Getting inside an instance without depending on its network.

Then reach it →
Terminals

A real shell inside the instance, as a floating card that survives navigating the rest of the dashboard.

Consoles

A graphical console for virtual machines, with ISO attach, power control and boot-to-firmware.

Sessions

Open sessions with protocol, node, instance, duration and transfer rate, plus a searchable history.

Profiles

Reusable configuration templates applied at instance creation, with the instances currently using each one.

04

Networking

Every interface and every address, mapped to what holds it.

Everything else it manages →
Networks

Create, edit and delete virtual networks, each with its own detail page and live state.

ACLs

Named network access control rules, applied to instances and to networks.

IPAM

Every assigned IPv4 and IPv6 address, mapped to its instance, MAC address and project.

05

Storage and images

Capacity you can see before it runs out, and images that arrive intact.

Everything else it manages →
Pools

Provision and inspect storage pools with capacity reported per pool, across local and distributed backends.

Volumes

Create, resize, attach and delete custom volumes, with snapshots and custom ISO attachments.

Images

What each cluster holds, imports from a remote image server, and resumable uploads with crash recovery.

06

Permissions

Who can reach what, and the credentials that prove it.

Who can do what →
Identities

Client certificates, unrestricted tokens and pending access requests, tracked across the whole estate.

Groups

Node-scoped groups with resource-level permission assignment, from full administration down to read-only.

Tenant access policies

Named policies made of rules — view, operate, console, snapshot, file transfer — granted per cluster, project or instance.

My Keys

Your own TLS client certificate for a target cluster and project, at the level and expiry you choose.

Certificates

Cluster certificate status, issuer, expiry and days remaining, with renewal and regeneration in place.

07

Federation

The estate seen from above, by geography and by hardware.

Regions and capacity →
Regions

Registered clusters on a map, with aggregate cores, memory, storage and GPUs summed per zone.

Technologies

Per node: server and API version, authentication state, kernel, architecture, storage backend and firewall driver, alongside CPU, memory, storage and the GPU cards physically present with their PCI addresses.

08

Settings

The control plane’s own configuration, and its own health.

Make it yours →
General

System preferences, and cache management for the frontend and backend stores.

Integrations

API keys with scope, level and expiry, plus an authenticated passthrough for your own tools.

MCP server

A Model Context Protocol endpoint an AI assistant can query, bound to the same key scope and audit trail as any other caller.

User Groups

Identity federation and role binding across the organizations you manage.

Personalization

Logos, background, theme and accent colour, applied to everyone in the organization at once.

System Info

Host CPU, memory, partitions and network, plus the backend process footprint and runtime.

Thirty surfaces,
one browser session.

Nothing here is a separate product or a paid add-on. It is one self-hosted control plane in front of the clusters you already run.

Product

What an instance
depends on.

Networks, storage, images and the projects that hold them, managed from the same session as the instance itself. Creating and reaching an instance are on the overview.

Networking
Networks

Bridges, physical interfaces and loopbacks on every node in one table, managed and unmanaged alike, each row carrying its addresses and the count of resources and projects using it.

ACLs

Named network access control rules applied to instances and networks.

IPAM

Every assigned address, IPv4 and IPv6, mapped to the instance, MAC address and project holding it.

Storage
Pools

Provision and inspect storage pools, with capacity reported per pool.

Volumes

Create, resize, attach and delete custom volumes.

Volume snapshots

Create, restore and delete, plus a view of snapshots still being taken.

ISO images

Upload an ISO and attach it to a virtual machine for installation or rescue.

Images
Images

List what each cluster holds, import from a remote image server, upload a local image, delete.

Resumable upload

A large image or ISO uploads in chunks against a durable server-side session, so a dropped connection resumes instead of restarting.

Two surfaces

The same upload machinery is exposed to a signed-in Partner in the dashboard and to an external application over an API key.

Projects
Projects

A tenant gets an isolated slice of a cluster. You choose whether images, networks, profiles and storage volumes are isolated inside it.

Resource limits

CPU, memory and storage set per project.

Profiles

Reusable configuration templates applied at instance creation.

Product

Who can reach what,
and whether you can prove it.

Roles resolved from your identity provider, policies scoped to the resource, an audited way in when nobody has standing access, certificates that tell you before they break, and an MCP endpoint held to the same rules.

Who can do what, and who is watching

The role decides which navigation exists at all, not merely which buttons are greyed out.

Three roles, five permissions,
and one audited way in.

Admin, Partner and Tenant resolve from the groups your identity provider already holds. Everything below that is a named policy you write.

HOW A REQUEST RESOLVES EXAMPLE POLICY
GROUP
Tenant
POLICY
platform-readwrite
SCOPED DOWN TO
CLUSTER
PROJECT
INSTANCE
PERMISSIONS GRANTED
view operate console snapshot file transfer

Change the policy and the cached answers that depend on it are flushed, so the next request is judged on the new rule.

Admin
Partner
Tenant
Scope
System-wide.
Its own clusters and organizations.
Project level, inside the organizations it is assigned to.
Organizations
Sees all organizations, their members and cluster bindings.
Sees its own.
Sees what it is assigned.
Clusters
Every registered cluster.
Full control of its own.
Reached through project assignment.
Projects and instances
Everywhere.
In its own clusters.
In assigned projects.
Archive management
Admin only, when the feature is enabled.
No access
No access
TENANT ACCESS POLICIES

Named policies, made of rules, shaped like IAM.

Five permissions, each granted per cluster, project or instance, and assigned to organization members. Changing a policy flushes the cached responses that depend on it, so an access change takes effect immediately.

A policy holds as many rules as it needs, and one policy per organization can be marked the default so a new tenant arrives already scoped instead of arriving with nothing and waiting for someone to notice.

view

Read the resource and everything the tables show about it.

operate

Create, start, stop, restart and delete.

console

Open a graphical console or a terminal.

snapshot

Take, restore and remove snapshots.

file transfer

Push files into an instance.

Each rule names a cluster, a project or a single instance, so access is scoped to the resource rather than to a person.

IDENTITIES AND GROUPS

A group is bound to its environment from the moment it exists.

