IO
IO Control
ioctlsite:create domain="io.app" --secure
fpmallocating php8.5-fpm socket pool...
nginxwriting upstream /etc/nginx/sites-enabled
certissuing Let's Encrypt ssl keys [ok]
ipnetdropped flood packets from 198.51.100.4
postfixpostfix mail relay spf_dkim configured
mariadbmaster-replica heartbeat state sync ok
agentsandbox terminal environment gated
systemload average: 0.12 · 16 cores active
ioctlsite:create domain="io.app" --secure
fpmallocating php8.5-fpm socket pool...
nginxwriting upstream /etc/nginx/sites-enabled
certissuing Let's Encrypt ssl keys [ok]
ipnetdropped flood packets from 198.51.100.4
postfixpostfix mail relay spf_dkim configured
mariadbmaster-replica heartbeat state sync ok
agentsandbox terminal environment gated
systemload average: 0.12 · 16 cores active
websockethandshake ok on channel "io.public"
dbpg_replica sync delay: 0.00ms
jobdaemon ssl.apply 100% completed [ok]
agenttool response: nginx.conf parsed valid
shieldauto-banned user agent: malicious scrape
systemdstarted iodba db diagram supervisor
gitlocal repository sync deploy key matched
backupsftp compressed snapshot transferred
reverbsocket event broadcast dispatched
websockethandshake ok on channel "io.public"
dbpg_replica sync delay: 0.00ms
jobdaemon ssl.apply 100% completed [ok]
agenttool response: nginx.conf parsed valid
shieldauto-banned user agent: malicious scrape
systemdstarted iodba db diagram supervisor
gitlocal repository sync deploy key matched
backupsftp compressed snapshot transferred
reverbsocket event broadcast dispatched
Bare-Metal Automation meets Autonomous AI Operations

The Autonomous Hosting Plane
for the Modern AI Era.

IO orchestrates lightning-fast, zero-overhead hosting stack automation directly on your Ubuntu servers, backed by sandbox-secured AI operators that automatically detect, repair, and deploy your services.

sub-10ms Relay Latency
100% Gated HITL Security
Zero VM Layer Overhead
node-01.io.app
load avg: 0.42
C1
C2
C3
C4
C5
C6
C7
C8
C9
C10
C11
C12
C13
C14
C15
C16
842 IP PEERS
2.4 MB/s TRAFFIC IN
1.8 MB/s TRAFFIC OUT
System initializing... [ok]
Nginx & PHP 8.5 active pools.
ipnet L4 network daemon active.
Type 'help' for available server commands.
node-01:~#
The Evolution of Ops

Why Legacy Hosting Panels Fail Modern Teams

Traditional control planes are bloated, slow, and completely blind to AI. IO reinvents the control plane from the bare metal up.

Legacy Control Panels

  • Heavy VM & Hypervisor Bloat: Consumes vital system resources before serving a single client.
  • Manual Debug Spelunking: A 502 Bad Gateway translates to hours of tedious socket log diagnostics.
  • Static Configuration Policies: Rigid configurations that buckle under real-time traffic anomalies.
  • Disconnected AI Workflow: No secure sandbox for AI models to execute CLI utilities or manage assets.

The IO Autonomous Plane

  • Direct Bare-Metal Speed: Native Ubuntu packages (Nginx, PG, DNS) serving clients at 100% capacity.
  • Autonomous Self-Healing: Deep log intelligence and automated daemon restarts within seconds.
  • Dynamic L7 Traffic Hardening: Responsive, live-adjustable request throttling and kernel IP bans.
  • HITL Gated Sandboxes: Secure environments for AI operators to execute terminal commands safely with approval.
Real-Time Terminal Simulator

Pristine Command-Line Execution

Manage your entire bare-metal cluster and initiate secure, multi-agent diagnostics inside our terminal fleet suite.

bin/ioctl
idle
Application Screenshot
terminal: /home/io/operator
Bootstrap & Deploy

Prepare. Provision. Install.

Real operator flow: archive the tree with --prepare, SSH-bootstrap a fresh box with --provision, then stage the full stack offline-first.

Prepare source trees in seconds, automate SSH provisioning, and deploy the entire multi-application host stack using optimized, offline-cached packages.

--prepare --provision --install serve stage base stage packages
./bin/io --prepare /path/to/io.app ./bin/io --provision 203.0.113.10 '…' sudo ./io --install http://…/latest
bin/io · installer idle
0%
Base Stage
Identity, users, and core host tools setup.
Packages
Installing Nginx, Postfix, PostgreSQL from offline cache.
Configure
Wiring services, BIND zones, and DB bootstrap.
Verify
Host health check and service validation.
Laravel
Final application install and database migrations.
Interactive Control Plane

Manipulate Operator Dials Instantly

Twist our responsive dials to balance security rates, FPM performance pools, and AI agent token allowances. Watch readouts compile in real-time.

