The substrate
you own

One control plane for bare metal, hypervisors, networks, firewalls and container stacks — declared in Git, observed continuously, driven by humans and AI agents through the same audited core.

Be master of your own destiny

Autonomous software runs around the clock. Rent the floor it stands on, and your costs, your capabilities and your continuity all belong to someone else.

The rent keeps rising

Cloud economics were built for bursty, uncertain demand. A software factory is the opposite: steady, always‑on load, running while nobody's at a desk — exactly the workload where repatriation pays back fastest. Owned commodity servers amortise. Rented cores never do.

The licensing lesson

Ask anyone who built on VMware what a change of ownership does to a renewal quote. Infrastructure you merely license can be re‑priced, re‑bundled or retired overnight. Micro‑Substrate drives open, heterogeneous gear — Proxmox, libvirt/KVM, standard Redfish — with no per‑core meter and no landlord.

Sovereignty is continuity

Your data in your jurisdiction, your keys in your hands, your estate declared in Git and rebuildable from a laptop. Nobody can geofence you, ration you, or deprecate the ground you stand on.

You can rent intelligence by the token. Rent the ground it stands on too, and you own nothing.

Everything between bare metal and your product, handled

The control plane

Run the whole estate from whichever surface suits the moment — browser, shell, API or AI agent — and every action lands in one audit trail. The web-facing process can't do damage; anything dangerous runs as an isolated, replayable job in a separate privileged worker.

micro-machines

A powered-off box becomes a ready host without hand-holding: VMs, OS baseline, networks, firewalls and access, all from your declarations. It stops at the container boundary on purpose — clean seams are what keep estates maintainable.

micro-glue

A production-grade stack — ingress, TLS, databases, messaging, monitoring, backups — from one YAML file, with no Dockerfiles to write or babysit. Forty-nine service templates (and growing).

The boundary is non‑negotiable: the project owns what runs on the substrate; the substrate owns what the substrate is; the operator owns the keys.

Everything talks to the same machine

Browser, shell, API and AI agent all drive one audited core — and the core drives everything from the BMC up.

MCP — your AI operator 83 typed tools. Agents read everything; mutations stay off the wire by design.
The micro shell ~200 verbs, deterministic exits, --json and --watch everywhere.
Console UI Fleet, topology, capacity, jobs — dials over lists, five-second refresh.
JSON API OpenAPI-documented; parity with shell and MCP enforced by tests, not memory.
Bare metal, one command PXE + standard Redfish: Dell iDRAC, HPE iLO, Supermicro. Power on and walk away.
Self-healing capacity Green means probed and healthy. Failures replaced; drift surfaced, never hidden.
3,883 contract tests, zero failing
4 operator surfaces with machine‑enforced parity
203 CLI verbs across the fleet
83 MCP tools for AI operators
49 service templates in the catalogue
6 proven scale tiers, laptop to datacentre

An estate you can script

Around two hundred verbs over one noun-verb grammar — fleet, metal, switch, secrets, projects, jobs — each with a fixed exit ladder your scripts can branch on.

  • --json for machines, --quiet for pipes, --watch to follow a job to its own exit code.
  • The browser console speaks the same verbs — an allowlisted command surface, never a raw shell, every line RBAC-checked and audited.
  • Works before the stack is even up: the bootstrap verbs run standalone for day-zero and disaster recovery.

No landlord at any layer

Every dependency that can hold an estate hostage is behind a seam you control.

Hypervisor-independent

One platform-agnostic machine spec. libvirt/KVM and Proxmox VE live today; the platform seam is where new targets plug in — your declarations never change.

Hardware-vendor-independent

Standard Redfish across Dell iDRAC, HPE iLO and Supermicro. Mixed fleets, commodity x86, second-hand iron — the control plane doesn't care whose badge is on the bezel.

Cloud-provider-independent

Your iron first, any colo second, cloud as just another target behind the same seam — never a landlord, never a per-core meter, never an egress ransom.

Datacentre-independent

The estate is declarations in Git, not a building. The drill we design to: datacentre gone, operator has a laptop — bare metal to fleet-green with data restored.

One machine to a full datacentre, without changing the tool

The same three containers drive a laptop or a datacentre. Growing a deployment is declaring more zones, onboarding more hypervisors and adding physical inventory — it is never a different tool.

Capacity, self-healing: strain goes amber, spares flash online, failures are replaced — declared, observed, converged.

Built for humans and autonomous agents alike

Every capability is reachable four ways — UI, CLI, JSON API and MCP — so a human and an agent drive the same machine, through the same RBAC gate, into the same audit log. Parity is guaranteed by mechanism, not by memory: a test suite walks the API spec and fails the build if any surface falls behind.

Agents observe, operators move

The MCP surface exposes the full read model. Mutations are off MCP by design — an agent constrained to MCP tools cannot mutate the estate even if compromised.

A resident agent per machine

A single dependency‑free daemon on every managed host, holding one outbound WebSocket. Live container state, host telemetry and an audited exec bridge — with no inbound ports, even behind NAT and firewalls.

Closed vocabularies

Jobs, roles, blueprints and reach states are typed registries, not free text — the shape an autonomous operator can reason about, and the shape a trust boundary can enforce.

Grey means “we don't know” — never “clean”

A monitoring surface that can render a false green is worse than no monitoring surface. Micro‑Substrate never fakes one.

  • A never‑probed machine renders unknown, not healthy. Absence of evidence is never presented as evidence of health.
  • Firewall sections the importer doesn't model report not compared — never “in sync”.
  • A job the runner refuses to execute lands in a distinct refused state — the visible outcome of a trust boundary doing its job.
  • When the resident agent goes offline, panels degrade to the last snapshot with a timestamp — never stale data presented as live.

The bottom of the pyramid

Micro‑Substrate is the foundation layer of Microcelium — the platform's Pyraburg architecture stacks intelligence and experience on top of it. It also stands alone: you do not need the wider platform to run your own substrate.

Prism

Experience — what users touch

Applications, portals, APIs and interfaces.

Loom

Intelligence — the workforce that never sleeps

Agents, workflows, memory and automation. micro‑loom.com

Micro-Substrate

Foundation — the substrate you own

Control plane · machines · networks · firewalls · container stacks · observability

Run your factory on your own floor

Talk to the engineers who build and operate it — about your estate, your constraints, and whether Micro‑Substrate fits.