Scoped at creation

A new group targets a specific node before anything else is set, so an auditing team or a development group is attached to the right environment from the start rather than corrected later.

Resource-level assignment

Choose the resource type, pin the exact project or pool, and set the level from full administration down to read-only.

Credentials in one place

Attach or revoke TLS client certificates and bind external OIDC identities from the group itself, leaving a visible record of who holds which privilege.

The identity inventory

Client certificates, unrestricted tokens and pending access requests, tracked across the whole estate rather than per cluster.

BREAK-GLASS

An Admin does not hold standing access to a tenant’s console.

Reaching one is a deliberate, time-boxed, audited act that the affected tenant can watch happen.

01 Open a grant

Against a specific cluster, with a written justification and an optional ticket reference.

02 Time-box it

For at most 24 hours. There is no standing access to fall back on.

03 Every use is audited

The grant is recorded, and so is each use of it.

04 The tenant sees it

Affected tenants can see the grants raised against their own clusters.

MY KEYS

Drive your own cluster with the native client.

A user generates their own TLS client certificate for a specific cluster and project, at standard or admin authorization level, with an expiry in days. The private key is stored in HashiCorp Vault rather than on disk, and the credential downloads as a PKCS#12 bundle.

No operator hands you a certificate over chat.

API KEYS

An API surface for your own tools.

Create, name, scope, expire and revoke keys for external applications. A key is granted per cluster at read, write or admin level and restricted to an explicit list of projects. Each key records when it was last used. Secrets are hashed with HMAC-SHA256 and never stored in plain form.

A request outside a key’s scope is refused, including an attempt to smuggle a different project through the request path.

INTEGRATIONS

Passthrough, with the guard rails on.

An authenticated passthrough to the LXD API for third-party tools, with a method allowlist, request timeouts and a cap on concurrent in-flight requests. Map a user in an external system to an Orcastra identity with its own per-cluster permissions, and sync organizations, members and branding over the same API key channel.

Read-only mode runs the whole dashboard in an enforced read-only state, with a visible banner, for demos and audits.

MCP SERVER

An agent is a caller, held to the same rules.

Orcastra publishes a Model Context Protocol server, so an AI assistant your team already runs can query the estate over the same scoped key, capability set and audit trail a person is subject to.

No model runs in the control plane. Orcastra performs no inference of its own.

Config handed to you at creation

Create an API key and the dashboard returns the MCP client config beside it: the command, the endpoint and the two credential values.

Two headers, no session

A key ID and a secret on every request. There is no sign-in step and no session token for an agent to hold or leak.

Capability-scoped, read-only first

An agent starts able to ask what exists. Write and exec capabilities are separate grants you add deliberately.

Revocable in one action

Revoke the key and every agent holding it stops at the same instant. The record of what it did remains.

AI ASSISTANTMCP SERVERORCASTRA APICLUSTER
CAPABILITY COVERAGE

What an agent can reach, one grant at a time.

Six capabilities, each granted on its own. The two ticked below are the usual starting pair: enough to answer questions about the estate, and unable to change anything in it.

CAPABILITY LEVEL WHAT IT COVERS
inventory.read read Clusters, nodes, projects, instances, networks, storage pools and volumes, images, regions and aggregate capacity. This is what answers “what do we have, and where”.
lxd.proxy read Cluster state straight from the platform API through the authenticated passthrough, with a method allowlist, request timeouts and a cap on concurrent requests.
storage.upload write Push an image or ISO into a cluster, using the same chunked, resumable upload the dashboard uses.
instance.files write Read and write files inside an instance.
instance.exec admin Run a command inside an instance. The highest-reach capability, and the one worth withholding longest.
tenant.provision admin Create tenants, projects and instances on their behalf.
SCOPED ON TOP

A capability is not estate-wide. The same key also names which clusters it may reach and which projects inside them, so inventory.read on one cluster tells an agent nothing about another.

WHAT IS NEVER COVERED

No capability opens a graphical console, and none grants break-glass. Reaching a tenant console stays a decision a named person makes with a written justification.

REFUSED, NOT FILTERED

A request outside the key’s capabilities or scope is refused outright, including an attempt to smuggle a different project through the request path. The refusal is recorded like any other call.

Certificate lifecycle

Expiry is the most predictable outage there is. It should never surprise you.

Trust that tells you
before it breaks.

Every cluster certificate in one table with its issuer, issue date, expiry and the exact number of days it has left.

TOTAL CERTIFICATES
8
VALID
1
EXPIRING SOON
1
EXPIRED
6
CLUSTER CERTIFICATES, BY TIME REMAINING DASHED MARK = ALERT THRESHOLD
pandora
INTERMEDIATE CA
VALID
20 days remaining RENEW
nuc2
INTERMEDIATE CA
EXPIRING SOON
Expires tomorrow RENEW
blitz01
INTERMEDIATE CA
EXPIRED
Expired 14 days ago RENEW
nuc-2
INTERMEDIATE CA
EXPIRED
Expired 38 days ago RENEW
zbook-semanan
INTERMEDIATE CA
EXPIRED
Expired 45 days ago RENEW
central1-argon
INTERMEDIATE CA
EXPIRED
Expired 151 days ago RENEW
EXPIRY ALERT BROADCAST TO
WARNINGS MONITORING ALARMS OVERVIEW

An expired certificate keeps its row rather than disappearing from the table, with the days elapsed spelled out. A lapsed cluster you are decommissioning and one you forgot look different here.

Alerting is automatic

A certificate nearing expiry is flagged for you and broadcast to three places at once: the Warnings list, the monitoring alarms, and the overview dashboard. You do not have to go looking.

Renewal is a decision

Click Renew to extend a certificate, or deliberately let it lapse when the cluster it belongs to is being decommissioned. Nothing rotates behind your back.

Regeneration you can paste

Recovering a pending or expired trust state produces a ready-to-run command for the target node. Run it, then verify the restored connection from the dashboard before you close the panel.

Private keys are never on disk here

Cluster certificates live in HashiCorp Vault rather than on the dashboard filesystem, and every cluster is reached over mTLS.

Product

Nothing happens
without a trace.