Edge Rate & Geo-Hardening Policy

Define request constraints and geofence hardness rules on Nginx before traffic hits PHP.

armed
Max Connection Rate 120 r/s
20 r/s 600 r/s
Geo-Shield Hardness 72%
0% (disabled) 100% (gated)
Auto-Block Window 15 mins
1 min 120 mins
Allow Threshold: ~4.5k/min Expected Drops: ~180/min Kernel Sync Lag: 3.8ms (IPSET)

PHP 8.5 FPM Pool Allocator

Dynamically balance processes and memory limits allocated per virtual host directory.

active
FPM Worker Processes 16 workers
2 64 workers
Memory Limit per Process 256 MiB
64 MiB 2 GiB
Max Execution Timeout 30s
5s 300s
Potential Concurrency: ~256 clients/s Total Pool Buffer: 4,096 MiB FPM Status: healthy (dynamic)

AI Sandbox & Token Budgets

Assign safe computational thresholds, pricing limits, and tool execution bounds to active AI operators.

gated
Max Multi-Agent Steps 12 steps
3 steps 30 steps
Session Token Budget $0.50
$0.05 $5.00
Confidence Gate 85%
50% (auto) 98% (strict HITL)
Permitted Actions: browse, check, patch Approval Requirements: HITL clearance required AI Mode: Secure Operator
Live Security Perimeter

Defend the Core against Layer 7 Floods

The IO Firewall intercepts requests in real-time. Watch allowed flows (Cyan) bypass the perimeter while suspicious threats (Red) detonate harmlessly against the shield.

Kernel IP Banning (IPSet)

Instantly isolate threat actors. Direct integration with Linux kernel ipset lists allows the firewall to drop hostile traffic before it reaches Nginx or FrankenPHP, saving 100% of app CPU cycles.

Geo-Country Hardening

Geofence your server with one click. Block entire geographic regions or threat-heavy routing origins (e.g. block CN, RU) at the edge, redirecting or dropping requests immediately.

Connection & Rate Limits

L7 locked

Guard against brute-force and rapid scrapes. Apply strict Nginx rate limits alongside L4 connlimit policies to restrict the maximum concurrent sockets permitted per IP or CIDR block.

Traffic Sockets Accounting

Real-time network bookkeeping. Powered by the ipnet collector daemon, IO monitors Rx/Tx bytes, packet counts, active ports, and service signatures per IP peer without introducing hypervisor latency.

IO Core Perimeter Filter
0 blocked · 0 allowed
🟢 Successful Connection
🟡 Rate Limited
🔴 Threat Blocked / Banned
🔵 Core Server
🧱 Blocked Region (RU/CN)
[SEC] Kernel packet filter active and observing eth0 interface...
Observe & Optimize

Deep Bare-Metal Network Insights

IO aggregates full-spectrum interface bandwidth, active TCP socket statistics, and edge Nginx HTTP log streams in real-time. See exactly how we analyze and trace every byte on the wire.

NIC Interface (eth0)

Direct hardware bandwidth analysis. Measures actual throughput (Mbps) and packet rates (PPS) directly from the interface card using optimized OS metrics.

RX: 14.8 Mbps
TX: 11.2 Mbps

IP Sockets Tracker (ipnet)

Go-compiled connection accountant. Runs as a background daemon to analyze active TCP/UDP pipes, Rx/Tx byte rates, destination ports, and syncing state to DB.

IP SOURCE CONNS RATE (IN/OUT)
192.168.1.150 14 12.4 MB/s / 8.2 MB/s
203.0.113.10 3 242 KB/s / 184 KB/s
185.220.101.5 1 12 KB/s / 4 KB/s

Nginx Request Stream

Continuous Edge L7 stream auditing. Tails active upstreams to report request rates, response times, caching metrics, and client info in real time.

[LOG] Nginx syslog stream reader initiated...
High-Availability Data

PostgreSQL, MariaDB, Redis — Managed & Synchronized

Track transactional heartbeats, map database nodes, monitor replicas, and synchronize primary-replica writes across your entire cluster at microsecond speeds.

Multi-Node Cluster Database Synchronizer
0 records synced · 0 lag
🔵 Primary Node
🟣 Replica Target
🟢 Synced Write Packet
🟡 Heartbeat Ping
Asynchronous Task Runner

Long ops with live progress.

SSL apply, stack actions, backups, deploys — workers pick them up; you watch electrified progress.

