Skip to content

Your apps and their data, isolated by design.

Deploy straight from a GitHub repository, and launch the database, cache, vector store, or broker behind it. Everything lands in your workspace's own private network, with every build step streaming live.

Works with
Engines live today
To a live endpoint
Free to start
The platform

One platform for the app and everything under it

Apps built from your repositories, and databases, caches, vector stores, and brokers to run them against — each provisioned the same way, isolated in its own private network. The full catalog lives in the dashboard, with more engines going live as each provisioning script ships.

RabbitMQ
ClickHouse
Gitea
Uptime Kuma
The problem

Self-hosting a service shouldn't be a project.

Provisioning, networking, TLS, firewalls, public endpoints — the boring parts stand between you and a running service. Sahabti handles them so you don't have to.

Networking is the hard part

VXLAN overlays, firewalls, public endpoints, MTU quirks — one misstep and traffic blackholes. Sahabti wires every service into its own isolated network automatically.

TLS everywhere, by hand

Certificates, renewals, MSS clamping over tunnels — encrypted access from anywhere is fiddly. Every instance gets a public hostname, and TLS comes preconfigured on every engine that supports it.

No isolation between tenants

Shared boxes leak. On Sahabti every database, cache, and self-hosted app runs in its own unprivileged container and private network — neighbors can never reach each other.

Features

Everything the platform handles

From a git push to a live URL, and from the first click to a connection string — provisioning, isolation, encryption, and monitoring are built in.

Isolated by design

Each workspace gets its own private VXLAN network, and each instance an unprivileged container inside it. Tenants can never reach each other — isolation is enforced at the network layer, not just a password.

Deploy from GitHub

Import a repository and Sahabti detects the stack, builds a container, and serves it over HTTPS. Every push ships a new version — health-checked before it takes over, and one click back to the exact image that was serving before.

Ready in ~75 seconds

Pick an engine and a size; the network, container, firewall, and endpoint are provisioned automatically. Then copy the connection string.

Reachable from anywhere

Every instance gets a public hostname and port, proxied straight into your private network — and TLS comes enabled by default on every engine that supports it.

Query it from the dashboard

PostgreSQL and MySQL come with a table editor, a SQL editor, and per-app database accounts. Statements run inside the instance, so even a fully private one is usable without a client or a tunnel.

Watch it build

Network, container, engine install, health check — every step streams onto the instance page as it happens, and a failure names the step it stopped on.

Live metrics

CPU, memory, disk, and network read straight off the hypervisor, over whichever window you pick — no agent to install.

API, tokens & teams

Every instance action is a REST route. Mint scoped workspace tokens for scripts and CI, and invite teammates with roles that decide what they can touch.

Built for agents too

An MCP endpoint puts the same platform in front of Claude, Cursor, or your own agent — with your permissions and your quota, and no tool that can read a password back.

What you can deploy

One dashboard, 8 engines live

Pick an engine and a size — about 75 seconds later you have an isolated instance with its own host, port, and credentials, reachable over the internet.

Managed SQL databases

PostgreSQL 17, MySQL 8.4, and MariaDB 11 — each with its own database and a scoped user. PostgreSQL and MySQL come up with TLS enabled.

NoSQL databases

FerretDB — a MongoDB-compatible document store on Postgres, up with TLS and its own credentials.

Caches & key-value

Valkey 8 and Memcached — up and answering on their own port, Valkey with TLS.

Vector databases

Qdrant for embeddings and semantic search, on its own API endpoint over TLS.

RabbitMQ

Message brokers

RabbitMQ with its management UI, ready for queues and pub/sub the moment it comes up.

ClickHouse
Gitea
Uptime Kuma

In the catalog, not yet live

ClickHouse, SeaweedFS, Gitea, n8n, k0s and the rest of the 33-engine catalog are listed in the dashboard and marked coming soon — each goes live when its provisioning script ships.

Every service, in its own private cloud.

Isolated networking, a live URL, and a build log you can watch — reachable from anywhere.

The parts that keep you up at night — isolation, encryption, and visibility — are handled by default.

  • Isolated by designIts own private network per tenant
  • Encrypted in transitTLS enabled by default
  • Visible while it runsLive CPU, memory, disk, network
  • No lock-inStandard engines and open protocols
Pricing

Quota-based pricing, no per-service bills

A plan is a shared pool of vCPU, memory, and disk. Deploy projects and spin up as many services as fit — start free, upgrade when you outgrow it.

Free

$0/mo

Kick the tyres — enough for a small database.

Start for free
  • 2 vCPU shared quota
  • 2 GB memory
  • 20 GB disk
  • Unlimited instances within quota
Most popular

Pro

$39/mo

Room for a full stack of databases and apps.

Choose Pro
  • 8 vCPU shared quota
  • 16 GB memory
  • 200 GB disk
  • Unlimited instances within quota

Scale

$99/mo

Production workloads with headroom.

Choose Scale
  • 16 vCPU shared quota
  • 32 GB memory
  • 480 GB disk
  • Unlimited instances within quota

FAQs

Common questions about running services on Sahabti.

Get started

Yournextdeployisoneclickaway.

Ship an app from your repository, or launch an isolated managed instance in seconds. Start free; upgrade when you outgrow the quota.