Telemetry streamed from the clusters themselves, and the durable trail behind it: metrics history, the activity audit, shipped logs and archived indices.

What it watches

Telemetry for the whole estate, on one screen, at the resolution you ask for.

Live now,
and why it matters.

Instance distribution, resource metrics, the heaviest consumers and the state of every node, refreshed from the clusters themselves rather than from a cache.

RESOURCE METRICS · CPU
5m15m30m1h6h24h
MINAVGMAX
STREAMED FROM THE CLUSTER, NOT FROM A CACHE
ALARM STATISTICS
CRITICAL
MAJOR
WARNING
INFO
SYNCHRONISED WITH WARNINGS
Instance distribution

The running-to-stopped ratio, kept separate for containers and virtual machines rather than lumped into one number.

Resource metrics

CPU, memory, storage and network I/O, each with minimum, average and maximum overlaid on the series.

The timeframe you need

Five-minute intervals through to twenty-four hours, with zoom in and out on the chart itself.

Top consumers

Sortable highest to lowest, so the instance eating a node is the first row rather than something you hunt for.

Storage pools

Capacity per pool across distributed backends, so a pool approaching its limit is visible before it fills.

Node status

Health, connectivity and resource allocation for every registered node, as cards rather than a buried table.

OPERATIONS AND WARNINGS

What is happening right now, and what is wrong.

A live operations ledger

Every asynchronous cluster task still running, with its precise timestamp and execution state, from an open console session to an instance being provisioned.

Warnings by severity

Critical, major, warning and informational events in one categorised list, surfacing an offline node, a missing network controller or a failing storage mount.

One alarm surface

The alarm statistics matrix on the monitoring page synchronises with this list, so a severity count and the warnings themselves never disagree.

Linked to the resource

A warning raised by a cluster links straight to the resource it names, rather than leaving you to work out which instance it meant.

What it records

From a live metric to an archived index, in one path.

A number on screen now,
and a record of it later.

01 · LIVE
Streamed metrics

CPU, memory, disk and network streamed live, straight from the cluster.

02 · LIVE
Fleet view

A time-series chart you can zoom and pan, the instances consuming the most resources, node connection state, and alerts broken down by severity.

03 · STORED
PostgreSQL history

A background collector writes historical metrics to PostgreSQL, kept for a retention window you configure, and pruned by a periodic task.

04 · STORED
Activity audit log

Every action recorded with the actor and the result, alongside session tracking for every terminal and console session.

05 · SHIPPED
Fluent Bit to OpenSearch

A sidecar tails container output and ships it to OpenSearch, with index lifecycle management applying age-based retention policies.

06 · ARCHIVED
Snapshot repository

Create, list, restore, delete and verify archived indices from the dashboard. Admin only, and the endpoints are not mounted unless the feature is enabled.

07 · QUERIED
OpenSearch Dashboards

Access logs, audit logs and an overview, as dashboards you query directly rather than a log file you grep.

Product

Your brand
on someone else’s control plane.

For anyone who puts this console in front of their own customers. Rebrand the environment, preview it, and apply it to everyone in the organization at once.

PRESET · LIGHT
CUSTOM · HEX ACCENT
PRESET · MIDNIGHT
SAME CONSOLE, THREE ORGANIZATIONS
UNDO REDO RESET PREVIEW
Logos per mode

A light-mode logo, a dark-mode logo and a favicon, uploaded or pulled from a URL.

Landing page background

A hero image with overlay opacity and blur, adjustable until it reads the way you want it to.

Your words

Application name, landing page tagline and the global footer notice, all editable.

Presets or exact hex

Curated theme presets from light through midnight, or type exact hex codes for the accent colour and sidebar.

Contrast handles itself

Sidebar logo and text colours adapt automatically, so a dark brand colour does not make the navigation unreadable.

Safe to experiment

Undo, redo, reset to defaults and a live preview, before anything is applied across the organization.

Product

The request path,
drawn as it actually runs.

What runs where, and what each part talks to. The requirements for installing it are on the overview.

browser
Next.js frontend
FastAPI backend
LXD / Incus / MicroCloud cluster
REST + WEBSOCKET ON mTLS
PostgreSQL
STATE · METRICS HISTORY · AUDIT
Redis
CACHED CLUSTER READS, ENCRYPTED
Authentik
TOKEN VALIDATION
Vault
CLUSTER CERTIFICATES · USER KEYS
frontend and backend stdout
Fluent Bit
OpenSearch
OpenSearch Dashboards
ACCESS · AUDIT · OVERVIEW
Frontend
Next.js 15, React 18, Tailwind CSS, Radix UI
Backend
FastAPI, Python 3.12, async SQLAlchemy, Alembic
Database
PostgreSQL 17
Cache
Redis 8, LRU eviction, values encrypted with Fernet
Identity
Authentik OAuth2 and OIDC, NextAuth 5, JWT validated against JWKS
Secrets
HashiCorp Vault, PKI and cluster certificates
Logging
Fluent Bit sidecar to OpenSearch
Managed infrastructure
LXD, Incus, MicroCloud over REST and WebSocket on mTLS
Deployment
Docker, separate development and production compose files
IN PRODUCTION

Authentik, Vault and OpenSearch run as separate hosts.

The full multi-host topology belongs in the documentation rather than on a marketing page.

docs.orcastra.io →
Licence

Free software,
and it stays that way.

Orcastra is released under the GNU General Public License, version 3. Not source-available, not open-core, not free until you need the useful part. The whole control plane is under one copyleft licence.

GPLv3
GNU GENERAL PUBLIC LICENSE
VERSION 3, 29 JUNE 2007
Read the full licence text →

A control plane you can
audit, fork and keep.

A licence is not a marketing badge. It decides what happens to your infrastructure the day you disagree with us, and GPLv3 answers that question in your favour rather than ours.

NO OPEN-CORE NO PAID TIER NO CLA PUBLIC REPOSITORY
WHAT THE LICENCE GRANTS YOU

Four freedoms, and they are
not ours to withdraw.

00 Run it

Use Orcastra for any purpose, in production, for customers, commercially, with no seat count and nobody to ask.

