Everything that lets a container reach outside its sandbox, from a bind mount to privileged mode, kernel capabilities, host namespaces, foreign volumes and foreign networks, sits behind a single grant an admin gives to a person.
A Compose file is user-written YAML. Gating only the obvious bind mount leaves a plain member one key away from root on the server. Deplo refuses at save time, names the key that tripped it and says who can grant it.
Lorem ipsum dolor sit amet consectetur. Posuere nunc scelerisque pharetra suspendisse ut interdum consectetur semper bibendum.
Point Deplo at a Next.js, Nuxt, SvelteKit, Astro or Remix repository and it builds, routes and serves it over HTTPS on your own server. No Dockerfile, no config, a public URL from the first deploy.
Connect GitHub, GitLab, Bitbucket or Gitea once and every push to your branch becomes a deploy. Open a pull request and reviewers get a live preview URL posted on it.
Connect Claude, ChatGPT, Cursor or any MCP-capable agent and let it deploy an app, read logs, explain a failed build or restart a database. It can only do what you allow.
Teams, roles and 44 fine-grained capabilities, one action each. Give a contractor one folder, require two-factor for the people who can delete things, and see who did what on a single timeline.
The boring operational parts are already handled. You just have to pick what to deploy.
Connect a repository or pick a template. Deplo builds it, routes it, gives it HTTPS and keeps it alive.
Your coding agent can deploy, read logs and roll back for you, with the same access a teammate gets.
Deplo knows. Every action has a name and a time on it, and you decide who's allowed to do what in the first place.
Your hardware, your network, your data. Open source, no lock-in, and no pricing page to keep an eye on.
Lorem ipsum dolor sit amet consectetur. Posuere nunc scelerisque pharetra suspendisse ut interdum consectetur.