Orcastra Orcastra
USE CASES

Infrastructure gets complicated.
Managing it doesn’t have to.

One cluster is easy.

The trouble starts when infrastructure spreads across several data centres, branch offices, customers, projects or business units, while the team looking after it stays exactly the same size.

Orcastra brings LXD, Incus and MicroCloud clusters into one control plane.

ORCASTRA CONTROL PLANE
one dashboard · one API · one audit trail
Jakarta
MICROCLOUD
12 instances · 8 GPU
Surabaya
LXD
8 instances · 96 TB
Batam
INCUS
16 instances · warning

Distributed infrastructure, unified operations.

Distributed infrastructure is normal.
Fragmented operations shouldn’t be.

WITHOUT A CONTROL PLANE

Every cluster answers to its own tab, its own credential, its own endpoint.

cluster-jkt cluster-sby customer-a customer-b VPN SSH Grafana Spreadsheet

The estate is knowable only by asking several people at once.

ONE OPERATING LAYER

The same estate, reachable from one place, under one policy.

Inventory Clusters Instances Policy Monitoring API Terminal Audit

Centralised operational visibility. Your existing monitoring stays where it is.

Where does Orcastra fit?

Choose the situation closest to your infrastructure.

Enterprise
Private cloud

Your servers. Your cloud. One place to operate it.

LXD · INCUS · MICROCLOUD
Distributed infrastructure
Multi-site and edge

Jakarta has a cluster. Surabaya has a cluster. One team watches both.

REGIONS · CAPACITY · WARNINGS
Service provider
Cloud provider

Sell your cloud, not your vendor’s dashboard.

ORGANIZATIONS · QUOTA · API
Managed services
MSP

Many customers, many clusters, one operations team.

BREAK-GLASS · AUDIT · POLICY
Governance
Compliance and audit

Prove who reached what, and on whose authority.

RBAC · AUDIT · SESSION HISTORY
Platform team
Internal cloud

A developer needs a VM, not a three-day ticket.

API KEYS · PROJECTS · SCOPES
AI infrastructure
GPU and research

GPUs are expensive. Know who is using them.

GPU INVENTORY · CAPACITY
Operations
Recovery

Server down, network gone, SSH with it.

CONSOLE · ISO · FIRMWARE
01 · ENTERPRISE PRIVATE CLOUD

Build a private cloud.
Do not give the infra team a headache.

You own the servers. You want virtual machines and containers to keep running on your own infrastructure.

What you do not want is every node, cluster, project, network and storage pool managed one at a time.

Orcastra becomes the management layer above LXD, Incus or MicroCloud.

PRIVATE CLOUD
COMPUTE
32 nodes
VIRTUAL MACHINES
184
CONTAINERS
96
STORAGE
420 TB
REGIONS
3
PROJECTS
27
InventoryInstancesNetworkStorageAccessAudit
One dashboard

Virtual machines, containers, networks, storage, projects and clusters in one place.

Multi-cluster

Operate many clusters at once, whatever platform each one runs.

Role and policy

Different teams get different access, scoped to the resource.

Audit trail

You can see who did what, on which cluster, and when.

No black box

The underlying cluster stays native. Nothing is rewritten.

Reversible

Switch Orcastra off and the cluster carries on running.

Enterprise BUMN Financial services Manufacturing Telco Healthcare
02 · MULTI-SITE INFRASTRUCTURE

Jakarta has a cluster.
Surabaya has a cluster.
One team still watches both.

Infrastructure grows by location, by business need, or by project.

Eventually one team is opening several dashboards, a VPN, a terminal and a spreadsheet just to know how everything is doing.

Orcastra makes every site legible as a single infrastructure estate.

Jakarta
MicroCloud
Healthy
384 cores
1.5 TB RAM
220 TB storage
8 GPU
Surabaya
LXD
Healthy
192 cores
768 GB RAM
96 TB storage
0 GPU
Batam
Incus
Warning
128 cores
512 GB RAM
64 TB storage
0 GPU
Bali
LXD
Healthy
64 cores
256 GB RAM
32 TB storage
2 GPU
Makassar
MicroCloud
Unreachable
cores
RAM
storage
GPU
Site health

Which sites are online, and which stopped answering.

Capacity

How much compute is genuinely still available, per zone.

Warnings

Which nodes are unreachable, named rather than averaged away.

Certificates

Which cluster certificate expires soon, before it becomes an outage.

03 · CLOUD SERVICE PROVIDER

Sell your cloud.
Not your vendor’s dashboard.