01 Study it

Read every line that touches your clusters. The repository is public, so an audit needs no vendor cooperation.

02 Change it

Patch it, extend it, strip out what you do not want, and run your version. Nothing in the licence requires our approval.

03 Share it

Redistribute the original or your modified version, provided you pass on the same freedoms under the same licence.

The last clause is the point of copyleft. Whoever receives Orcastra from you receives it under GPLv3 too, so the freedoms travel with the software rather than stopping at the first company to repackage it.

WHAT IT ASKS OF YOU

Obligations, stated plainly.

Running Orcastra internally, however you like, asks nothing of you at all. The obligations begin only when you distribute it to someone else.

Run it privately
No obligation. Deploy it, modify it, keep the changes to yourself. GPLv3 is not a network licence, so operating a service on it does not by itself require publishing anything.
Distribute it
Ship the corresponding source, keep it under GPLv3, and preserve the copyright and licence notices.
Distribute a modified version
The same, and your modifications are covered too. This is the clause that keeps a fork honest.
Patents and hardware
GPLv3 includes an express patent grant and an anti-lock-down provision, so a device shipping Orcastra cannot use signing keys to stop you replacing it.
Combining with your own code
Software you link into a GPLv3 work becomes subject to the licence when you distribute the combination. Calling the REST API from a separate program of yours does not.

This page describes the licence in ordinary language for orientation. The licence text itself is what governs, and it is not legal advice.

THE STACK UNDERNEATH

Open all the way down.

Orcastra manages LXD, Incus and MicroCloud, which are open source themselves, and runs on an open stack. There is no proprietary component holding the middle of it together.

See the platform →
WHERE TO GET IT
Source
The full repository, public, with the history intact.
Deployment
Self-hosted with Docker. There is no hosted service and no signup.
Community
Questions and patches in the open, on the forum.
Support

Same software.
Two ways to be looked after.

Run Orcastra on your own, free, with the community. Or buy a support agreement and put our team on the other end of it. The software is identical either way.

There is no feature difference between the free and the supported version. No locked modules, no enterprise-only screens, no licence key that unlocks the useful part. Paying buys our attention, not extra software.

COMMUNITY

Free, for anyone.

Do not need support? Then do not buy any. Download it, run it, put it in front of your customers. Nobody has to be asked and nothing expires.

Every feature, no exceptions

The whole control plane under GPLv3, the same build a supported customer runs.

Help from the forum

Questions and answers in the open on Discourse, where the archive helps whoever asks next.

Issues on GitHub

Report a bug, read the code that caused it, and follow the fix in public.

ENTERPRISE
PROFESSIONAL SERVICE

Paid, and someone answers.

A commercial support agreement for teams that need a name to call when a cluster misbehaves at an inconvenient hour. You are buying priority and a service level agreement, not a different product.

Priority queue

Your report goes to the front of ours, ahead of community traffic.

An SLA in writing

Response commitments agreed with you in the contract rather than implied by a forum thread.

Our team on your deployment

Help with installation, upgrades and the cluster-side problems that reach the dashboard.

Only for our dashboard

The agreement covers Orcastra. It is not a support contract for LXD, Incus or MicroCloud themselves.

WHO PROVIDES IT

Enterprise support is distributed by
PT Sivali Catur Lestari.

Distributor
PT Sivali Catur Lestari, trading as Sivali Cloud Technology, holds the distribution rights for Orcastra enterprise support.
Sales
[email protected] for a quote, a scoping call, or a copy of the agreement terms.
Subscribe
Visit sivali.co to take out an enterprise support subscription.
The software itself
Unchanged. Orcastra stays GPLv3 with a public repository whether you hold a support agreement or not.
FAQ

Everything you probably want to ask
before putting Orcastra in front of your clusters.

Cannot find the answer? Ask on Discourse, or read the Orcastra repository on GitHub.

General

4 QUESTIONS

What is Orcastra, exactly?

Orcastra is an open-source control plane, or cloud management platform, for managing many LXD, Incus and MicroCloud clusters from one place.

Instead of opening a separate dashboard, CLI or endpoint for every cluster, you get one dashboard and one API for all of them.

Is Orcastra a new hypervisor?

No. Orcastra does not replace LXD, Incus or MicroCloud.

Your infrastructure keeps running on its own platform. Orcastra sits above it as a management layer.

Turn Orcastra off and your instances, networks, storage and clusters carry on exactly as before.

Why not just use the native CLI?

You absolutely can. Orcastra is built so that you keep the native CLI available at all times.

It earns its place once the number of clusters, nodes, projects, users and customers grows and you need:

one inventory one dashboard centralised access control an audit trail monitoring an API multi-cluster operations

The CLI does not go anywhere. Orcastra just makes the operational overhead much smaller.

Who is Orcastra for?

Typically teams whose infrastructure has grown past a single server. For example:

Cloud service providers Managed service providers Platform engineering teams Internal private cloud Campus and research computing Enterprise infrastructure teams Lab or edge infrastructure across several locations

If you run a single-node homelab, Orcastra still works. You may simply not need everything it offers yet.

Platform

5 QUESTIONS

Which platforms are supported?

Orcastra currently focuses on LXD, Incus and MicroCloud.

A single Orcastra deployment can manage several clusters running different platforms.

Can it manage many clusters at once?

Yes. That is one of the main reasons Orcastra exists.

Register as many clusters as you like and see them as one infrastructure estate. They can sit in:

different data centres different cities different countries edge locations different customer environments

Do all clusters have to run the same platform?

No. One site can run LXD, another Incus, another MicroCloud.

Orcastra gives you the same operating experience across all of them.

Can it manage both containers and virtual machines?

Yes. LXD and Incus support system containers and KVM virtual machines, and Orcastra manages both from the same interface.

When you create an instance you simply choose:

Container Lighter, with faster startup.
Virtual machine Full isolation, with its own kernel.

Does Orcastra store its own copy of the cluster configuration?

Orcastra stores what the control plane needs to run, but the cluster remains the real source of truth for your infrastructure.

It does not convert LXD, Incus or MicroCloud into a proprietary format. The principle is simple:

Your cluster stays your cluster.

