Self-hosted
Self-hosting is not a trial or a community edition. It is the whole product: no license server, no telemetry, no limits on tasks, workers, projects or members.
Start
Docker Compose starts the control plane, MongoDB and Redis. The production overrides add Caddy with automatic HTTPS. Kubernetes (Helm, Terraform) and plain Node.js are documented too.
git clone https://github.com/ankulalwani/agent-orchestration.git && cd agent-orchestration
cp .env.example .env # set JWT_SECRET and ENCRYPTION_KEY
docker compose up -d --build
# open http://localhost:4000 and create the first accountControl
Your network
Task timelines, reports, artifacts and secrets stay on infrastructure you run. Integrations can call back into private systems.
Your credentials
Agent logins and provider keys live in each worker’s OS credential store; organization secrets are encrypted with your key.
Your registry
Register private skills, MCP servers and plugins with your own trust levels, permissions and approval policies.
No phone-home
No license checks, telemetry or marketplace calls. Outbound features such as push notifications are off until you enable them.
No limits
Unlimited tasks, workers, projects, members and execution time.
Your identity provider
Sign in with any OpenID Connect provider — Entra ID, Okta, Keycloak — plus Google, GitHub and passwords with two-factor.
Operations
Documented mongodump/restore with a tested drill; a nightly backup CronJob in the Helm chart.
Migrations run automatically under a lock; workers keep working while the control plane restarts.
Several API replicas with Redis; an autoscaler and disruption budget in the Helm chart.
Health and readiness probes, Prometheus metrics and alert rules, Sentry-compatible error tracking.
Rotate the encryption key with a documented, verifiable procedure.
Publish worker releases signed with an offline key; workers roll back bad versions by themselves.
Capabilities
Use the manifests in our directories, or none of them. Your installation owns its registry.
Self-hosted: you control the registry
Your installation keeps its own capability registry. Register entries from this directory, or your own private skills, MCP servers and plugins; set versions, permissions and install policies. Nothing is fetched from us, and nothing phones home.
Managed cloud: we run it for you
The same registry, operated by us. Your organization registers and installs capabilities the same way, with the same policies and approvals. Compare the two.
Or, if you'd rather not run servers, use the managed cloud with the same features.