MicroVMsfor serious apps

Mikrom gives every app a real isolated runtime, a durable release history, managed ingress, private networking, and enough operational control to grow without rebuilding your platform.

release stream
$ mikrom deploy web --branch mainsource locked: github.com/acme/web@8f31c2abuild artifact: oci image signedrelease gate: health checks passedruntime: microVM scheduledingress: app.acme.com tls active
Control planegoverned app and release operations
microVMsstronger workload isolation by default
Ingresscustom domains, TLS, and edge routing
Observabilitylogs, health checks, and runtime signals
Rollbackreversible production releases
Postgresmanaged database lifecycle workflows
Machines that deploy

Real computers for apps, agents, and workers.

A PaaS should not hide fragile machines. Mikrom gives every workload a microVM-isolated Linux runtime governed by a release control plane.

Product apps

Each app gets a dedicated runtime with ingress, TLS, logs, and rollback aligned to the deployment.

ingressTLSrollback

Agent & worker backends

Agent APIs, background workers, and queues run with clear boundaries, private networking, and runtime observability.

private nethealth checksmetrics

Stateful services

Postgres, snapshots, backups, and branches stay close to the operating life of the app.

Postgressnapshotsbackups
The actual control plane

What you get is what's on screen.

No slideware. Every app, database, and domain in Mikrom lives inside the same control plane shown below.

Mikrom Marketplace screen with one-click app deploysMarketplace · one-click deploys
1

One sidebar, not four dashboards. Applications, Databases, Storage, and Networking live in the same control plane.

2

Marketplace deploys. Ready-made services like Vaultwarden or Excalidraw go live in one click, no repository required.

3

Workspace boundaries. Every project keeps its own default scope, so teams don't share state by accident.

A real durable filesystem

State does not disappear when the runtime moves.

Mikrom treats storage, backups, and snapshots as part of delivery. Ceph gives the platform a distributed foundation for workloads that need serious persistence.

Ceph + snapshots
State, recovery, and database workflows stay attached to the release.
Ceph storage foundationsnapshot-aware releasesmanaged Postgres lifecycle
Nothing to manage

Your team ships software. Mikrom runs the machinery.

Certificates, routing, health gates, logs, and rollback should not become internal infrastructure projects.

No certificate chores

TLS and custom domains are part of the release, not a separate checklist.

No routing puzzles

Ingress and readiness decide when traffic reaches the right workload.

No blind launches

Build logs, runtime logs, and metrics sit beside the deployment.

Grow without drama.

Keep the same primitives from the first deploy to production: microVMs, ingress, private networking, state, and a control plane.

microVMruntime boundaryTLSmanaged ingressCephstorage foundationNATScontrol messages
A connection to everything

Connect services without spreading secrets everywhere.

Repositories, tokens, webhooks, databases, and internal services are governed from the control plane.

Secrets and PATs
Credentials controlled by the platform and consumed by deployments.
Release APIs
CLI, dashboard, and automation share the same operational surface.
Internal services
Private DNS, mesh networking, and NATS coordinate platform services.

Ready to move a real workload?

Bring one app or your whole stack — the same microVM runtime, ingress, and rollback controls apply from the first deploy.

Request access

Nothing to babysit. Real primitives underneath.

Early teams deploying on Mikrom

[LOGO][LOGO][LOGO][LOGO][LOGO]
Production discipline

Support that knows the stack.

When something fails, the useful signals are already attached to the release: source, build, runtime, ingress, metrics, and rollback.

Deployment provenance ties every release to source, configuration, runtime placement, and promotion history.
Workloads run in lightweight microVMs for a stronger tenant boundary and fast startup.
The control plane separates release decisions from runtime execution and ingress routing.
Firecracker, Cloud Hypervisor, Pingora, and the modern container ecosystem shape the platform underneath.
Mikrom is developed as a European digital sovereignty project, with platform decisions grounded in EU legal expectations and data-responsible operations.