Deployment

4 QUESTIONS

Is Orcastra SaaS or self-hosted?

Self-hosted. You install Orcastra on your own infrastructure.

There is no requirement to connect to a hosted Orcastra service.

How is Orcastra deployed?

With Docker. The control-plane stack consists of several services:

frontend backend PostgreSQL Redis a log shipper

Secrets and sensitive credentials can be held in HashiCorp Vault.

Do I need an agent inside every VM?

No. Orcastra talks to your clusters through the platform API.

For console and terminal it uses the channel the cluster already provides, without depending on SSH inside the guest.

Do my clusters need a public IP?

What matters is that the Orcastra control plane can reach the cluster API.

The network design is yours. A cluster does not have to be exposed to the internet just so Orcastra can manage it.

Instances

3 QUESTIONS

Can I create an instance directly from Orcastra?

Yes, and you set the whole configuration on one page, including:

instance type image node project CPU memory storage network GPU passthrough cloud-init snapshots security policy migration settings boot order

Orcastra deliberately avoids the long wizard that only reveals an important setting several steps in.

Can I choose the node before deploying?

Yes. Once a node is selected, Orcastra reads the resources actually available on it.

So the network, storage pool and GPU device options match what that node can genuinely provide.

Can I watch provisioning progress?

Yes. The browser receives progress from the cluster event stream over a WebSocket.

You watch provisioning happen instead of refreshing the page repeatedly.

Console and terminal

4 QUESTIONS

The instance has no SSH. Can I still get in?

Yes. The Orcastra terminal does not depend on an SSH daemon inside the instance.

It stays reachable even when:

SSH is not installed SSH is broken there is no public IP the guest network is misbehaving the SSH port is closed

A virtual machine will not boot. Can I recover it from Orcastra?

Yes. Open the graphical console straight from the browser.

For a virtual machine you can also:

watch the boot process enter the console attach an ISO boot to firmware carry out the recovery

Can I open several terminals at once?

Yes. Terminals and consoles appear as floating sessions over the dashboard.

Open a terminal on server A, a console on server B, and move around the rest of the dashboard without losing either session.

Can I transfer files into an instance?

Yes. Files go in through the terminal session, with no need to open SSH or run an extra service inside the guest.

Networking and storage

3 QUESTIONS

Can Orcastra manage networking?

Yes. It shows and manages resources such as:

virtual networks physical interfaces bridges loopbacks ACLs IPv4 IPv6 IP allocation

IPAM also shows which instance, MAC address and project each address belongs to.

Can Orcastra manage storage?

Yes. It works with the storage pools and volumes available on the cluster, so you can:

see capacity create a volume resize a volume attach a volume delete a volume take a snapshot restore a snapshot

Can I upload ISOs and images?

Yes. Images and ISOs upload to the cluster.

Large uploads are resumable, so a dropped connection does not send you back to the beginning.

Projects and multi-tenancy

3 QUESTIONS

Can a cloud provider use Orcastra?

Yes. Organizations, projects, policies and cluster binding are all designed for multi-tenant environments.

A service provider can run Orcastra as the control plane behind the infrastructure they sell.

Can I set a quota per customer?

Resource limits are applied through projects, for example:

CPU memory storage

A project also acts as an isolation boundary for resources such as networks, images, profiles and storage.

Can I brand it for each customer?

Yes. Each organization can carry its own branding:

application name tagline logo favicon accent colour theme footer

A service provider does not have to show the same generic interface to every customer.

Security

5 QUESTIONS

How do login and identity management work?

Orcastra can use an external identity provider over OAuth2 and OIDC.

The roles and groups from that provider then decide what someone can reach inside Orcastra.

Is there RBAC?

Yes. Access is granted per resource. A given user might only be allowed to:

view a cluster operate an instance open a console take a snapshot transfer files

And the scope can be narrowed to a cluster, a project or a single instance.

Does an admin automatically get into every tenant?

Not necessarily. Orcastra has break-glass access for the cases where an admin genuinely needs to enter a tenant environment.

That access:

has to be deliberate carries a justification can be time-boxed is recorded is visible to the tenant

So emergency access does not mean an admin holds permanent access to everything.

Where are cluster credentials stored?

Sensitive credentials can be held in HashiCorp Vault.

Private keys do not have to sit as plain files on the dashboard filesystem.

Is there an audit log?

Yes. Orcastra records activity so you know:

who did something on which cluster to which resource and when

For environments that need accountability, this is considerably more useful than reading somebody’s shell history.

API and automation

3 QUESTIONS

Is every feature available over the API?

Orcastra is designed API-first. What the console can do is exposed over the API as well, so it can be driven by:

an internal portal automation a billing system a provisioning system third-party tools

Can an API key be restricted?

Yes. A key can carry:

a scope an access level an expiry a project restriction

And it can be revoked at any time.

Can I grant API access without full admin?

Yes. Capabilities are granted individually:

inventory.read Read clusters, projects, instances and capacity.
lxd.proxy Reach the cluster API through Orcastra.
storage.upload Upload an image or ISO.
instance.exec Run a command inside an instance.
instance.files Read or write files inside an instance.
tenant.provision Provision tenants, projects and instances.

Not every integration needs admin rights.

AI and MCP

3 QUESTIONS

Does Orcastra have its own AI?

No. Orcastra is not an AI model and runs no LLM in the control plane.

Then what is MCP for?

Orcastra publishes an MCP server so the AI assistant or agent your team already uses can read your infrastructure through Orcastra.

An agent might ask:

which clusters are active? which node is running out of resources? what is running in a given project? which cluster has warnings? how much CPU or memory is there in a region?

Access still follows the capabilities and scope you defined.

Can an AI agent change my infrastructure?

By default, no. Capabilities are granted one at a time.

An agent can start with read-only access, and you decide whether it ever needs more.

AI does not get the keys to the kingdom automatically.

Monitoring and operations

3 QUESTIONS

Does Orcastra include monitoring?

Yes, for infrastructure telemetry such as:

CPU memory storage network node state top resource consumers cluster warnings

The data is read from the clusters Orcastra manages.

Can I monitor certificate expiry?