A local cloud provider does not have to build an entire control plane from nothing.

Orcastra can be the infrastructure layer behind the cloud service you sell.

CUSTOMER
YOUR PORTAL
ORCASTRA API
LXD / INCUS / MICROCLOUD

Your infrastructure. Your customer. Your brand.

ISOLATED PER CUSTOMER
PT Alpha
QUOTA24 CPU
STORAGE2 TB
PT Beta
QUOTA64 CPU
STORAGE5 TB
PT Gamma
QUOTA16 CPU
STORAGE1 TB
Organization per customer

Each customer environment stays separated from the others.

Project isolation

Network, image, profile and storage boundaries inside a cluster.

Resource quota

CPU, memory and storage allocated per customer, validated against the node.

Scoped API key

Connect your own portal without handing it admin rights.

White-label

Your logo, your brand, your customer experience.

Audited access

Reaching a customer console is deliberate, recorded and visible to them.

04 · MANAGED SERVICE PROVIDER

Many customers.
Many clusters.
One operations team.

Customer A runs MicroCloud. Customer B runs LXD. Customer C runs Incus.

Every environment is different. The phone that rings is still yours.

Customer A
MICROCLOUD
STATEHealthy
TICKET
Customer B
LXD
STATEWarning
TICKETINC-4821
Customer C
INCUS
STATEHealthy
TICKET
One console, many estates

Every customer cluster in one inventory, without a separate login for each.

Access on request

No standing admin credential sitting in a password manager forever.

Per-customer policy

What your engineers can do is scoped per customer, not granted globally.

The record follows

Every session is logged against the customer it touched.

BREAK-GLASS ACCESS
REASON
Investigating ticket INC-4821
ACCESS WINDOW
2 hours
TICKET
INC-4821
Grant and open

A managed service should leave the customer in control, not require them to hand over every admin credential permanently.

COMPLIANCE & AUDIT

An auditor does not only ask:
“Is the system secure?”

They ask the specific questions, and they expect the answer to already exist.

Who logged in? Who opened the console? Why did they have access? At what time? To which server? Where is the evidence?
AUDIT TIMELINE
10:21 Ryo ArdianOpened break-glass access
10:23 Console session started
10:27 Instance restarted
10:31 Session closed
RBAC policy break-glass audit session history read-only
INFRASTRUCTURE MODERNIZATION

Modernize the stack.
Keep it understandable.

For organizations starting to build an open-source private cloud, or reducing their dependency on a proprietary virtualization stack.

Orcastra manages the target infrastructure once workloads are running on LXD, Incus or MicroCloud. It does not perform the migration itself.

LEGACY
Traditional virtualization Multiple management layers Licensing dependency
MANAGED BY ORCASTRA
LXD Incus MicroCloud
PLATFORM ENGINEERING

A developer needs a VM.
Not a three-day ticket.

Give every engineer a project, a shell and a scoped token, and give the platform team one place to see all of it.

Developer portal
Internal API
Orcastra
Project
Instance
LEAST PRIVILEGE, GRANTED ONE AT A TIME
inventory.read GRANTED
storage.upload GRANTED
tenant.provision GRANTED
instance.exec WITHHELD
Self-service, bounded

The portal provisions against a key that can only reach the projects you named.

One place to look

The platform team keeps a single inventory across every environment developers touch.

AI & GPU INFRASTRUCTURE

GPUs are expensive.
At minimum, know who is using them.

For an enterprise AI lab, a university AI centre, a GPU private cloud, an ML team or a research infrastructure group.

Orcastra shows which GPUs a node physically has and passes one through. It is not a scheduler and reports no utilisation figure.

JAKARTA AI CLUSTER GPU INVENTORY
Node 01 4× NVIDIA L40S 2 available
Node 02 8× NVIDIA H100 0 available
Node 03 2× NVIDIA A100 1 available

Where a node reports no GPU, the picker says so rather than offering an empty list.

GPU capacity per site

Which cards exist, on which node, and how many are still unassigned.

Passthrough by device or address

Pick a physical GPU on the target node, or enter a PCI address.

Attached to a project

A GPU instance belongs to a project, so the allocation has an owner.

CAMPUS & RESEARCH

One infrastructure.
Many labs, lecturers, students and projects.

Shared compute, divided into projects with their own boundaries and their own limits.

