Deployment¶
Kapelle is a control plane (Postgres, NATS, OpenBao, LiteLLM, the controller, the workers, the surface gateway, the Console and the edge) plus one or more sandbox hosts. The same stack runs on a developer's Linux laptop and on servers, with no Kubernetes.
Control plane¶
Docker Compose files under deploy/compose/, in profiles you add as you need them: storage, services,
surfaces, edge (public names and TLS), observability and the dedicated NATS accounts. just dev-up starts the
base stack and just --list shows the profile recipes (dev-up-services, dev-up-edge, dev-up-mattermost,
...). Every variable and profile is in the dev environment; a first run from a clone is
getting started. The deployment's public address is KAPELLE_PUBLIC_BASE_URL, and the
first Console admin is created with just console-admin create (Console API).
Sandbox hosts¶
- Firecracker hosts need
/dev/kvm, run the host daemonvmdand the credential gatewaycredgwd, and are provisioned withdeploy/host/provision.sh(--checkis a dry run that is safe anywhere;--applyneeds root and changes kernel tunables, so it is for a dedicated host, never a workstation).deploy/host/README.mdlists what it installs: the pinned Firecracker and jailer, system users, systemd units, log rotation and a production sudoers grant. A host is then registered with the controller (deploy/host/register-host.sh).just doctorchecks a host's prerequisites. - Nevia (Aiven's computers) is the other provider; its setup and the golden image are in
deploy/nevia/and the dev environment's "Running a team on Nevia" section.
Upgrades and checks¶
Upgrades is the runbook for every pinned component, just versions compares each pin with its
upstream, and CI describes what each workflow checks. Never run provisioning scripts or experiments
against a host that holds teams you care about.
Secrets¶
Long-lived secrets live in OpenBao and are entered through the Console or PUT /secrets/{name}; none is stored
in the repository or inside a sandbox. See egress and destinations.
Depth: architecture, Operations and security and Agent microVMs.