Yes. Orcastra lists each certificate with its:

issuer issue date expiry date days remaining

A certificate approaching expiry raises a warning before it becomes an outage that was entirely preventable.

Are certificates rotated automatically?

Orcastra does not quietly replace credentials behind your back.

Renewal stays a visible action an operator controls.

Open source

4 QUESTIONS

Is Orcastra genuinely open source?

Yes. Orcastra is released under GPLv3 and the repository is public.

Is there a closed-source enterprise edition?

No. Community users and customers with an enterprise support agreement run the same Orcastra.

There is no:

enterprise-only module important feature behind a lock licence key that unlocks anything separate proprietary build

So what does Enterprise pay for?

You pay for support, not extra software. An enterprise agreement provides:

a priority queue an agreed response time an SLA deployment help upgrade assistance Orcastra troubleshooting

The software itself is identical.

What if I do not want to pay for support?

Then use it for free. Download it, install it, run it in production, even use it to serve your own customers.

There is no trial that suddenly expires.

If you need help, the community is on Discourse and issues can be reported on GitHub.

Support

2 QUESTIONS

Does enterprise support cover LXD, Incus and MicroCloud too?

No. Orcastra enterprise support is support for Orcastra.

The agreement is not automatically a support contract for the underlying LXD, Incus or MicroCloud platforms.

Who provides enterprise support?

Orcastra enterprise support is distributed by PT Sivali Catur Lestari — Sivali Cloud Technology.

For a quotation, scoping or the agreement terms: [email protected]

Still have questions?

Did not find your answer?

Good. That probably means the question deserves a place in this FAQ.

Found a bug? Open an issue on GitHub. Already know how to fix it? A pull request is even more welcome.

Open source works better when the people running it help shape it.

USE CASES

Infrastructure gets complicated.
Managing it doesn’t have to.

One cluster is easy.

The trouble starts when infrastructure spreads across several data centres, branch offices, customers, projects or business units, while the team looking after it stays exactly the same size.

Orcastra brings LXD, Incus and MicroCloud clusters into one control plane.

ORCASTRA CONTROL PLANE
one dashboard · one API · one audit trail
Jakarta
MICROCLOUD
12 instances · 8 GPU
Surabaya
LXD
8 instances · 96 TB
Batam
INCUS
16 instances · warning

Distributed infrastructure, unified operations.

Distributed infrastructure is normal.
Fragmented operations shouldn’t be.

WITHOUT A CONTROL PLANE

Every cluster answers to its own tab, its own credential, its own endpoint.

cluster-jkt cluster-sby customer-a customer-b VPN SSH Grafana Spreadsheet

The estate is knowable only by asking several people at once.

ONE OPERATING LAYER

The same estate, reachable from one place, under one policy.

Inventory Clusters Instances Policy Monitoring API Terminal Audit

Centralised operational visibility. Your existing monitoring stays where it is.

Where does Orcastra fit?

Choose the situation closest to your infrastructure.

Enterprise
Private cloud

Your servers. Your cloud. One place to operate it.

LXD · INCUS · MICROCLOUD
Distributed infrastructure
Multi-site and edge

Jakarta has a cluster. Surabaya has a cluster. One team watches both.

REGIONS · CAPACITY · WARNINGS
Service provider
Cloud provider

Sell your cloud, not your vendor’s dashboard.

ORGANIZATIONS · QUOTA · API
Managed services
MSP

Many customers, many clusters, one operations team.

BREAK-GLASS · AUDIT · POLICY
Governance
Compliance and audit

Prove who reached what, and on whose authority.

RBAC · AUDIT · SESSION HISTORY
Platform team
Internal cloud

A developer needs a VM, not a three-day ticket.

API KEYS · PROJECTS · SCOPES
AI infrastructure
GPU and research

GPUs are expensive. Know who is using them.

GPU INVENTORY · CAPACITY
Operations
Recovery

Server down, network gone, SSH with it.

CONSOLE · ISO · FIRMWARE
01 · ENTERPRISE PRIVATE CLOUD

Build a private cloud.
Do not give the infra team a headache.

You own the servers. You want virtual machines and containers to keep running on your own infrastructure.

What you do not want is every node, cluster, project, network and storage pool managed one at a time.

Orcastra becomes the management layer above LXD, Incus or MicroCloud.

PRIVATE CLOUD
COMPUTE
32 nodes
VIRTUAL MACHINES
184
CONTAINERS
96
STORAGE
420 TB
REGIONS
3
PROJECTS
27
InventoryInstancesNetworkStorageAccessAudit
One dashboard

Virtual machines, containers, networks, storage, projects and clusters in one place.

Multi-cluster

Operate many clusters at once, whatever platform each one runs.

Role and policy

Different teams get different access, scoped to the resource.

Audit trail

You can see who did what, on which cluster, and when.

No black box

The underlying cluster stays native. Nothing is rewritten.

Reversible

Switch Orcastra off and the cluster carries on running.

Enterprise BUMN Financial services Manufacturing Telco Healthcare
02 · MULTI-SITE INFRASTRUCTURE

Jakarta has a cluster.
Surabaya has a cluster.
One team still watches both.

Infrastructure grows by location, by business need, or by project.

Eventually one team is opening several dashboards, a VPN, a terminal and a spreadsheet just to know how everything is doing.

Orcastra makes every site legible as a single infrastructure estate.

Jakarta
MicroCloud
Healthy
384 cores
1.5 TB RAM
220 TB storage
8 GPU
Surabaya
LXD
Healthy
192 cores
768 GB RAM
96 TB storage
0 GPU
Batam
Incus
Warning
128 cores
512 GB RAM
64 TB storage
0 GPU
Bali
LXD
Healthy
64 cores
256 GB RAM
32 TB storage
2 GPU
Makassar
MicroCloud
Unreachable
cores
RAM
storage
GPU
Site health

Which sites are online, and which stopped answering.

Capacity

How much compute is genuinely still available, per zone.

Warnings

Which nodes are unreachable, named rather than averaged away.

Certificates

Which cluster certificate expires soon, before it becomes an outage.

03 · CLOUD SERVICE PROVIDER

Sell your cloud.
Not your vendor’s dashboard.

