Your own cloud, on your own machines.
sheep turns a few computers you own into a multi-tenant cloud: accounts and permissions, object storage, virtual machines and private networks. For developers and small teams who want cloud building blocks without renting them.
Try it: run a few instances, then unplug a node. This simulates the design in your browser; sheep does not run instances yet.
Control plane
Accepts the request, records it, answers pending. Never waits for hardware.
API responses
sheep-agent
Why not use what already exists?
The parts exist. A cloud you can hand to other people, on a few machines, does not.
- Proxmox
- Runs virtual machines well. It is built for an administrator, not for tenants who sign up, get keys and call an API.
- MinIO
- Stores objects. Compute, networks and a shared permission model are out of scope.
- OpenStack
- A full cloud, built for data centers and the teams that operate them. Heavy for three machines in a closet.
- sheep
- One API and one permission model across storage, compute and networks. Isolated tenants. Sized for a few machines and one person to run.
What happens when you press the button
Two planes with different jobs. The control plane is a database application: fast and transactional. The data plane is a loop over hardware: slow, unreliable, and allowed to retry.
control plane one request
- MiddlewareRequest ID, logging, timeout, panic recovery.
- RoutingThe action name
compute.RunInstancepicks the handler. Services declare their actions; the gateway keeps no list. - AuthenticationVerify the request signature, find the caller.
- DecodingParse and validate input. Bad requests stop here.
- AuthorizationCheck the caller, action and resource against IAM policies.
- TransactionWrite the desired state and an event row in one commit.
- ResponseReturn
pending. - RelayOutside the request, a worker moves the event to the agents. At least once.
data plane forever
sheep-agent runs on every node. It compares what should exist with what does, and fixes the difference.
loop:
want := desired state
have := what this node sees
if want != have:
act, report, try again later
Four services, kept separate
Each one is its own context with its own API, storage and permissions, the way public clouds split theirs.
- iam
- Users, keys and policies. Every request is signed and every action is checked.
- storage
- Buckets and objects on your own disks, behind an S3-style API.
- compute
- Virtual machines on KVM, isolated per tenant.
- vpc
- Private networks between those machines.
Where it stands
sheep is early. Nothing runs yet. Work happens in milestones; the next one is planned when the current one lands.
Foundationin progress
Configuration, logging, the Postgres store, a transactional outbox, the service registry and the HTTP gateway.
First slicenext
Sign in to sheep and store a file on your own hardware, with authorization enforced.
Built in the open
Written in Go, with PostgreSQL for state and KVM for compute. Every architectural decision is recorded in an ADR before the code that follows it. Read the code on GitHub.
Questions or ideas
faruk@sheeped.dev