Run your fleet from one field.

One place to run your company's production infrastructure. Teams manage every server, service and certificate with precise access instead of shared admin keys, and every change is recorded. Self-hosted on servers you own.

Get started

Everything your products run on, in one place.

Your products depend on servers, domains, databases and dozens of services. Opfield brings all of it into one panel your team works from, on servers you own, so every change is visible, permitted and recorded.

Today
SSH sessions on every server
eu-fra-01eu-fra-02db-fra-01
$ sudo systemctl restart nginxPermission denied (publickey).
nginx configs edited by hand
api.northwind.io.conf proxy_pass http://10.0.4.12:8080; # old upstream, do not touch[warn] conflicting server name
Certificates in a shared folder
certs/api.northwind.io.pemcerts/app_old.pemcerts/app_new_FINAL.pemapp.northwind.io expires in 3 days
Passwords in a team chat
d.kovacs root password for db-fra-01:N0rthw1nd-2023!m.ivanova thanks, will change it later
Three different monitoring dashboards
Nobody sure who changed what
ops who restarted payments-api?d.kovacs not mem.ivanova maybe the cron job?
SSH sessions on every server
eu-fra-01eu-fra-02db-fra-01
$ sudo systemctl restart nginxPermission denied (publickey).
nginx configs edited by hand
api.northwind.io.conf proxy_pass http://10.0.4.12:8080; # old upstream, do not touch[warn] conflicting server name
Certificates in a shared folder
certs/api.northwind.io.pemcerts/app_old.pemcerts/app_new_FINAL.pemapp.northwind.io expires in 3 days
Passwords in a team chat
d.kovacs root password for db-fra-01:N0rthw1nd-2023!m.ivanova thanks, will change it later
Three different monitoring dashboards
Nobody sure who changed what
ops who restarted payments-api?d.kovacs not mem.ivanova maybe the cron job?
→
With Opfield
opfieldnorthwind
Every server in one list5 servers
Domains, routes and certificates managed togetherapi.northwind.iovalid · 84 d
Access granted per person and per actionPayments teamviewdeploy
Every change in one history14:01:58m.ivanovaapproved release

The whole stack, without the glue work.

Today one change is copied by hand across config files, terminals, dashboards and certificate folders. In Opfield it is one action.

Domains and certificates

Put any service on a domain with HTTPS in minutes. Certificates renew themselves and access rules travel with the route.

Routes3 of 41
HostUpstreamTLSHealth
api.northwind.iopayments-api ×3valid · 84 dayspassing
app.northwind.ioweb ×2valid · 61 dayspassing
status.northwind.iostatus pagevalid · 84 dayspassing
ACME · auto-renewinternal PKIaccess policy · 2health check · 10 s

Releases without downtime

Deploy containers and Compose projects, switch traffic only when the new version is healthy, roll back in one click.

payments-apiblue / green
bluepayments-api:2.4.1running
greenpayments-api:2.4.2deployingrunning
traffic · api.northwind.ioblue → green
blueweb:9.12.0running

Databases

PostgreSQL, Redis and ClickHouse with health checks, backups and private connections to your applications.

Databasesdb-fra-01
payments-dbPostgreSQL 16
sessionsRedis 7
eventsClickHouse
payments-dbprivatepayments-api

Monitoring and logs

See every server and service, search logs, alert your team and publish a status page for customers.

Servers5 connected
eu-fra-01Ingress31%
eu-fra-02Docker58%
us-ash-01Docker44%
db-fra-01Database22%
edge-ams-01Ingressdraining

Automation

Connect CI/CD, webhooks and the API, so releases and routine operations run without manual steps.

Automationstoken · ci-deploy
git push · mainRelease payments-api 2.4.2released
schedule · 02:00Back up payments-dbdone
webhook · registryUpdate web to 9.12.0released
API · CI pipelineAdd route status.northwind.ioapplied
Allowedservices:deploy payments/*databases:backuproutes:edit

Private connections

Connect services and databases across servers and clouds privately, without a VPN or open ports.

Private connections2 links
payments-apius-ash-01Virginia
payments-dbdb-fra-01Frankfurt
webeu-fra-02Frankfurt
sessionsdb-fra-01Frankfurt
no open portsno VPNacross servers and clouds

Built so production stays up.

Downtime costs revenue and trust. Opfield is designed so that no single failure takes your services down: not a server, not a bad release, not Opfield itself, not even an expired license.

Failover · payments-api2 servers
Routeapi.northwind.io→payments-apiserving
eu-fra-02primaryservingnot respondingoffline
us-ash-01standbystanding bytaking overserving
Events
14:03:07eu-fra-02 stopped responding
14:03:09standby on us-ash-01 took over
14:03:10api.northwind.io serving from us-ash-01
Statuslive
Opfield panelupdating
Your services
api.northwind.ioserving
app.northwind.ioserving
status.northwind.ioserving
payments-dbserving
traffic never passes through the panel
Automatic failoverRun a service on several servers. If one goes down, a standby takes over and traffic follows on its own.multi-node availability
Safe releasesA new version goes live only after it passes health checks. The previous one stays ready for an instant rollback.blue/green · health checks
Independent of the panelSites, services and databases keep serving even while Opfield itself is down or being updated.control plane off the data path
Nothing expires by surpriseCertificates and server identities renew themselves while running.ACME · internal PKI
Backups and alertsScheduled database backups, alerts to your team and a public status page.backups · alert rules · status pages
No license hostageIf a license lapses, nothing stops. Only creating and changing paid resources pauses until renewal.continuity policy

Everyone gets exactly the access they need.

