Your apps, your servers. Every instance a microVM. Deploy with git push.
Jokku is a self-hosted platform modeled on Dokku. It builds your Dockerfile, boots each instance in its own Firecracker microVM, puts your domains on HTTPS, and spreads your apps across every server you add.
-----> getting started
From a bare server to HTTPS in four commands.
Nothing to configure, and nothing to install on your laptop. Just git and ssh.
- 01
Install
$ curl -fsSL …/install.sh | sudo shOn a fresh Ubuntu or Debian server with KVM. Your SSH keys can deploy right away.
- 02
Push
$ git push jokku mainJokku builds your Dockerfile, boots it and prints a working URL.
- 03
Add a domain
$ jokku domains:add myapp myapp.comPoint your DNS at the server. Every server can take traffic.
- 04
Turn on HTTPS
$ jokku letsencrypt:enable myappCertificates are issued, renewed, and HTTP redirects to HTTPS.
-----> what you get
Everything a platform does. On servers you own.
Deploys, scaling, certificates, volumes and private networking, running on hardware you control, from one binary.
A microVM for every instance→
Each instance boots in its own Firecracker virtual machine, with its own kernel, from a read-only disk built from your image. Restarting or updating Jokku leaves them running.
Clusters in one command→
One server is a complete Jokku. Join more over an encrypted mesh and apps spread across them. If one dies, its apps start on the others.
Zero-downtime deploys→
New instances boot beside the old ones and take traffic once they pass checks. A failed deploy is rejected, and the old version keeps serving.
HTTPS without thinking→
Let’s Encrypt certificates for every domain, renewed for you, by the Caddy built into Jokku and shared across your servers.
Dockerfiles, compose, images→
Build a Dockerfile, deploy a whole compose file with each service as a process, or run any image from a registry.
Volumes that move→
Give a database a disk that moves with it when its server is drained, and back it up, encrypted, to any S3-compatible bucket.
Apps find each other by name→
cache.internal reaches your cache app from any app, on any server, over WireGuard.
Logs and a shell, anywhere→
Follow every instance and every request in one stream, or open a shell inside a running microVM with jokku enter.
-----> jokku top
Watch every request land.
A live view of your servers, apps and microVMs, right in your terminal. Press 6 and every request flies across its app’s lane, green, yellow or red, and lands on the instance and server that answered.
-----> under the hood
From git push to a running microVM.
Every deploy takes the same path, whether it started as a push, a compose file or a registry image. Nothing changes until the new version is healthy.
- 01
git push
Your source streams to the control server.
source.tar
- 02
BuildKit
Your Dockerfile builds to an OCI image.
oci image
- 03
Root disk
Layers flatten into one read-only disk.
rootfs.ext4
- 04
Release
Build, config and sizes, numbered and immutable.
v12
- 05
microVMs
Instances boot, pass checks, take traffic.
web.1 web.2 web.3
-----> coming from dokku
If you know Dokku, you already know Jokku.
Same command names, same argument order, same output, same git push. What changes is where your apps run, and how many servers they can use.
| dokku | jokku | |
|---|---|---|
| Runs apps in | Containers | Firecracker microVMs |
| Servers | One | As many as you add |
| Proxy | nginx | Caddy, built in |
| storage:mount | A host directory | A disk that moves with its app |
| Builds | Buildpacks, Dockerfile, … | Dockerfile, compose, images |
-----> status
Early, and moving fast.
One server or a cluster, git push deploys work today. Here’s what’s built and what’s next.
- M0 Done
Control plane
API, SQLite, CLI over SSH, git receive, the installer, safe updates
- M1 Done
Single-server deploys
BuildKit builds, Firecracker microVMs, embedded Caddy, rollouts, logs, ps:*
- M2 Done
Clusters
WireGuard mesh, one-command joins, scheduling, failover, jokku top
- M3 Building
Remote API
Registry images and logins are done; HTTPS API tokens, git:sync and deploy keys are next
- M4 Building
Depth
enter, volumes and S3 backups are done; scheduled backups, the jailer, run, rollbacks and services are next
Your servers. Your apps. One push.
Bring a fresh Ubuntu or Debian server with KVM and ports 80 and 443 free. The installer does the rest.