v0.5.0Early development: see what works today

Your apps, your servers. Every instance a microVM. Deploy with git push.

Jokku is a self-hosted platform modeled on Dokku. It builds your Dockerfile, boots each instance in its own Firecracker microVM, puts your domains on HTTPS, and spreads your apps across every server you add.

Get started
~/code/myapp
$
Built onFirecrackerWireGuardCaddyBuildKitSQLite

-----> getting started

From a bare server to HTTPS in four commands.

Nothing to configure, and nothing to install on your laptop. Just git and ssh.

  1. 01

    Install

    $ curl -fsSL …/install.sh | sudo sh

    On a fresh Ubuntu or Debian server with KVM. Your SSH keys can deploy right away.

  2. 02

    Push

    $ git push jokku main

    Jokku builds your Dockerfile, boots it and prints a working URL.

  3. 03

    Add a domain

    $ jokku domains:add myapp myapp.com

    Point your DNS at the server. Every server can take traffic.

  4. 04

    Turn on HTTPS

    $ jokku letsencrypt:enable myapp

    Certificates are issued, renewed, and HTTP redirects to HTTPS.

-----> what you get

Everything a platform does. On servers you own.

Deploys, scaling, certificates, volumes and private networking, running on hardware you control, from one binary.

web.1firecracker microVM
your processas the image’s USER
volumesvdd · /app/data
scratch layervdc · writable
root diskvda · read-only, shared
kernel 6.1init is PID 1
web.2firecracker microVM
your processas the image’s USER
volumesvdd · /app/data
scratch layervdc · writable
root diskvda · read-only, shared
kernel 6.1init is PID 1

A microVM for every instance→

Each instance boots in its own Firecracker virtual machine, with its own kernel, from a read-only disk built from your image. Restarting or updating Jokku leaves them running.

$ jokku cluster:join-command
server-1control
server-2worker
server-3worker
WireGuard mesh · udp/51820

Clusters in one command→

One server is a complete Jokku. Join more over an encrypted mesh and apps spread across them. If one dies, its apps start on the others.

v11
v12
bootswitchretire
● checks pass, then traffic moves

Zero-downtime deploys→

New instances boot beside the old ones and take traffic once they pass checks. A failed deploy is rejected, and the old version keeps serving.

$ jokku letsencrypt:enable myapp
https://myapp.comrenews itself
https://www.myapp.comrenews itself
https://api.myapp.comrenews itself

HTTPS without thinking→

Let’s Encrypt certificates for every domain, renewed for you, by the Caddy built into Jokku and shared across your servers.

$ git push jokku main
$ jokku builder:compose shop
$ jokku builder:image cache redis:7
Dockerfile · compose.yaml · any registry image

Dockerfiles, compose, images→

Build a Dockerfile, deploy a whole compose file with each service as a process, or run any image from a registry.

$ jokku nodes:drain server-1
server-1server-2
data82%
copied while the app keeps running

Volumes that move→

Give a database a disk that moves with it when its server is drained, and back it up, encrypted, to any S3-compatible bucket.

# shop’s config
REDIS_URL=redis://cache.internal:6379
JOBS=http://worker.shop.internal
resolves on any server, follows deploys

Apps find each other by name→

cache.internal reaches your cache app from any app, on any server, over WireGuard.

$ jokku logs myapp -t
app[web.1]: Listening on :3000
app[router]: GET / status=200 4.2ms
$ jokku enter myapp
/app $

Logs and a shell, anywhere→

Follow every instance and every request in one stream, or open a shell inside a running microVM with jokku enter.

-----> jokku top

Watch every request land.

A live view of your servers, apps and microVMs, right in your terminal. Press 6 and every request flies across its app’s lane, green, yellow or red, and lands on the instance and server that answered.

Tour jokku top
ssh -t jokku@your-server top
jokku top · control server-1 · v0.5.0 · 3/3 nodes · 4 apps · 7/7 instances healthy
1 Overview2 Nodes3 Apps4 Instances5 Events6 Traffic
35.7 req/s·p50 5.1ms p95 24ms·0.4% errors·18,204 total
api19.2/s
myapp9.8/s
shop6.0/s
docs0.6/s
requests by node server-1 12.1/s · server-2 11.6/s · server-3 12.0/s
Recent requests
1-6/tab views p pause c clear ? help q quit

-----> under the hood

From git push to a running microVM.

Every deploy takes the same path, whether it started as a push, a compose file or a registry image. Nothing changes until the new version is healthy.

  1. 01

    git push

    Your source streams to the control server.

    source.tar

  2. 02

    BuildKit

    Your Dockerfile builds to an OCI image.

    oci image

  3. 03

    Root disk

    Layers flatten into one read-only disk.

    rootfs.ext4

  4. 04

    Release

    Build, config and sizes, numbered and immutable.

    v12

  5. 05

    microVMs

    Instances boot, pass checks, take traffic.

    web.1 web.2 web.3

-----> coming from dokku

If you know Dokku, you already know Jokku.

Same command names, same argument order, same output, same git push. What changes is where your apps run, and how many servers they can use.

muscle memory, intact
$ dokkujokku apps:list
$ dokkujokku apps:create myapp
$ dokkujokku config:set myapp SECRET=s3cret
$ dokkujokku domains:add myapp myapp.com
$ dokkujokku letsencrypt:enable myapp
$ dokkujokku ps:scale myapp web=3 worker=1
$ dokkujokku logs myapp -t
$ dokkujokku ps:report myapp
dokkujokku
Runs apps inContainersFirecracker microVMs
ServersOneAs many as you add
ProxynginxCaddy, built in
storage:mountA host directoryA disk that moves with its app
BuildsBuildpacks, Dockerfile, …Dockerfile, compose, images

-----> status

Early, and moving fast.

One server or a cluster, git push deploys work today. Here’s what’s built and what’s next.

  1. M0 Done

    Control plane

    API, SQLite, CLI over SSH, git receive, the installer, safe updates

  2. M1 Done

    Single-server deploys

    BuildKit builds, Firecracker microVMs, embedded Caddy, rollouts, logs, ps:*

  3. M2 Done

    Clusters

    WireGuard mesh, one-command joins, scheduling, failover, jokku top

  4. M3 Building

    Remote API

    Registry images and logins are done; HTTPS API tokens, git:sync and deploy keys are next

  5. M4 Building

    Depth

    enter, volumes and S3 backups are done; scheduled backups, the jailer, run, rollbacks and services are next

Your servers. Your apps. One push.

Bring a fresh Ubuntu or Debian server with KVM and ports 80 and 443 free. The installer does the rest.

$curl -fsSL https://raw.githubusercontent.com/wes/jokku/main/install.sh | sudo sh