Open Source PaaS

The sovereign PaaS for modern infrastructure.

Connect your VPS. Deploy apps, services, databases, and workers. PostgreSQL HA with Patroni. Redis Sentinel failover. AI auto-remediation. WireGuard VPN mesh. No vendor lock-in.

Free & Open Source (AGPL v3) Zero-Trust Multi-Server AI Senate Auto-Remediation Deploy Anywhere
Grid Dashboard — Production Cluster
ALL SYSTEMS OPERATIONAL
Services
12
4 active
HA Status
Active
PostgreSQL + Redis
WireGuard
Connected
3 peers
AI Guardian
Watching
7 anomalies today
api-gateway
12d uptime
1.2GB / 2GB
34% CPU
auth-service
30d uptime
890MB / 1.5GB
22% CPU
web-frontend
8d uptime
456MB / 1GB
11% CPU
worker-payments
14d uptime
678MB / 2GB
45% CPU
PostgreSQL HA: Primary → Replica (0ms lag)Redis Sentinel: 3 nodes healthy
17
AI Providers
Senate Committee consensus
40+
Addons
Postgres, Redis, Kafka...
5
Deploy Types
Git, Docker, Upload, Template, Function
0
Vendor Lock-In
Standard Docker containers

Cloud hosting is broken.

These aren't edge cases. They're the standard experience for teams deploying to the cloud.

You're paying 3-10x too much for cloud hosting

AWS, GCP, Azure mark up compute by 300-1000%. Managed PaaS adds another layer. Your infrastructure costs are eating your runway.

Vendor lock-in traps your business

Once you build on a managed platform, you can't leave. Proprietary APIs, custom runtimes, opaque pricing. Your infrastructure becomes a liability.

High availability is sold as a premium add-on

PostgreSQL replication, Redis failover, auto-scaling — these are table stakes. Yet every platform charges extra for basic reliability.

DevOps complexity slows your team down

Kubernetes, Terraform, Helm charts, IAM policies. Your developers spend more time on infrastructure than building product.

How Grid Solves It

Each problem gets a platform-level architectural solution. Not patches. Permanent fixes.

Run on Your Own VPS

Connect any VPS from any provider. Grid orchestrates your infrastructure while you keep full ownership. Compute costs drop by up to 90%.

Built-In High Availability

PostgreSQL HA with Patroni streaming replication. Redis Sentinel auto-failover. WireGuard VPN mesh. All included. Zero extra cost.

AI Autoscaling & Self-Healing

Three autoscaler engines watch your metrics. AI detects anomalies and auto-remediates. Docker daemon down? Disk full? Grid fixes itself.

Push to Deploy

Connect GitHub, GitLab, or Bitbucket. Every push triggers a Nixpacks build — any language, any framework. PR previews with full-stack environments.

Multi-Cloud Deploy Anywhere

BYO-VPS (Hetzner, DO), AWS, GCP, Azure, bare metal, or air-gapped. No closed garden. Transfer services between nodes with zero downtime.

100% Open Source

AGPL v3 licensed. No open-core tricks. If Grid disappears, your workloads keep running as standard Docker containers on your servers.

Unique Capabilities

No other PaaS does this.

Features that separate Grid from every other platform. Built-in, not bolted on. Open-source, not proprietary.

AI Senate Committee

17 LLM providers. 2+ models deliberate on infrastructure decisions via Propose → Review → Synthesize. Multi-model consensus with per-user cost caps before any automated action.

17 providers

Jules Auto-Fix Loop

Failed deployment? Jules analyzes the error, opens a Pull Request with the fix, and deploys automatically. AI remediation that ships code, not just alerts.

Auto-PR

SSRF Guard with DNS Rebind Protection

Serverless runtime monkey-patches fetch/http/urllib to block RFC 1918, link-local, and cloud metadata IPs. Resolve-then-check — immune to DNS rebinding attacks.

Runtime shield

Custom Addon Bundles

Declare Postgres, Redis, Meilisearch, MinIO clusters, Kafka, and 40+ database engines as infrastructure-as-code alongside your app. Full lifecycle: logs, health, backup, metrics, deprovision.

Unlimited addons

Docker Socket Isolation

Build containers never get direct Docker socket access. A read-only proxy mediates every command. No other PaaS isolates the build surface at this level.

