Basalt Basalt
Basalt Basalt
Rows of bare-metal server racks in a dimly lit datacenter corridor

Now with MCP AI integration

Enterprise Hyperconverged Infrastructure

Basalt replaces VMware vSphere + NSX with a Rust-native HCI control plane. Database-enforced tenancy, FIPS 140-3 cryptography, and air-gap operations are built in.

  • FIPS 140-3
  • Zero OpenSSL
  • Postgres RLS
  • Air-gap ready

Platform architecture

Desired state is the control plane

Postgres holds the desired state. Three binaries reconcile it.

The gateway projects per-host manifests, agents reconcile them, and Postgres enforces tenant isolation with row-level security.

Virtualization control-plane diagram — gateway, agent, image service, and Postgres layered into the hardware rack

Gateway · Agent · Image Service · Postgres

Brokerless control plane

0 message brokers

State changes land in Postgres. The gateway, image service, and host agents converge from the same row-level-secured source.

  1. 01 Gateway projects manifests
  2. 02 Image service publishes boot media
  3. 03 Agent converges each host

Core capabilities

One API. Four domains.

Every operation becomes the same auditable task shape before it reaches compute, network, storage, or trust controls.

Canonical control surface

API task model

Requests enter once, become tenant-scoped tasks, and reconcile through the same desired-state ledger.

04
domains
01
task contract

/compute

Compute sovereignty

  • KVM/libvirt lifecycle
  • Template → create → running → migrate
  • Evacuation + redeploy-from-image

/network

Network as code

  • OVS/OpenFlow SDN
  • Three-layer policy: zone · VM · NIC
  • Microsegmentation at the packet boundary

/storage

Storage coherence

  • Ceph orchestration — Mon · Mgr · OSD
  • Pool capabilities as queryable objects
  • Placement-aware scheduling

/trust

Trust by construction

  • Activation leases · zero-trust agent identity
  • Row-level security at the database boundary
  • FIPS 140-3 via aws-lc-rs

assurance bridge

One API decisions become operational promises.

The brand geometry marks the handoff between the task model and the operating map: the same assurance controls travel with every customer action before regions, registries, and support workflows diverge.

  1. control plane FIPS 140-3 boundary Crypto posture follows registry, licensing, and support actions through the handoff.
  2. policy mesh Zero-trust handoff Identity, role, and tenant context stay attached before work fans out by geography.
  3. data guard Row-level isolation Customer records stay scoped as the operating map moves from API to region.
Global distribution — earth view of network arcs spanning continents

Geographic distribution

Deploy anywhere.

Place workloads by region, latency, sovereignty, or fault domain. The control plane is one Postgres — one reconciliation loop coordinates every site.

Self-healing reconciliation

Drift triggers convergence, not pages.

The manifest projection system watches declared state against actual state in real time. When drift is detected, Basalt converges — automatically, atomically, without operator intervention.

  • BMC fencing — rogue nodes are isolated at the hardware level before recovery begins
  • Manifest projection — declared state is continuously projected onto every enrolled host
  • DRBD failover — block-level replication promotes a standby in seconds, not minutes
  • bootc atomic updates — OS images swap atomically; rollback is a single pointer flip

Why Basalt

Built for what others bolt on

Capabilities that enterprise platforms charge add-on licenses for — shipped as first-class platform primitives.

Certified

FIPS 140-3 Throughout

aws-lc-rs + rustls with zero OpenSSL dependency. End-to-end FIPS-aligned cryptography for regulated procurement.

Resource Activation Leases

Gateway-issued, agent-enforced leases prevent dual-active split-brain failures. Agents won't execute dangerous operations without a fresh lease grant.

Three Components Only

Gateway, image-service, and agent — plus one Postgres. Replaces a full vCenter + ESXi + NSX-T + vSAN + vRealize stack with ~512 MB management plane footprint.

Ceph Orchestration Built-In

OSD, Mon, Mgr placement, RBD pool lifecycle, client credential rotation, and libvirt secret install — all first-class gateway APIs, no separate cephadm exercise.

Self-Healing Infrastructure

Desired-state manifest projection continuously reconciles per-host state. When a host fails, BMC fencing triggers automatically — and the manifest drives VM recovery on healthy hosts.

Intelligence-native design

Every API call carries its own context.
AI agents understand what they see.

The control plane speaks MCP natively. Agents read infrastructure state through typed, self-describing tools — no glue code, no translation layer.

9 MCP read tools across the full state surface

Agent ↔ Control plane

One protocol surface, enough context to reason.

Instead of scraping dashboards, an agent asks the control plane for typed state and receives the shape of the infrastructure back with the answer.

agent request Find safe landing zones for this workload before the migration window.

mcp route vm.get · host.list · cluster.get · task.list · network.list

typed return health, allocation, convergence, pending work, and connectivity status.

health capacity drift progress connectivity
Compute context Virtual machines Fleet inventory plus per-VM readiness for placement and migration questions. vm.listvm.get
  • vm.list List virtual machines visible to the caller, with status and resource allocation.
  • vm.get Retrieve full state for a single VM — config, health, network, and migration eligibility.
Hardware context Hosts Capacity, topology, workload, and drift signals from the physical layer. host.listhost.get
  • host.list Enumerate hosts in a cluster with role, health, and capacity metrics.
  • host.get Deep-read a single host: hardware topology, running workloads, and drift status.
Control context Clusters Aggregate convergence state across nodes, networks, and storage pools. cluster.listcluster.get
  • cluster.list List clusters with aggregate resource utilization and convergence state.
  • cluster.get Full cluster snapshot — nodes, networks, storage pools, and pending tasks.
Operations context Tasks + networks Step-level work history and connectivity boundaries before an agent acts. task.listtask.getnetwork.list
  • task.list Query in-flight and completed tasks with step-level progress detail.
  • task.get Get a single task with granular step progress, timing, and error context.
  • network.list List network zones and bridges with VLAN assignments and connectivity status.

Deployment & licensing

The final decision is operational surface area.

Basalt compresses deployment, licensing, and day-two operations into one calm platform shape. The alternative is not just more products — it is more upgrade choreography, more entitlement math, and more places for drift to hide.

Basalt operating model 4 core parts
4

Ship the platform, not a new estate.

Three static binaries and one Postgres database keep the control plane legible from install through upgrade.

  1. 01
    Install

    Deploy as an RPM or bootc OCI appliance on AlmaLinux 10.

  2. 02
    Enroll

    Agents join through platform identity instead of a ticket queue.

  3. 03
    License capacity

    Entitlement follows infrastructure capacity, not socket archaeology.

  4. 04
    Reconcile

    Drift returns to declared state inside the platform loop.

Incumbent pattern 12+ surfaces
12+

Operate the estate around the estate.

Every extra system adds a lifecycle, a license rule, a certificate boundary, and another failure mode.

vCenter ESXi NSX-T vSAN Aria / vRealize Message queues Multiple databases Schema registry JMX exporter Upgrade choreography Per-socket licensing Certificate sidecars
Deployment footprint Basalt stays small enough to reason about.

One control plane, one database, one install path.

Licensing model Capacity replaces procurement theatre.

Price the infrastructure you operate instead of decoding product bundles.

Operational risk Fewer surfaces means fewer handoffs.

The team debugs the platform, not the connective tissue between platforms.

Decision path

Bring your rack count. Leave with a deployment plan.

We will map your current estate against Basalt's footprint, licensing shape, and migration path with engineers who can answer the hard questions.