Skip to content

How it works

Ownkube runs your apps on infrastructure it owns and operates. You push a repo or a container, Ownkube builds and deploys it, and you get a live URL with managed Postgres, automatic TLS, logs, metrics, autoscaling, and rollbacks built in. You pay Ownkube for what you use. No cloud account, no cluster to provision.

  1. Connect a source

    Connect a GitHub or GitLab repository, or point Ownkube at a container image in a registry (or a public image). See Registries.

  2. Ownkube builds

    For source deployments, Ownkube builds the image (with or without a Dockerfile) in its build capacity and stores the result. Container deployments skip this step.

  3. Ownkube deploys

    Pick a tag in the create-deployment flow from your dashboard, set the port and environment variables, and Ownkube rolls it out. Rolling updates, health checks, and zero-downtime rollouts are handled for you.

  4. You get a live URL

    Every web deployment gets a ready-to-share hostname on a Cloudflare-backed domain, with automatic TLS and DDoS, bot, and scrape protection out of the box.

Every config change (new image tag, env var update, autoscaling change) triggers a rolling update. New containers start and pass health checks before old containers receive traffic or terminate. A bad rollout is a one-click rollback to the last healthy revision.

ComponentWhere it runsWho owns it
Your applicationsOwnkube-operated infrastructureYou, deployed by Ownkube
Your databasesOwnkube-operated infrastructureYou, managed by Ownkube
Functions (beta)Ownkube-operated, tied to an account + regionYou
Container imagesYour registry (GitHub-built, or a public image)You
Secrets + env varsEncrypted secret storeYou, encrypted at rest
User accounts + billingOwnkube control planeOwnkube

Every deployment ships with a live log stream, CPU and memory metrics, and health and sync status. There is nothing to wire up: the dashboard and the CLI read the same signals for every app you run.

Everything above is Ownkube Compute, the default. When you want your own data boundary, your own bill, or a compliance scope that stays on your account, the same app runs inside your own AWS account instead, with the same push-to-deploy workflow, dashboard, and observability. It is an option, not a requirement, and most personal software never needs it.

The Advanced (own cloud) section covers how that path works end to end: the control plane and trust model, connecting an account, and the cluster shapes.