Run the modules you need
Velrix is a set of modules. Add or remove one without changing the others: the mesh finds it by its signed beacon, and a module that is not there is something the rest plan around, not an error.
Core
What most installations start with.
- edgeThe way in for browsers and the API
- webclientServes the web client
- authSign-in, single sign-on and two-step sign-in
- iamPermissions, roles and sessions
- orgsOrganisations, teams and projects
- profilesEach person’s name and preferences
- avatarsPictures for people and teams
- setupThe first-time setup wizard
- deskEach person’s desk and its icons
- lookName, brand colours and wallpaper
- designHow every window is drawn
- localesLanguages and every string in them
- noticesThe tray of notices
- consentWhat each person has allowed
- managerThe operators’ window
- hostRuns a server’s workloads
- computeApps: containers and VMs as one
- volumesVolumes for apps and files
- filesA file manager over your volumes
Optional
Added when an installation needs them, by area.
Workloads
- machinesVirtual machines from a catalogue of images
- jobsOne-shot CI and build jobs in a sandbox
- kubernetesManaged RKE2 or k3s clusters
- kubeA Kubernetes-compatible API
- registryAn OCI container registry
- gitGit servers as apps, with CI runs as jobs
- catalogSizes and blueprints
- libraryBlueprints and script templates in one place
- scriptsInstall scripts for machines
- deploymentsRevisions, rollouts and rollback
- ssh-keysThe SSH key wallet
- terminalTerminals onto apps and machines
- cloud-shellsShells in the browser, in a container or microVM
- cockpitEverything you run, on one board
- logsWhat workloads wrote: search and live tail
Networks and domains
- networkGeneve networks per project
- ipamAddress blocks, pools and who held what
- ingressHostnames for apps on 80 and 443, with certificates
- domainsDomain names through a registrar
- nameserverAuthoritative DNS, signed with DNSSEC
Identity
- oauthAn OAuth 2.1 and OpenID Connect provider
- api-keysScoped keys for integrations
- onboardingSign-up and required first steps
Money
- billingPrices, invoices and credit noteswith payment and tax providers
- meteringUsage, counted once for everyone
- licenseThe licence and its usage reports
Operations and compliance
- complianceSign-in records and disclosure requests
- policy-managerEvery module’s policies in one app
- observatoryThe live mesh, its traffic and every module’s copies
- metricsResource use, kept for 13 months
- hardwareSensors and disk health, with warnings
- chaosFailure tests on a schedule, within limits
- updatesSigned updates, online or by stick
- backupsBackups of state, volumes and VM disks
- migrateVM import from vCenter, ESXi or an OVA
- netbootDiskless boot with approved enrolment
- federationLinks between Velrix realms
- realmkeyThe offline realm key ceremony
- docsThe Docs window, for the modules you run
Integrations
- mcpAn MCP server for AI agents
- stacksOpenTofu and Ansible runs with approvals
- Terraform and OpenTofu(tool)A provider generated from the specs
- Ansible(tool)A collection generated from the specs
Providers: plugins inside one module
A provider connects one module to an outside service, such as a payment gateway. It runs sealed inside that module and never talks to the rest of the mesh.
- Sandboxed
- A WebAssembly plugin that reaches only the hosts it declares, through its owner. No files, no other modules.
- Nothing left behind
- It stores nothing and stops with its owner, so nothing keeps calling out while that module is down.
- Signed and tested
- Every provider is signed, and its owner tests it against the contract for its kind before offering it.
- Room for your own
- Operators can add providers from signers they trust, such as their own payment processor, without a release.
Providers by the module they plug into
- billing
- Payment gateways:Stripe, bank transfer with OCR
- Tax engines:Stripe Tax, or billing’s own rules
- VAT-number checks:VIES
- Exchange rates:Riksbanken, ECB
- Invoice delivery:Peppol, e-mailed PDF
- Accounting export:SIE file, Fortnox, Visma
- auth
- Sign-in:OpenID Connect, OAuth 2.0, SAML
- notices
- Notification channels:E-mail, SMS, Teams, Slack
- Support desks:Zammad, TOPdesk, ServiceNowAvailable at launch
- logs
- Log sinks:syslog, OTLP, Splunk, Elastic, Sentinel
- compliance
- Disclosure formats:Per jurisdictionAvailable at launch
- edge
- Certificate issuers:ACME: Let’s Encrypt, ZeroSSL, HARICA, your own CA
- onboarding
- Captcha:Cap (self-hosted), Friendly Captcha, hCaptcha
- Company lookup:Bolagsverket
- machines
- Software licences:Windows Server: SPLA, KMS, BYOLAvailable at launch
- kubernetes
- Distributions:RKE2, k3sAvailable at launch
- orgs
- Directory sync:SCIM 2.0: Entra ID, Okta
- Directory pull:Entra ID (Graph), Active DirectoryAvailable at launch
- hardware
- Management controllers:Redfish: iDRAC, iLO, XCC
- backups
- Backup targets:S3-compatible (Safespring, Elastx, MinIO, Ceph), SFTP, a local disk
- migrate
- Migration sources:VMware vCenter and ESXi
- domains
- Registrars:Openprovider
A provider is normally included with the module that owns it, with no price of its own.
See Velrixon your own terms
We walk through the platform and the architecture, and how Velrix would run in your organisation.