AeolusREVYTECH · CloudBSD

Standard OCI containers.
Native CloudBSD jails.

Aeolus runs standard OCI images directly on CloudBSD with jail isolation and RCTL limits. Familiar container CLI — no Linux guest VM layer.

Checking live demos…
aeolus run
# Pull OCI layers, start a CloudBSD jail
aeolus run -d --name web -p 443:443 --memory 2G registry.example/caddy:latest

François Boucher — Juno Asking Aeolus to Release the Winds (public domain)

Live cluster status

Public demo surface for the three-node lane and product endpoints. Labels are abstract — no lab addresses.

Live topology

Every chip is a live instance from status.json — redundant web, database, cache, and workers across blog + n1/n2/n3.

Three-node Aeolus mesh with animated traffic n1 n2 n3

blog

    n1

      n2

        n3

          • n1…
          • n2…
          • n3…

          Nodes authenticate to each other over mutual TLS on a private cluster CA. Browsers never see that CA — public names use Let’s Encrypt.

          Instances

            Runtime

            CLI version
            —
            Running jails / containers
            —
            Ensembles
            —
            Last health tick
            —

            How the parts fit

            OCI image in, CloudBSD jail out. Ensembles wire multi-service stacks the way an operator expects.

            Image → CLI → jail

            OCI image to aeolus CLI to CloudBSD jail OCI image layers + config aeolus CLI runtime CloudBSD jail RCTL · mounts

            Ensemble: WordPress + database + cache

            Services share a lifecycle. Network aliases land in each jail’s hosts file so wordpress reaches db and memcache by name.

            aeolus-blog ensemble with wordpress, db, and memcache ensemble: aeolus-blog wordpress publish :80 memcache object cache mariadb primary redis cluster cache

            Two certificate planes

            Node mesh (private)

            An offline cluster CA issues node certificates. Nodes prove identity to each other — operators stay off the public CA.

            Public names (Let’s Encrypt)

            Product hostnames such as blog.aeolus.cloudbsd.org present certificates browsers already trust.

            How networking works

            Publish a port, give services aliases, hit the product name from a browser. Map the same pattern onto your own nodes.

            Browser to public name to jail publish path Browser blog.aeolus.cloudbsd.org public TLS Published jail port -p 443:443 · ensemble DNS /etc/hosts in-jail aliases

            On your cluster: publish the service port, point DNS at the node that publishes it, and keep node-to-node auth on the private mesh CA.

            On your cluster

            Same Docker-shaped surface. Install the CloudBSD package that ships aeolus, then create, run, and ensemble.

            create · run · ensemble
            # Single service
            aeolus create --name api -p 8443:443 --memory 1G ./bundle
            aeolus start api
            aeolus ps
            
            # Multi-service stack (WordPress-shaped)
            aeolus ensemble validate ./ensemble.yml
            aeolus ensemble up ./ensemble.yml
            aeolus ensemble status ./ensemble.yml
            
            # Cluster mesh (nodes only — not for browsers)
            aeolus cert bootstrap --cn cluster.example
            aeolus cert issue-node n1
            aeolus cert issue-node n2
            1. Install Aeolus from your CloudBSD package set.
            2. Bootstrap a private cluster CA and issue one cert per node.
            3. Run workloads with aeolus run or group them with aeolus ensemble up.
            4. Publish ports and attach public TLS only to the names browsers will open.

            What you get

            • Kernel-level jail isolation. Workloads run in CloudBSD jails with RCTL limits, mounts, and capabilities.
            • Multi-service ensembles. Group interdependent services with shared lifecycle, startup ordering, and network aliasing.
            • Encrypted cluster mesh. Nodes authenticate over mutual TLS. Public hostnames get Let’s Encrypt certificates browsers trust.
            • Predictable CLI. Docker-shaped commands map to jail lifecycle — including ensemble for multi-service stacks.

            Live demos

            Live instances running on CloudBSD: