Compute sovereignty
Hardware-level control. Enterprise-grade isolation.
KVM lifecycle, live migration, and redeploy-from-image — one API, one reconciliation loop.
Geographic distribution
Deploy anywhere. The control plane is one Postgres.
Place workloads by region, latency, sovereignty, or fault domain. One reconciliation loop coordinates every site from a single Postgres of record.
Geographic distribution
Deploy anywhere. The control plane is one Postgres.
Place workloads by region, latency, sovereignty, or fault domain. One reconciliation loop coordinates every site from a single Postgres of record.
Platform architecture
Postgres holds the desired state. Three binaries reconcile it.
The gateway projects per-host manifests, agents reconcile them, and Postgres enforces tenant isolation with row-level security.
0 message brokers
Gateway · Agent · Image Service · Postgres
Core capabilities
Four domains. One control surface.
domains
One API, one task model, one reconciliation loop
Compute sovereignty
- KVM/libvirt lifecycle
- Template → create → running → migrate
- Evacuation + redeploy-from-image
Network as code
- OVS/OpenFlow SDN
- Three-layer policy: zone · VM · NIC
- Microsegmentation at the packet boundary
Storage coherence
- Ceph orchestration — Mon · Mgr · OSD
- Pool capabilities as queryable objects
- Placement-aware scheduling
Trust by construction
- Activation leases · zero-trust agent identity
- Row-level security at the database boundary
- FIPS 140-3 via aws-lc-rs
Intelligence-native design
Every operation carries its reason. That is the interface.
9 MCP read tools across the full state surface
Bare metal to production in six stages
- 01 Discover hardware
Provisioner walks the rack, inventories every host, and registers topology.
- 02 Configure the site
Setup TUI declares network ranges, storage pools, and identity trust roots.
- 03 Enroll agents
Each host agent presents its identity and joins the reconciliation loop.
- 04 Deploy workloads
VMs instantiate from versioned templates through the gateway API.
- 05 Self-configure networks
Overlay and underlay converge to declared topology without manual wiring.
- 06 Observe and converge
Monitoring lights up. Drift triggers reconciliation, not pages.
Deployment & licensing
Compare the operational shape. Then choose.
Basalt is three binaries and one database. The incumbent is a constellation of appliances, queues, and per-socket contracts.