Pilot-stage · Accra, Ghana · 2026

A public cloud, built in Ghana, for the developers building next.

Codafords runs app hosting, functions, databases and storage on a private, self-managed cluster we own end to end.

4
products live and exercised end to end
7
languages built with no Dockerfile
2
storage tiers, each purpose-matched
100%
self-managed, owned infrastructure
Part I — Infrastructure

Topology: from bare cluster to a tenant’s live URL.

Five purpose-built layers. Traffic flows top to bottom; a tenant’s code flows bottom to top.

Edge

Edge, DNS & TLS

ingress-nginx · cert-manager

Every route enters through the ingress. TLS certificates are issued automatically, for platform URLs and custom domains alike.

ingress-nginx
default ingress class
cert-manager
automatic TLS issuance
DNS + custom domains
verified per tenant
SafeLine WAF
reserved, not default
TLS-terminated HTTP control plane
Control

Control plane & identity

API / scheduler · OAuth2 / OIDC

The platform API, scheduler and identity run in their own pool, dedicated to Codafords.

Control & API
scheduler + platform API
Identity
signup, login, sessions
Layered RBAC
least-privilege, anti-escalation
Capacity guardrail
admission-time headroom check
scheduling decisions node pools
Pools

Purpose-built node pools

enforced node affinity

Workloads are split into isolated pools. A cluster policy enforces node affinity, so tenant workloads run only in the tenant pool, physically separate from platform infrastructure.

Platform infra
shared platform services
DevOps
CI/CD tooling
Storage
block + object backends
Tenant resource
every tenant workload, only here
persistent volumes build artifacts
Data

Two storage tiers

block · S3-compatible

Block storage for anything that needs a low-latency disk, object storage for everything better kept as blobs.

Block storage
Postgres, GitLab, registry, metrics
CodaSimpleStorage
artifacts, backups, tenant buckets
Encrypted secrets
every credential, token, TLS key
Off-site replication
nightly, physically separate
isolated namespace per tenant project
Tenant

Tenant & deployment

quota’d · NetworkPolicy-enforced

Each project is its own quota’d, isolated workload. NetworkPolicies restrict traffic across tenants, and HTTP workloads scale to zero when idle.

Tenant project
isolated namespace + quota
Deployment
image from tenant registry
Autoscaling
HTTP-based, scales to zero
Live URL
<slug>.codafords.app
Autoscaling

Event-driven autoscaling drives tenant apps and CodaFunctions, and can scale HTTP workloads to zero.

Capacity guardrail

An admission-time check verifies cluster headroom before a new tenant is provisioned. Pilot stage.

Credential discipline

Every credential generated in the project is logged in one access-controlled, git-ignored record.

The deploy pipeline

Real, automated, auditable — end to end.

push live in ~90s
  1. 01

    Connect

    A GitHub repo through a GitHub App, or a push to Codafords GitLab.

  2. 02

    Detect

    Build detection with no Dockerfile, plus a custom Next.js buildpack.

  3. 03

    Build

    Built on the DevOps pool, isolated from tenant workloads.

  4. 04

    Register

    Image stored in the platform’s own registry, scoped per tenant.

  5. 05

    Deploy

    Rolled out into the tenant pool with TLS and live status.

Part II — What Codafords offers

Live today. Exercised against the real platform.

Every product below has been run end to end on the running cluster.

01Live

App Hosting

Push code, get a running, publicly reachable app.

  • GitHub App install-and-go, or Codafords’ own built-in GitLab
  • No Dockerfile across seven languages, plus tested Next.js paths
  • Custom domains with automatic, free TLS and live deployment health
02Live

CodaFunctions

Deploy a single function instead of a whole app.

  • HTTP, scheduled and event-driven triggers on NATS JetStream
  • Go, Node.js and Python runtimes
  • An in-browser editor that redeploys through the same pipeline
03Live

CodaDBaaS

A dedicated production-grade database per tenant, provisioned in minutes.

  • PostgreSQL via CloudNativePG and MongoDB via the official Community Operator
  • TLS mandatory on every connection, verified live for both engines
  • IP allowlisting, automatic backups and opt-in read replicas
04Live

CodaSimpleStorage

An S3-like storage service, API-driven by design.

  • Public or private buckets, and static site hosting with SPA routing
  • Version history with one-click restore on every object change
  • Per-bucket CORS and nightly off-site backup replication
05Live

Account & Dashboard

One dashboard for everything a tenant runs.

  • Self-service signup, login and password reset
  • Complete self-service account deletion of every owned resource
  • A single dashboard across Projects, Functions, Databases and Storage

Build on it today.

Every layer above is running right now. Connect a repository and get a live URL in about ninety seconds.