Read-only proxy

Zero-Downtime Server Transfers

Drag services between nodes with automatic backup, SSH transfer, restore, and DNS update. 48-hour rollback window with pre-transfer safety snapshot.

Auto-rollback

Zero-Trust Node Attestation

Every server proves its identity via challenge-response HMAC-SHA256 before joining the mesh. Per-node gateway secrets, encrypted Celery tasks, strict SSH host key verification.

Crypto attested

Inter-Server TLS Enforcement

TLS between all nodes with certificate validation. No plaintext inter-node traffic. `STRICT` mode by default — no trust-on-first-use for SSH.

TLS enforced

Fail-Closed Security Model

If SECRET_KEY or encryption keys are missing, Grid crashes on boot — no silent fallback to hardcoded defaults. Defense in depth, not hope.

Crash-secure
Ecosystem Deploy

One Command. Full Stack.

AI scans your repos, generates a deploy plan with dependency-aware waves, then orchestrates the full stack — addons first, services in topological order. All addons auto-provisioned. Zero manual config.

High Availability

Zero Downtime. Every Layer.

PostgreSQL streaming replication with Patroni. Redis Sentinel auto-failover. AI-powered predictive autoscaling. Disaster recovery with defined RPO/RTO targets. Your infrastructure survives anything.

PostgreSQL HA Streaming Replication

Patroni-managed primary with streaming replicas. Automatic failover in seconds. PgCat read/write splitting for zero-downtime upgrades.

Redis Sentinel HA

Automatic cache and broker failover via Redis Sentinel. Configurable quorum, replica priorities, and down-after-milliseconds tuning.

AI-Powered Autoscaler

Three engines: Classic CPU hysteresis, AI-enhanced with Prometheus + Loki anomaly detection, and K8s/Docker admin surface.

Disaster Recovery

Tiered backup schedules (6h/24h/7d), cloud replication to S3/R2/MinIO, encryption key rotation with multi-key support.

WireGuard VPN Mesh

Encrypted node-to-node mesh networking across your fleet. Auto-allocated IPs, per-peer latency tracking, multiple named meshes.

Self-Healing Orchestration

Failure classification: Docker daemon down, disk full, OOM. Auto-escalates to AI after 5 failed attempts with intelligent remediation.

Battle-tested HA. Not a paid add-on.

PostgreSQL streaming replication, Redis Sentinel, AI autoscaling, and disaster recovery are all built-in. No extra infrastructure, no vendor lock-in, no per-seat fees.

WireGuard VPN Mesh — 8 Nodes · 28 Encrypted Links · Multi-Region
All traffic encrypted · WireGuard tunnelAvg latency: 12ms · 0 packet loss · 99.999% uptime
Developer First

Control your infrastructure from anywhere.

The grid CLI + a real-time dashboard. Every push triggers a full pipeline: build → scan → sign → deploy → health check → monitor. AI auto-remediates failures. Zero-downtime blue-green releases.

Full Pipeline in Seconds

Build → Scan → Sign → Deploy → Health Check. Blue-green releases with zero downtime.

Any Language, Any Framework

Nixpacks auto-detects and builds. 5 deployment types: Git, Docker, Upload, Template, Function.

Signed & Hardened

Trivy CVE scan, Cosign image signing, gVisor sandbox, Falco syscall monitoring. Every deploy.

AI Self-Healing

AI Guardian watches post-deploy. Detects anomalies, auto-remediates, opens PRs for failures.

user@grid-cluster:~
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
# Grid — Full Deployment Pipeline
# ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
~/my-app git push origin main
Webhook received — triggering deploy pipeline
┌─ Phase 1: Build ─────────────────────────────┐
Nixpacks auto-detecting framework...
Detected Next.js 15 + TypeScript + PostgreSQL
Installing dependencies (npm ci)
Running build (next build)
Build completed in 18.4s
┌─ Phase 2: Security Scan ──────────────────────┐
Trivy scanning container image for CVEs...
0 critical, 0 high, 2 low (acceptable)
Cosign signing image with Sigstore keyless...
Signature verified (OIDC identity: deploy@grid)
Falco baseline syscall profile updated
┌─ Phase 3: Deploy ─────────────────────────────┐
Blue-green: spinning up my-app@v47
Container started (gVisor sandbox, 512MB/2GB)
WireGuard mesh peer registered (10.0.1.42)
Traefik routing → my-app.grid.internal
SSL certificate provisioned (Let's Encrypt)
┌─ Phase 4: Health & Release ────────────────────┐
Health check — GET /health → 200 OK
gVisor sandbox attestation passed
Traffic switched → live (0ms downtime)
AI Guardian monitoring enabled (auto-remediate)
Deploy complete — v47 live in 23s
https://my-app.example.app
PostgreSQL HA bound · Redis Sentinel connected
~/my-app _