No shared server passwords, no admin keys passed around in chat. Give each person, team, contractor or AI agent access to specific servers and actions, and always know who changed what and when.

Precise permissionsPer team or per person, down to one server, one service or one action.
Complete historyPeople, integrations and AI agents are recorded in the same audit trail.
Ready for security reviewStream the audit trail to your SIEM and hand auditors one source of truth.
Group · Payments team4 rules · 6 members
ResourceScopeAllowed actions
Serverseu-fra-*viewconsole
Servicespayments/*viewdeploylogs
Routesapi.northwind.ioviewedit
Databasespayments-dbread
everything elsedenied
Audit trailstreaming to SIEM
14:01:58m.ivanovaapproved the new payments-api release
14:01:40agent · release-botplanned release payments-api 2.4.2
13:57:02d.kovacsissued certificate internal.northwind.io
13:42:19systemrenewed server identity eu-fra-02

AI agents that follow your rules.

Let AI take on routine operations without handing it the keys. The built-in assistant and the agents your engineers already use work through the same permissions, ask before they change anything, and leave the same audit trail as people.

Built into Opfield

AI Workspace

Describe the outcome in plain words. The assistant works out what has to change, shows you the plan and waits for approval before it touches anything.

AI Workspaceplan mode
Release payments-api 2.4.2 behind api.northwind.io with no downtime.
Plan · 3 steps
1Pull payments-api 2.4.2 on eu-fra-02
2Start the new version next to the old one and wait for health checks
3Move api.northwind.io traffic to the new version
Waiting for approval
  • Ready-made scenarios for routine work
  • A plan you approve before anything changes
  • Secrets never show up in chat or history
For external agents

Your own agents, over MCP

Opfield is an MCP server. Connect Claude Code, Codex, Cursor or any MCP-compatible agent, and your admin decides what it may touch.

terminalzsh
$ claude mcp add opfield https://ops.northwind.io/mcp
→ Opening the browser to sign in…
opfieldops.northwind.io
release-bot requests accessCan access
services:deploy payments/*routes:viewlogs:read
signed in · m.ivanova
  • Sign-in and consent over OAuth
  • Only the tools its permissions allow
  • Every action checked and recorded

AI is optional. Everything in Opfield works the same without it.

Secure by design, not by configuration.

A tool that manages your servers has to be the safest thing on them. Opfield removes the usual attack surface instead of asking you to lock it down.

No open management portsServers connect out to Opfield over encrypted channels. Nothing on them waits for inbound connections.outbound-only
Verified from the first secondA new server joins only with a one-time token tied to your Opfield certificate.pinned enrollment
Every server has its own identityEach server holds its own certificate, checked on every connection.mTLS
Strong sign-inTwo-factor codes or passkeys, required per team.TOTP · passkeys
Opfieldeu-fra-01Ingress · mTLSeu-fra-02Docker · mTLSus-ash-01Docker · mTLSdb-fra-01Database · mTLSedge-ams-01Ingress · draining
server → Opfield · outbound onlyopen management ports: 0
Self-hosted on every plan
Source available
Updates on your schedule

Running in minutes, on your own server.

One command on a Linux server installs Opfield. Setup continues in the browser: add your servers, domains and team.

Linux · Docker · guided browser setup
root@cp-01 ~bash
$ curl -sSL get.opfield.dev | bash
Opfield installer
·Checking Docker runtimeok
·Creating opfield networkok
·Starting control planeok
✓Health check passed
→Continue in your browser: https://cp-01:8443/setup

Built into infrastructure that has to keep working.

“Opfield lets us deliver an operating environment, not a pile of handover notes. Clients keep a clear view of what runs and full control of it.”
WIWiolett IndustriesProduct and infrastructure partner
“In trading infrastructure, deployment and observability cannot be separate concerns. Opfield keeps the operational layer coherent without getting in the way of execution.”
RTRemedy TradeSystematic trading operator
“Opfield removes a lot of operational complexity from delivery. Our teams get one place to understand services, access, health and change.”
JWJust WorkingEnterprise integration partner
“Opfield gives us one operating surface for the infrastructure behind financial systems, where visibility and controlled change matter as much as speed.”
DADFK AlgotradeFintech engineering and operations

Self-hosted on every plan.

Opfield always runs on infrastructure you own. No per-server or per-user fees beyond the published plan limits.

Community

Free for internal and other non-competing use.

$0/mo
free
  • Up to 25 servers and 3 users
  • Domains, routes, containers and monitoring
  • AI Workspace and MCP for your agents
All Community features →
Managed cloud—
Personal

Everything paid, without plan limits.

$23$29/mo
founder price
  • No limits on servers or users
  • Managed databases, storage and static sites
  • Zero-downtime releases and Compose projects
All Personal features →
Business

For teams running production workloads.

$150$189/mo
founder price
  • Automatic failover across servers
  • Deploy on git push with isolated build workers
  • Structured logs, audit export and security scanning
All Business features →
Enterprise

Advanced security, compliance and assisted rollout.

On request
  • SSO group mapping and SCIM
  • Internal certificate authority and SIEM export
  • Dedicated contact and assisted migration
All Enterprise features →

Run your fleet from one field.

Install Opfield on your own server in minutes, or talk to us about rolling it out across your teams.

Get started
Talk to us →