Skip to content

Deployment

Kapelle is a control plane (Postgres, NATS, OpenBao, LiteLLM, the controller, the workers, the surface gateway, the Console and the edge) plus one or more sandbox hosts. The same stack runs on a developer's Linux laptop and on servers, with no Kubernetes.

Control plane

Docker Compose files under deploy/compose/, in profiles you add as you need them: storage, services, surfaces, edge (public names and TLS), observability and the dedicated NATS accounts. just dev-up starts the base stack and just --list shows the profile recipes (dev-up-services, dev-up-edge, dev-up-mattermost, ...). Every variable and profile is in the dev environment; a first run from a clone is getting started. The deployment's public address is KAPELLE_PUBLIC_BASE_URL, and the first Console admin is created with just console-admin create (Console API).

Sandbox hosts

  • Firecracker hosts need /dev/kvm, run the host daemon vmd and the credential gateway credgwd, and are provisioned with deploy/host/provision.sh (--check is a dry run that is safe anywhere; --apply needs root and changes kernel tunables, so it is for a dedicated host, never a workstation). deploy/host/README.md lists what it installs: the pinned Firecracker and jailer, system users, systemd units, log rotation and a production sudoers grant. A host is then registered with the controller (deploy/host/register-host.sh). just doctor checks a host's prerequisites.
  • Nevia (Aiven's computers) is the other provider; its setup and the golden image are in deploy/nevia/ and the dev environment's "Running a team on Nevia" section.

Upgrades and checks

Upgrades is the runbook for every pinned component, just versions compares each pin with its upstream, and CI describes what each workflow checks. Never run provisioning scripts or experiments against a host that holds teams you care about.

Secrets

Long-lived secrets live in OpenBao and are entered through the Console or PUT /secrets/{name}; none is stored in the repository or inside a sandbox. See egress and destinations.

Depth: architecture, Operations and security and Agent microVMs.