A local cloud provider does not have to build an entire control plane from nothing.

Orcastra can be the infrastructure layer behind the cloud service you sell.

CUSTOMER
YOUR PORTAL
ORCASTRA API
LXD / INCUS / MICROCLOUD

Your infrastructure. Your customer. Your brand.

ISOLATED PER CUSTOMER
PT Alpha
QUOTA24 CPU
STORAGE2 TB
PT Beta
QUOTA64 CPU
STORAGE5 TB
PT Gamma
QUOTA16 CPU
STORAGE1 TB
Organization per customer

Each customer environment stays separated from the others.

Project isolation

Network, image, profile and storage boundaries inside a cluster.

Resource quota

CPU, memory and storage allocated per customer, validated against the node.

Scoped API key

Connect your own portal without handing it admin rights.

White-label

Your logo, your brand, your customer experience.

Audited access

Reaching a customer console is deliberate, recorded and visible to them.

04 · MANAGED SERVICE PROVIDER

Many customers.
Many clusters.
One operations team.

Customer A runs MicroCloud. Customer B runs LXD. Customer C runs Incus.

Every environment is different. The phone that rings is still yours.

Customer A
MICROCLOUD
STATEHealthy
TICKET
Customer B
LXD
STATEWarning
TICKETINC-4821
Customer C
INCUS
STATEHealthy
TICKET
One console, many estates

Every customer cluster in one inventory, without a separate login for each.

Access on request

No standing admin credential sitting in a password manager forever.

Per-customer policy

What your engineers can do is scoped per customer, not granted globally.

The record follows

Every session is logged against the customer it touched.

BREAK-GLASS ACCESS
REASON
Investigating ticket INC-4821
ACCESS WINDOW
2 hours
TICKET
INC-4821
Grant and open

A managed service should leave the customer in control, not require them to hand over every admin credential permanently.

COMPLIANCE & AUDIT

An auditor does not only ask:
“Is the system secure?”

They ask the specific questions, and they expect the answer to already exist.

Who logged in? Who opened the console? Why did they have access? At what time? To which server? Where is the evidence?
AUDIT TIMELINE
10:21 Ryo ArdianOpened break-glass access
10:23 Console session started
10:27 Instance restarted
10:31 Session closed
RBAC policy break-glass audit session history read-only
INFRASTRUCTURE MODERNIZATION

Modernize the stack.
Keep it understandable.

For organizations starting to build an open-source private cloud, or reducing their dependency on a proprietary virtualization stack.

Orcastra manages the target infrastructure once workloads are running on LXD, Incus or MicroCloud. It does not perform the migration itself.

LEGACY
Traditional virtualization Multiple management layers Licensing dependency
MANAGED BY ORCASTRA
LXD Incus MicroCloud
PLATFORM ENGINEERING

A developer needs a VM.
Not a three-day ticket.

Give every engineer a project, a shell and a scoped token, and give the platform team one place to see all of it.

Developer portal
Internal API
Orcastra
Project
Instance
LEAST PRIVILEGE, GRANTED ONE AT A TIME
inventory.read GRANTED
storage.upload GRANTED
tenant.provision GRANTED
instance.exec WITHHELD
Self-service, bounded

The portal provisions against a key that can only reach the projects you named.

One place to look

The platform team keeps a single inventory across every environment developers touch.

AI & GPU INFRASTRUCTURE

GPUs are expensive.
At minimum, know who is using them.

For an enterprise AI lab, a university AI centre, a GPU private cloud, an ML team or a research infrastructure group.

Orcastra shows which GPUs a node physically has and passes one through. It is not a scheduler and reports no utilisation figure.

JAKARTA AI CLUSTER GPU INVENTORY
Node 01 4× NVIDIA L40S 2 available
Node 02 8× NVIDIA H100 0 available
Node 03 2× NVIDIA A100 1 available

Where a node reports no GPU, the picker says so rather than offering an empty list.

GPU capacity per site

Which cards exist, on which node, and how many are still unassigned.

Passthrough by device or address

Pick a physical GPU on the target node, or enter a PCI address.

Attached to a project

A GPU instance belongs to a project, so the allocation has an owner.

CAMPUS & RESEARCH

One infrastructure.
Many labs, lecturers, students and projects.

Shared compute, divided into projects with their own boundaries and their own limits.

AI Research Lab
GPU ACCESS
4 GPU · 12 instances
Computer Science Lab
VM QUOTA
64 CPU · 256 GB
Student Project
LIMITED RESOURCES
8 CPU · 32 GB
External Researcher
PROJECT-ONLY ACCESS
read + console
RECOVERY

Server down.
Network gone.
SSH went with it.

Sometimes the dashboard is not enough. You just need a way back into the machine.

Console and terminal run over the cluster’s own channel, so no public IP, no SSH daemon and no working guest network is required.

recovery-01 · console TEXTGRAPHICSISO
GUEST DISPLAY, OVER THE CLUSTER CHANNEL
BOOTCONSOLEISO ATTACHFIRMWAREFILE TRANSFERRECONNECT
recovery-01 · terminal
root@recovery-01:~# mount -o remount,rw /
root@recovery-01:~# 
No public IP required

The channel belongs to the cluster, not to the guest network.

No SSH required

Nothing has to be installed or running inside the instance first.

Attach the installer

Upload an ISO, attach it, and boot to firmware from the same window.

Push a file straight in

Drag a file onto the terminal and it lands inside the instance.

DR OPERATIONS

A DR site checked once a year
is not a DR strategy.

Orcastra does not perform replication and does not replace a DR orchestration system. It gives you visibility and operational access to the recovery infrastructure.

PRIMARY
Healthy
DR SITE
Healthy
CERTIFICATE
Valid
STORAGE
68% free
CLUSTER
Online
LEAN INFRASTRUCTURE TEAM

The infrastructure team is four people.
The server count is in the hundreds.

Infrastructure is allowed to grow. The operations team does not have to grow with it.

BEFORE
VPN SSH Spreadsheet Dashboard Terminal Monitoring Ticket
WITH ORCASTRA
Inventory Monitor Operate Access Audit
AI-ASSISTED OPERATIONS

Let AI read the infrastructure.
Do not hand it root.