Stop Paying the Cloud Tax

Grid runs on your infrastructure. No managed service markup. No per-seat pricing.

Best Value

Grid

The Sovereign PaaS

Free & Open Source
  • Run on your own VPS
  • PostgreSQL HA built-in
  • Redis Sentinel included
  • AI predictive autoscaling
  • Multi-Git provider support
  • WireGuard VPN mesh
  • Custom addon bundles
  • 100% open source (AGPL v3)
Install Grid Free

Managed PaaS

Vercel / Railway / Heroku

$20-36+/mo per seat
  • Platform lock-in
  • No HA by default
  • Opaque pricing at scale
  • Proprietary runtime
  • Limited git providers
  • No VPN mesh
  • No custom addons
  • Open-core only
Learn More

Cloud Giants

AWS / GCP / Azure

Variable + hidden costs
  • Extreme vendor lock-in
  • Complex IAM & VPC setup
  • Unpredictable billing
  • Requires DevOps team
  • Manual HA configuration
  • Separate VPN service
  • No addon system
  • Proprietary everything
Learn More
The Ecosystem Behind Grid

Secured by SMSLYCLOUD

Grid is one product in the SMSLYCLOUD infrastructure trust ecosystem — building the tools modern businesses need to communicate, verify, deploy, and grow.

Build

Grid PaaS

Free open-source PaaS. Deploy entire ecosystems on your infrastructure with zero lock-in.

Secure

Security Gateway

Zero-trust routing and policy enforcement. Real-time threat detection across all channels.

Verify

Identity Service

High-assurance identity management. Carrier-level verification with SilentOTP™.

Communicate

Global Messaging

SMS, WhatsApp, Voice, and Email. Cryptographic proof of delivery built on Transaction Chain™.

Grow

Ignite

AI-powered marketing that runs itself. Trend intel, leads, and content on autopilot.

Enterprise Security

Hardened for Production

Every container runs in its own gVisor sandbox. Falco monitors syscalls for anomalies in real-time. fail2ban blocks intrusion attempts. Trivy scans for CVEs at push and daily. Cosign verifies every image before deployment. Scoped registry RBAC controls who can pull what.

  • Zero-trust multi-server identity attestation (HMAC-SHA256)
  • End-to-end WireGuard VPN mesh across all regions
  • SSRF guard — runtime protection with DNS rebinding defense
  • Docker socket isolation via read-only proxy
  • Inter-server TLS enforcement (no plaintext traffic)
  • Fail-closed config — crash on missing keys, never fall back
  • 13-secret formal rotation runbook with upstream action matrix
  • Strict SSH host key verification (no trust-on-first-use)

gVisor Sandboxing

User-space kernel per container. No shared kernel surface, no breakout vectors.

Falco Runtime Security

Real-time syscall monitoring. Detects anomalies, cryptomining, container escapes.

fail2ban Intrusion Prevention

Automatic IP ban on repeated auth failures. Works across SSH, API, and registry.

Trivy CVE Scanning

Continuous scanning at push + daily runtime. Filesystem, image, and IaC.

Scoped Container Registry

Per-project pull/push RBAC. JWT auth backed by platform credentials.

Cosign Image Signing

Sigstore keyless signing. Every image verified before deployment.

Container Hardening Pipeline
gVisorSandbox
FalcoSyscall Monitor
fail2banIntrusion Block
TrivyCVE Scan
CosignImage Verify
RegistryScoped RBAC
Every container passes through all 6 stages before reaching production
SOC 2 Type II
GDPR Compliant
ISO 27001
HIPAA Ready
Ready to deploy?

Deploy your first cluster in minutes.

100% free and open-source. Connect your VPS and start deploying. No credit card required.