Skip to content
// any server, fully managed

Turn any cheap server into a managed platform.

Install one outbound-only agent on a server you already rent — from any provider — and kusta handles your deploys, security updates and monitoring, and joins your servers into one private network. Run real production apps without becoming a sysadmin.

outbound-only agent · your root, your bill · cancel anytime

fleetagent ⇄ kusta
encrypted tunnel heartbeat ↑ tasks & deploys ↓
01 how it works

From bare server to managed platform in three steps.

No control panel to migrate to, no SSH keys to hand over. You keep the server; kusta manages it in place.

STEP 01

Run one command

Paste the install line on any Linux server. The agent enrolls with a one-time token and dials out — no inbound port, no exposed SSH.

$ kusta up
STEP 02

Deploy your app

Push a git repo and kusta builds and ships it — or launch a ready-made app from our catalog, live in minutes.

$ git push kusta main
STEP 03

It stays managed

From then on kusta patches the OS in your maintenance window, rolls back updates that come up unhealthy, and alerts you when a server needs a human.

$ kusta status
02 what you get

The DevOps you'd rather not run, handled.

Everything that stands between a cheap server and real production traffic — all on autopilot.

deployed 40s ago

Application deployments

Push from git and kusta builds and ships your app automatically — or launch a ready-made one from our catalog, with a domain and HTTPS out of the box.

rolled back · 12s

Automatic rollback

Every deploy has to come up healthy — even a crash loop is caught. One that doesn't rolls back to the last good version by itself, and the broken release stays blocked.

window 03–05h · patched

Security & OS updates

Security fixes land automatically inside a maintenance window you set — with opt-in auto-reboots for kernel updates. kusta does the 3 a.m. work.

all healthy · 24/7

Monitoring & alerting

Every server reports in around the clock. If one goes offline, a disk fills up or patching gets stuck, you know — critical alerts go straight to your inbox.

db.prod.internal

Private server network

Servers at any mix of providers share one encrypted network. The database on one box is db.prod.internal on every other — and your laptop joins with a QR code.

0 inbound ports

Secure by default

The agent only dials out: no inbound port, no exposed SSH. And every command it runs is cryptographically signed and verified on the box first.

03 why kusta

The price and control of a raw server, the experience of a platform.

Keep the cheap box you already rent; add the managed layer a small team would otherwise have to own.

vs. bare server + scripts

No fragile scripts to babysit for patching or deploys — it's built in and maintained.

vs. a full PaaS

No premium markup on compute and no vendor cage. You still own the box; kusta just manages it.

vs. hiring DevOps

Ship production apps solo — kusta handles the ops work a full-time engineer would.

04 private network

Every server you own, one private network.

Servers at any mix of providers behave like one rack: encrypted links, stable internal names, nothing exposed to the internet.

Names that just resolve

Put the database on one box and the app on another — the app still finds it at db.prod.internal. No IPs to copy around, nothing to reconfigure when containers restart.

Your laptop joins too

Scan a QR code and your laptop is inside the network — query the production database from your desk without exposing a single port. Works with the standard WireGuard apps.

Direct and encrypted

Traffic flows directly between your servers, end-to-end encrypted. kusta only configures the network — your data never touches our infrastructure.

private network*.internal
encrypted connection direct traffic — no middleman
05 eu data sovereignty

Your data stays in the EU.

kusta manages your server where it already lives — GDPR-ready and provider-agnostic, on infrastructure you own.

EU-hosted

Runs where your server already sits

GDPR-ready

Data stays on your own infrastructure

Outbound-only

The agent dials out; nothing listens

06 no lock-in

Cancel anytime. Your server keeps running.

kusta is a management layer, not a landlord. Remove the agent and your apps stay exactly where they are.

You keep root

Full root access to the server the entire time. kusta never takes the keys away.

Your provider, your bill

Rent the server from whoever you like and pay them directly. kusta doesn't resell compute.

Cancel anytime

Remove the agent whenever you want and the server keeps running exactly as it is.

07 faq

Answers before you install.

What is kusta, exactly?

A management layer for a server you already rent. You install one small agent, and kusta gives that server git-based deployments, automatic security and OS updates, and round-the-clock monitoring — the managed-platform experience without the sysadmin work.

Do I have to open any ports?

No. The agent only makes outbound connections to kusta. Nothing new listens on the internet — no inbound port, and not even SSH needs to be exposed.

Does it lock me in?

No. You rent the server from your own provider and keep root the whole time. Cancel anytime, remove the agent, and the server keeps running your apps untouched.

Can it break my running apps?

No update is trusted until it proves itself: after every deploy kusta checks that all containers come up healthy — crash loops included. A version that doesn't is rolled back to the last good one automatically and stays blocked. And because you keep root, you can always step in yourself.

Can my servers talk to each other privately?

Yes. Your servers form one encrypted private network, even across different providers — a service on one box reaches another as db.prod.internal, with traffic flowing directly between the servers, never through kusta. Your laptop can join the same network with a QR code.

How do I find out when something's wrong?

kusta watches every server around the clock: offline, disk filling up, sustained CPU or memory pressure, security patching that got stuck. Warnings show up in the console; critical alerts land in your inbox — and you get an all-clear when they resolve.

Where does it run?

On your own server at any provider you choose — EU hosts included — so your data stays on infrastructure you control.

the waitlist

Give your cheap server a managed platform.

kusta is opening up soon. Join the waitlist and we'll email you the moment you can point it at your first server.

Double opt-in · no spam · privacy · unsubscribe anytime