Orcastra is not the model. No LLM runs inside the control plane.

It publishes an MCP server, so the assistant your team already uses can read the estate through a key you scoped and can revoke.

Which nodes in Jakarta still have GPU capacity?
Which certificates expire this month?
Show stopped instances in Surabaya.
Which clusters are unreachable?
AI ASSISTANTMCP SERVERORCASTRAINFRASTRUCTURE
jakarta-01 · node 01 · 2 of 4 L40S unassigned
Read-only first

An agent starts able to ask what exists, and nothing more.

Capability-based

Each capability is a separate grant, not a role that implies the rest.

Same audit trail

An agent call is recorded with its actor and result, like a person’s.

Revocable

Revoke the key and every agent holding it stops in the same instant.

QUICK ORIENTATION

Which capabilities each situation leans on.

Every capability is available in every deployment. This is only a map of which ones each situation tends to reach for first.

MULTI-CLUSTER MULTI-TENANT AUDIT API CONSOLE MCP
Enterprise private cloud
Multi-site
Cloud provider
MSP
Compliance
Platform engineering
Campus
AI infrastructure

Different industries.
The same operational problem.

Whether you are an enterprise, a cloud provider, an MSP, a university, a government body, a research centre, a telco, a bank or a manufacturer, the problem is usually identical.

Infrastructure is spread out. There are too many tools. Access gets harder to control. And the bigger the estate grows, the harder it becomes to answer a simple question.

01

What do we have?

02

Where is it?

03

Who can reach it?

04

What is broken?

05

How much capacity is left?

Orcastra answers all five from one place.

TECHNICAL FOUNDATION

Same infrastructure.
Better operating layer.

Three platforms underneath, one operating model above. Pick per site, manage as one.

CANONICAL
LXD

Virtual machines and system containers in one platform.

CANONICAL
MicroCloud

A compact private cloud stack built around LXD, MicroCeph and MicroOVN.

LINUX CONTAINERS
Incus

A community-driven system container and virtual machine manager.

Orcastra INVENTORY · OPERATIONS · POLICY · MONITORING · API · CONSOLE · AUDIT

Orcastra does not take over
your infrastructure.

Native stays native

LXD stays LXD. Incus stays Incus. MicroCloud stays MicroCloud.

No proprietary data plane

Your workloads remain on the underlying platform, in its own format.

Reversible by design

Turn Orcastra off and the cluster keeps running exactly as before.

Open source

GPLv3, with a public repository and no contributor licence agreement.

One control plane.
Your infrastructure stays yours.

Manage LXD, Incus and MicroCloud across clusters, sites, teams and customers.

NO INFRASTRUCTURE TAKEOVER NO HOSTED CONTROL PLANE NO BLACK BOX
Multi-cluster

Manage every cluster
from one place.

Add an existing LXD, MicroCloud or Incus cluster and Orcastra inventories its projects, instances, storage and networks for you.

jakarta-01MicroCloud · 5 nodes
surabaya-01LXD · 3 nodes
singapore-01Incus · 4 nodes
Orcastra control plane
Console (SPICE)
REST API
Terminal
01Global visibility

A single inventory across every cluster and region, filtered by project, cluster, status or tag.

02Projects everywhere

A team's project spans clusters. Quotas, networks and images follow the project rather than the machine it happens to live on.

03Unified operations

Create, start, stop, restart and delete instances with one workflow, whether the target is a container or a virtual machine.

04One API

One REST surface in front of every cluster. Your own applications reach it with a scoped API key, or through an authenticated passthrough to the LXD API.

05Scoped access

Roles bind to projects and clusters. An operator in Surabaya never sees the Singapore inventory unless policy says so.

Product UI

The cluster inventory shown directly at full width, with no device frame around it.

Many clusters, one plane

Orcastra is a control plane. Your clusters keep running exactly where they are.

One control plane.
Every cluster you already run.

REGION
CLUSTER
PROJECT
INSTANCE
OrcastraOne control plane
Jakarta
Surabaya
Singapore
MicroCloud
LXD
Incus
LXD
MicroCloud
Incus
12 projects
7 projects
4 projects
container · virtual machine
container · virtual machine
container · virtual machine
Clusters
Register a cluster, discover it, and watch its health.
Members
LXD and MicroCloud cluster member state.
Server
Per-cluster server metadata and hardware resources.
Operations
A live view of asynchronous cluster operations still running.
Warnings
Warnings raised by the cluster itself, each linking to the resource it names.
Node registration
A new node arrives with its endpoint, facility, operator and region recorded.
Certificates
Renew, verify and regenerate cluster certificates, with expiry warnings across every cluster.
Version checks
The dashboard flags LXD and MicroCloud versions it does not support.
Regions
Nodes grouped by geographic region, each with a hardware summary and zone information.
Technologies
An aggregated hardware and software inventory across every connected node.
Regions and capacity

A macroscopic view of where your infrastructure actually sits.

Every site you run,
and what is left in it.

Registered clusters plotted on a map, with the aggregate compute behind each marker: cores, memory, storage and GPUs, totalled per zone.

AGGREGATE CAPACITY BY ZONE ALLOCATED OF TOTAL
CORESMEMORYSTORAGEGPU
Jakarta
PRIMARY FACILITY
Singapore
COLOCATION
Surabaya
EDGE SITE
Federated total
Aggregate capacity per zone

Cores, memory, storage and GPU availability summed across every federated zone, so you can size a deployment before you start it.

Facilities, not just cities

Each regional card names the data centre or facility it represents, alongside a snapshot of the hardware in it.

Expand for the hardware

Open a region to see CPU socket configuration, specific GPU models and storage backends such as NVMe or ZFS.

Live instance ratio

The running-to-stopped split for that area, next to the list of nodes operating inside the boundary.

Jump to the map

Every node in the expanded view carries a shortcut that pinpoints it on the map.

Locations from a directory

Assigning a cluster a location means picking from a searchable directory of regions, cities and provinces, not typing free text.

Bring a cluster under management.
Change nothing inside it.