Your apps and their data, isolated by design.
Deploy straight from a GitHub repository, and launch the database, cache, vector store, or broker behind it. Everything lands in your workspace's own private network, with every build step streaming live.
One platform for the app and everything under it
Apps built from your repositories, and databases, caches, vector stores, and brokers to run them against — each provisioned the same way, isolated in its own private network. The full catalog lives in the dashboard, with more engines going live as each provisioning script ships.
Self-hosting a service shouldn't be a project.
Provisioning, networking, TLS, firewalls, public endpoints — the boring parts stand between you and a running service. Sahabti handles them so you don't have to.
Networking is the hard part
VXLAN overlays, firewalls, public endpoints, MTU quirks — one misstep and traffic blackholes. Sahabti wires every service into its own isolated network automatically.
TLS everywhere, by hand
Certificates, renewals, MSS clamping over tunnels — encrypted access from anywhere is fiddly. Every instance gets a public hostname, and TLS comes preconfigured on every engine that supports it.
No isolation between tenants
Shared boxes leak. On Sahabti every database, cache, and self-hosted app runs in its own unprivileged container and private network — neighbors can never reach each other.
Everything the platform handles
From a git push to a live URL, and from the first click to a connection string — provisioning, isolation, encryption, and monitoring are built in.
Isolated by design
Each workspace gets its own private VXLAN network, and each instance an unprivileged container inside it. Tenants can never reach each other — isolation is enforced at the network layer, not just a password.
Deploy from GitHub
Import a repository and Sahabti detects the stack, builds a container, and serves it over HTTPS. Every push ships a new version — health-checked before it takes over, and one click back to the exact image that was serving before.
Ready in ~75 seconds
Pick an engine and a size; the network, container, firewall, and endpoint are provisioned automatically. Then copy the connection string.
Reachable from anywhere
Every instance gets a public hostname and port, proxied straight into your private network — and TLS comes enabled by default on every engine that supports it.
Query it from the dashboard
PostgreSQL and MySQL come with a table editor, a SQL editor, and per-app database accounts. Statements run inside the instance, so even a fully private one is usable without a client or a tunnel.
Watch it build
Network, container, engine install, health check — every step streams onto the instance page as it happens, and a failure names the step it stopped on.
Live metrics
CPU, memory, disk, and network read straight off the hypervisor, over whichever window you pick — no agent to install.
API, tokens & teams
Every instance action is a REST route. Mint scoped workspace tokens for scripts and CI, and invite teammates with roles that decide what they can touch.
Built for agents too
An MCP endpoint puts the same platform in front of Claude, Cursor, or your own agent — with your permissions and your quota, and no tool that can read a password back.
One dashboard, 8 engines live
Pick an engine and a size — about 75 seconds later you have an isolated instance with its own host, port, and credentials, reachable over the internet.
Managed SQL databases
PostgreSQL 17, MySQL 8.4, and MariaDB 11 — each with its own database and a scoped user. PostgreSQL and MySQL come up with TLS enabled.
NoSQL databases
FerretDB — a MongoDB-compatible document store on Postgres, up with TLS and its own credentials.
Caches & key-value
Valkey 8 and Memcached — up and answering on their own port, Valkey with TLS.
Vector databases
Qdrant for embeddings and semantic search, on its own API endpoint over TLS.
Message brokers
RabbitMQ with its management UI, ready for queues and pub/sub the moment it comes up.
In the catalog, not yet live
ClickHouse, SeaweedFS, Gitea, n8n, k0s and the rest of the 33-engine catalog are listed in the dashboard and marked coming soon — each goes live when its provisioning script ships.
Every service, in its own private cloud.
Isolated networking, a live URL, and a build log you can watch — reachable from anywhere.
The parts that keep you up at night — isolation, encryption, and visibility — are handled by default.
- Isolated by designIts own private network per tenant
- Encrypted in transitTLS enabled by default
- Visible while it runsLive CPU, memory, disk, network
- No lock-inStandard engines and open protocols
Quota-based pricing, no per-service bills
A plan is a shared pool of vCPU, memory, and disk. Deploy projects and spin up as many services as fit — start free, upgrade when you outgrow it.
Free
Kick the tyres — enough for a small database.
- 2 vCPU shared quota
- 2 GB memory
- 20 GB disk
- Unlimited instances within quota
Pro
Room for a full stack of databases and apps.
- 8 vCPU shared quota
- 16 GB memory
- 200 GB disk
- Unlimited instances within quota
Scale
Production workloads with headroom.
- 16 vCPU shared quota
- 32 GB memory
- 480 GB disk
- Unlimited instances within quota
FAQs
Common questions about running services on Sahabti.
Yournextdeployisoneclickaway.
Ship an app from your repository, or launch an isolated managed instance in seconds. Start free; upgrade when you outgrow the quota.