Server management, rebuilt on a smaller foundation.
Perigone is a server management stack designed from the ground up around security, strict permissions and a small footprint to keep self-hosting affordable while making it more secure.
The problem
Today’s server stacks carry a lot of weight.
Perigone tries to answer what would happen if server management was reimagined from the ground up.
-
Bloated
Modern systems have piled up layers: general-purpose operating systems, daemons, container runtimes, orchestrators, and large app images.
We want to reduce that.
-
Resource hungry
Apart from the apps, the management layer already occupies memory, CPU and a long list of background processes. For smaller systems, this often means a large share of resources “wasted”.
-
Built on old concepts
Much of today’s tooling rests on older designs that were not built with modern systems in mind. A complete re-imagining of the entire stack can remove this legacy bloat.
-
Security as an afterthought
Hardening usually arrives later, as policies or scanners laid over the top. Defaults stay permissive, and getting to a secure setup is complicated.
Our approach
A new architecture changes what is possible.
Perigone is designed around isolated components and explicit capabilities instead of shared, trusted-by-default layers. These are the goals that follow from it.
-
Better security
Isolation is a core part of the platform, not just a layer on top. A small trusted base means less code runs with full privilege, and every workload is kept apart from the others by default.
-
Strict permissions
Nothing by default. A workload gets exactly the capabilities it is given, with no other access to the network, the filesystem or other workloads.
-
Cleaner images
Packaging apps in cleaner images means faster downloads, fewer things to attack, faster app startup, and more disk space for the data that actually matters to you.
-
Fewer processes
Less machinery running next to your workloads means more resources are available for the apps you actually need.
Components
How the pieces fit together.
Perigone is built as a small number of layers, each with one clear job. It runs on a modular base platform and adds modern server management capabilities.
Built by Perigone
Interface
OptionalPerigone
The optional user-facing app store and management UI. Find, install and manage apps in an easy, user-friendly way, or skip it and run Perigone Core on its own.
Control
StandalonePerigone Core
The declarative management layer, similar in spirit to Kubernetes. It does not need the UI and can run entirely on its own. Useful if you have a technical background or want to learn more about the inner workings of the system.
The platform underneath
Platform
System components
Small, isolated services that run, connect, store and package workloads.
-
component_manager
Component framework
Starts components and routes capabilities between them. Nothing gets access it was not handed.
-
Netstack3
Network stack
Networking runs as its own isolated component, not inside the kernel.
-
Fxfs
Storage
Persistent data on a copy-on-write filesystem.
-
Package system
Packages
Content-addressed packages, verified by hash.
-
Driver framework
Drivers
Hardware drivers run in userspace, outside the kernel.
-
Starnix
Linux compatibility
Runs existing Linux programs, so current software can come along.
Foundation
Kernel
Powered by Zircon. A small kernel that keeps the privileged part of the system minimal, with everything else running isolated on top of it.
Principles
What guides the design.
-
Secure by default
The safe configuration is the one you get without doing anything.
-
Small on purpose
Every component has to justify the resources it uses.
-
Explicit over implicit
Permissions, dependencies and access are declared, never assumed.
-
Simple to operate
Running a server shouldn’t require understanding a stack of tools.
Where things stand.
Perigone is in early development. There is no download yet and no release date to share. This page describes what the project is aiming for, not features you can use today.
Follow along on GitHub