🔒 OptimusHub is SOC 2 ready - built for air-gapped and regulated environments
Product

A self-hosted operational control hub for critical infrastructure

OptimusHub is a local management and operations layer that installs inside your network and connects to the infrastructure you already run - VMs, Kubernetes clusters, databases, and delivery pipelines - through one interface, one permission model, and one audit trail. It standardizes how you deploy, manage, and operate what's already there; it does not replace your container runtime, orchestrator, or the tools that build your software, and it is not a component in your application's request path.

Talk to us about your operating environment →
Eight categories, one control plane

Everything to run on-prem without the chaos.

No add-ons, no integrations to maintain. Every category below is deployed, managed, and audited from the same platform.

Infrastructure

vSphere & VM Management

Power, clone, resize, snapshot, and browser-console any VM. DR plans with RTO/RPO targets, DRS affinity groups, and self-service provisioning with approval flows.

Kubernetes

Full Cluster Control

Manage workloads, Helm releases, namespaces, and pod exec across clusters. Namespace-level RBAC - viewer or manager per namespace per user. Air-gapped cluster import wizard requires no internet.

Catalogs

Apps, Data & Monitoring

Deploy internal apps, databases (PostgreSQL, MySQL, Redis, Kafka), and monitoring stacks (Prometheus, Grafana, Loki) from unified catalogs - via Helm, Ansible, or Docker Compose.

Security

Secrets, Certs & Vault

Built-in PKI/CA: issue, auto-renew, and revoke internal TLS certificates. Fernet-encrypted secrets vault for SSH keys, kubeconfigs, registry credentials, and DB connections.

Observability

Audit, Alerts & Logs

Immutable audit trail of every platform action - who, what, when, from where. Threshold alert rules with SMTP delivery. Live deployment log streaming and SSH tail.

Data

Backup & Query Studio

Encrypted database backup policies with cron schedules and on-demand runs. In-browser Query Studio for SQL (PostgreSQL, MySQL, MariaDB) and NoSQL (MongoDB, Redis).

Developer Tools

CLI, Workspaces & SSH

opti CLI covers every platform resource from the terminal - device-flow login or API tokens for CI/CD. Language-aware dev workspaces with browser VS Code. Audited SSH console and internal web proxy.

Access Control

RBAC, SSO & Groups

Three built-in roles plus custom roles with granular per-feature permissions. SSO via LDAP, OIDC, and SAML with group-to-role mapping. Namespace-level Kubernetes access grants.

Connect. Standardize. Operate. Audit.

1

Connect

OptimusHub connects to the clusters, VMs, databases, and pipelines you already run, using credentials and network paths you configure.

2

Standardize

Define deployment and operational workflows once, as a repeatable definition instead of a runbook.

3

Operate

Apply that definition consistently across sites, environments, and teams from one interface.

4

Audit

Every action is recorded in one trail your team - and your auditors - can actually read.

What changes about your architecture if you adopt it.

OptimusHub is
  • A local management and operations layer, installed inside your network
  • A standardized way to deploy, manage, and operate what you already run
  • Built for on-premise, hybrid, and air-gapped environments from day one
  • Useful to IT, DevOps, DBA, and software-delivery teams - not just Kubernetes specialists
OptimusHub is not
  • A cloud service that hosts your systems or data
  • A replacement for Kubernetes, Docker, Helm, or your existing cluster
  • A runtime dependency for your applications
  • A component in your application's traffic path
  • A network redesign or a virtualization platform
Where this fits

A control layer, not a replacement for everything you run.

OptimusHub is a self-hosted operational control hub designed for teams that need to coordinate critical infrastructure across on-premises, hybrid, and restricted environments. Its role is not to replace every system teams already use. Its role is to make the operational paths between those systems more consistent, controlled, and easier to run.

Explore by operating reality

Frequently asked questions

Infrastructure

What infrastructure does OptimusHub require to run?
OptimusHub runs in Docker and is intentionally not built around Kubernetes. Its core value is the ability to reach and orchestrate the virtual machines and compute resources that organizations already operate, so it is designed to fit real enterprise VM estates rather than require a Kubernetes-first model.
Can OptimusHub run entirely on-premises?
Yes. OptimusHub is designed for on-premises and private environments, and it can be deployed inside your own network perimeter. External connectivity is only required for the integrations you choose to enable, such as Git or other third-party services.
Does OptimusHub support hybrid environments?
Yes. OptimusHub is built to operate across mixed infrastructure estates, including on-premises resources and cloud environments. The goal is to give organizations one operational layer across heterogeneous infrastructure instead of forcing them into a single hosting model.

Deployment capabilities

Can OptimusHub deploy both infrastructure and applications?
Yes. It can provision infrastructure and deploy applications from the same platform; today it supports managing Docker Compose and Helm-based workloads, and for cloud infrastructure provisioning it uses Pulumi rather than Terraform.
How is OptimusHub's built-in CI/CD different from standard Git-based pipelines?
OptimusHub includes a native CI/CD engine that goes beyond basic repository-triggered jobs. A pipeline can continue all the way to creating a real application entry in the platform catalog, which makes it much closer to an end-to-end platform workflow than a conventional "run steps and exit" pipeline.

Developer experience

What does the developer experience look like in OptimusHub?
A developer can create a full development environment with a single click. That environment is already connected to Git, based on a ready-made template, and includes a Web IDE connected to the same environment. OptimusHub currently supports templates for seven programming languages.
Can different teams get access to different areas in OptimusHub?
Yes. OptimusHub supports giving different teams access to different places and capabilities through its permission system. It is not yet a deeper multi-layer tenant model, but it supports practical access separation between teams today.
How fast can an organization get started with OptimusHub?
Getting started is meant to be fast. The platform is packaged for quick installation, and in practice organizations should be able to get it up and gain access to its capabilities within hours, not weeks.

See where this fits into what you already run.

Bring one environment or workflow. We'll help map the current friction and where a control layer would actually sit.

Talk to us about your operating environment →