AI Research Lab
GPU ACCESS
4 GPU · 12 instances
Computer Science Lab
VM QUOTA
64 CPU · 256 GB
Student Project
LIMITED RESOURCES
8 CPU · 32 GB
External Researcher
PROJECT-ONLY ACCESS
read + console
RECOVERY

Server down.
Network gone.
SSH went with it.

Sometimes the dashboard is not enough. You just need a way back into the machine.

Console and terminal run over the cluster’s own channel, so no public IP, no SSH daemon and no working guest network is required.

recovery-01 · console TEXTGRAPHICSISO
GUEST DISPLAY, OVER THE CLUSTER CHANNEL
BOOTCONSOLEISO ATTACHFIRMWAREFILE TRANSFERRECONNECT
recovery-01 · terminal
root@recovery-01:~# mount -o remount,rw /
root@recovery-01:~# 
No public IP required

The channel belongs to the cluster, not to the guest network.

No SSH required

Nothing has to be installed or running inside the instance first.

Attach the installer

Upload an ISO, attach it, and boot to firmware from the same window.

Push a file straight in

Drag a file onto the terminal and it lands inside the instance.

DR OPERATIONS

A DR site checked once a year
is not a DR strategy.

Orcastra does not perform replication and does not replace a DR orchestration system. It gives you visibility and operational access to the recovery infrastructure.

PRIMARY
Healthy
DR SITE
Healthy
CERTIFICATE
Valid
STORAGE
68% free
CLUSTER
Online
LEAN INFRASTRUCTURE TEAM

The infrastructure team is four people.
The server count is in the hundreds.

Infrastructure is allowed to grow. The operations team does not have to grow with it.

BEFORE
VPN SSH Spreadsheet Dashboard Terminal Monitoring Ticket
WITH ORCASTRA
Inventory Monitor Operate Access Audit
AI-ASSISTED OPERATIONS

Let AI read the infrastructure.
Do not hand it root.

Orcastra is not the model. No LLM runs inside the control plane.

It publishes an MCP server, so the assistant your team already uses can read the estate through a key you scoped and can revoke.

Which nodes in Jakarta still have GPU capacity?
Which certificates expire this month?
Show stopped instances in Surabaya.
Which clusters are unreachable?
AI ASSISTANTMCP SERVERORCASTRAINFRASTRUCTURE
jakarta-01 · node 01 · 2 of 4 L40S unassigned
Read-only first

An agent starts able to ask what exists, and nothing more.

Capability-based

Each capability is a separate grant, not a role that implies the rest.

Same audit trail

An agent call is recorded with its actor and result, like a person’s.

Revocable

Revoke the key and every agent holding it stops in the same instant.

QUICK ORIENTATION

Which capabilities each situation leans on.

Every capability is available in every deployment. This is only a map of which ones each situation tends to reach for first.

MULTI-CLUSTER MULTI-TENANT AUDIT API CONSOLE MCP
Enterprise private cloud
Multi-site
Cloud provider
MSP
Compliance
Platform engineering
Campus
AI infrastructure

Different industries.
The same operational problem.

Whether you are an enterprise, a cloud provider, an MSP, a university, a government body, a research centre, a telco, a bank or a manufacturer, the problem is usually identical.

Infrastructure is spread out. There are too many tools. Access gets harder to control. And the bigger the estate grows, the harder it becomes to answer a simple question.

01

What do we have?

02

Where is it?

03

Who can reach it?

04

What is broken?

05

How much capacity is left?

Orcastra answers all five from one place.

TECHNICAL FOUNDATION

Same infrastructure.
Better operating layer.

Three platforms underneath, one operating model above. Pick per site, manage as one.

CANONICAL
LXD

Virtual machines and system containers in one platform.

CANONICAL
MicroCloud

A compact private cloud stack built around LXD, MicroCeph and MicroOVN.

LINUX CONTAINERS
Incus

A community-driven system container and virtual machine manager.

Orcastra INVENTORY · OPERATIONS · POLICY · MONITORING · API · CONSOLE · AUDIT

Orcastra does not take over
your infrastructure.

Native stays native

LXD stays LXD. Incus stays Incus. MicroCloud stays MicroCloud.

No proprietary data plane

Your workloads remain on the underlying platform, in its own format.

Reversible by design

Turn Orcastra off and the cluster keeps running exactly as before.

Open source

GPLv3, with a public repository and no contributor licence agreement.

One control plane.
Your infrastructure stays yours.

Manage LXD, Incus and MicroCloud across clusters, sites, teams and customers.

NO INFRASTRUCTURE TAKEOVER NO HOSTED CONTROL PLANE NO BLACK BOX