Your infrastructure, orchestrated. In development.
A control plane for databases, caches, apps and load balancers on your own cloud servers. No Kubernetes, no vendor lock-in, no per-database markup. This one is still being built: the screens below are the plan, not a product you can buy yet.
Illustrative interface
Hosted for you
Not available yet, and not onboarding. Leave your details if you want to hear when it is.
Your servers, one control plane
Databases, caches, apps and load balancers across your own cloud, to be orchestrated from one place.
Platform ease, your bill
The aim is the ease of a platform on servers you already pay for, with no per-seat pricing and no per-database surcharges.
Self-healing
Automated failover, backups, monitoring, alerting and incident creation are the target: infrastructure that fixes itself.
Everything you need to run production.
One place to manage your entire infrastructure: the developer experience of a PaaS with the economics and control of your own servers. Everything on this page describes what Cortex is being built to do. None of it is available to sign up for yet.
- MySQL, PostgreSQL with replication and automated failover
- Redis and Typesense clusters, provisioned and monitored
- Deploy any container with zero-downtime rolling updates
- Built-in container registry with vulnerability scanning
- HAProxy load balancing with floating IP support
- Real-time metrics, alerting, and self-healing
- Automatic TLS via LetsEncrypt
- Hetzner Cloud, Robot, DigitalOcean, AWS, OVH, or bring your own
Everything starts with a project
Projects are the planned unit: they group applications, services and infrastructure into one thing. An e-commerce platform, a SaaS backend, a data pipeline. Deploy apps, bind them to databases and caches, manage environment-specific configs, and see everything that belongs together in one view.
- Deploy multiple applications within a project
- Bind apps to databases, caches, and search clusters
- Environment-specific configurations (staging, production)
- Single view from containers to databases
Servers, provisioned in seconds
The intent is that you connect a cloud provider and Cortex turns bare servers into working infrastructure: server creation, agent installation, networking and firewall rules, all automated. Hosts get organised by function, and placement rules decide which hardware a service lands on.
- Fully automated provisioning: select region and size, done
- Host Groups for organizing by purpose
- Failed provisioning auto-recovers, stuck hosts are retried
- Hetzner Cloud and Robot today, DigitalOcean, AWS, and OVH ready
- Bring your own servers via agent-only installation
Databases that just work
MySQL and PostgreSQL clusters from a click, with Cortex handling replication, automated backups, point-in-time recovery and failover promotion so a replica takes over when a primary goes down. This is the design, not something you can run today.
- Standalone or replicated clusters
- Automated daily backups with retention policies
- Monitor query performance, slow queries, and connections
- Create databases and users with scoped permissions
Redis and Typesense, ready to go
Redis clusters with sentinel-based failover, or Typesense search clusters with automatic API key provisioning, both reporting memory usage, command rates, search latency and indexing performance.
- Redis replication with automatic failover
- Typesense clusters with metrics integration
- ACL-based user management
See everything, from host to query
Metrics for every layer: host CPU and memory, container resources, database query throughput and slow queries, Redis command rates, HAProxy session load, flowing through OpenTelemetry to ClickHouse at 30-second resolution. The telemetry packages underneath this are real and released; the control plane consuming them is not finished.
- Centralized logs from all containers and services
- Alert rules on any metric with Slack, email, and webhook routing
- Automatic incident creation with full context
- Maintenance windows to suppress noise during planned work
Vulnerability intelligence, not just scanning
Container images, host operating systems and installed binaries scanned with Trivy, enriched with CVSS severity, EPSS exploit probability and CISA KEV for what is actively exploited, so the list is what matters rather than noise.
- Filter by fixable vs. unfixable vulnerabilities
- Compliance reporting for SOC 2 audits
- Full API request and audit logging
- SSH key management with rotation
Private by default, connected when you need it
Services talk over private networks and only edge hosts expose public ports, with a Tailscale overlay for encrypted mesh networking across regions and providers, and three-layer traffic routing from DNS to container via Cloudflare.
- Automatic TLS via LetsEncrypt for every domain
- Direct, HAProxy edge, or Cloudflare proxy routing modes
- Tailscale VPN with ACL policies from the dashboard
- Floating IP failover for high availability
Built on open source
These are the packages underneath, maintained in the open and run in production. No black box.
Core packages
Real-time system metrics from Linux and macOS in pure PHP. CPU, memory, storage, network, and container metrics with no
SLA-driven autoscaling for Laravel queue workers. Declare how long a job may wait before pickup, and the manager solves
Health checks, Kubernetes probes, Prometheus metrics, and system monitoring for Laravel applications.
Collector-free telemetry for Laravel. Prometheus metrics, OTLP traces, events and logs. No C extension, no protobuf, no
Get Cbox Cortex managed
No spam. Just a heads-up when it is ready for you.
Request Early Access
A few details so I can prioritize the right people.
No spam. I'll email you personally when it's ready.