Queued Jobs Monitor
0 jobs in flight
Reactive Host Orchestration

Rules That Fire Before You Would

Define metrics-driven triggers that monitor CPU pool saturation, latency thresholds, and queue backlogs. Automatically execute scaling actions, IP bans, or worker restarts.

Metrics-driven Orchestration Engine
0 automations fired
🔵 Metric Stream
🟣 Armed Threshold Rule
🟢 Active Scaling Action
Automation Log Feed
Watching 6 core infrastructure metrics... rules active
Developer Flow

Push → webhook → ship.

Git-native hosting with automated deploy keys, webhooks, and post-deploy orchestration.

Git bare repositories with custom SSH access control lists are provisioned automatically. Every commit push triggers sub-10ms atomic webhook deployments, reloading pools cleanly.

  • Bare Repos: Host secure local Git repositories on the node.
  • Webhooks: Sub-10ms push event triggers for GitHub & GitLab.
  • Atomic Deploys: Warm PHP restarts and post-deploy Artisan optimization.
git.manager — deployment active
[PUSH RECEIVED] repo: io.app
remote: Analyzing commit 8f2a1c...
remote: Running pre-deploy hooks...
git.deploy.webhook EXECUTING
[LOG] Running artisan optimize:clear
[LOG] Restarting horizon workers
✓ Deployment successful
git push
origin main · bare repo
wait
Webhook fire
POST hooks/deploy · 201
wait
Deploy key
id_io_git_deploy · ACL write
wait
Remote SSH
Host entry · IdentitiesOnly
wait
Job progress
git.deploy.remote · live
wait
Site reload
Nginx apply · warm pool
wait
[git] waiting for push…
Autonomous Agent Sandbox

AI Agents That Code & Govern

Deploy secure, multi-provider agents bound to strict system rules. Complete with isolated tool registries, context skills, knowledge directories, and real-time live turn streaming.

agent.profile : "operator" armed
id operator-core · security: strict · sandbox: containerized
model anthropic.claude-3-5-sonnet · temperature: 0.2
tools browse_url · project_patch · shell_exec · host_job · ask_user
limits 12 steps hard limit · $0.50 budget trigger · auto-halt: true
hitl secure clearances required for network & binary operations

Tool Registry

Class-backed, secure execution pathways that only run authorized commands.

Multi-Agent

Spawn nested, asynchronous child sub-agents over Relay with zero context pollution.

Workspace

Isolated sandboxed directories containing local file trees and real-time build previews.

Live Relay Turns

Non-blocking operational loops streaming tool logs as they execute.

ssl-renew-check turn streaming
browse_url docs.io.app · 240ms done
project_patch 3 files · streaming run
agent_call · deploy-check relay batch · 2/4 channels sub
ask_user confirm · apply SSL? hitl
host_job · ssl.apply queued wait
Thinking · patching nginx site · waiting on HITL… IO is working
High-Speed State Sync

Sub-10ms Event Streaming

Our ultra-low latency WebSocket bus—the **IO Relay Server**—synchronizes states immediately between your central Hive UI, bare-metal terminals, and AI sandboxes.

Hover over nodes on the map to focus them, or click on any node to dispatch a manual state broadcast packet. Watch it stream across the topology map.

0 Broadcast Packets Sync'd
4.2ms Mean Propagation Lag
Sync Frequency 3.0s
Simulated Packet Loss 0%
IO Relay Bus: io.public
IO Relay
bin/ioctl
Hive UI
AI Agent
Stack Host
LIVE EVENT BUS LOGS ● streaming
Unified Infrastructure Suite

Fully Integrated Stack Capabilities

Enjoy out-of-the-box hosting orchestrations and advanced, multi-agent AI features with absolutely zero third-party licensing.

Web & PHP Pools

Deploy secure virtual hosts with dynamic Nginx upstream routing, custom domain binding, PHP-FPM pools, and live traffic charts.

Database Clustering

Fully inspect databases, synchronize MariaDB master-slave configurations, design tables, and render clean schema diagrams instantly.

AI Operators

Dispatch sandbox-secured AI operators that audit configurations, check logs, patch files, and suggest actions with complete transparency.

Perimeter Firewall

Kernel-level threat dropping via IPSet, rate-limiting on Nginx, port scanning protection, and dynamic country-level request blocks.

Postfix Mail Server

Establish production-grade mail boxes with fully compliant DKIM, SPF, and DMARC setups automatically aligned with your DNS system.

Auto Backups

Configure cron-scheduled snapshots of your sites and database structures directly to offline SFTP locations with secure deploy keys.

Next-Gen Web Core

IO Edge: High-Performance Rust Web Server

A native Rust-powered edge web server designed from the ground up to handle high-concurrency reverse proxying, TLS termination, L7 security, and PHP routing with zero hypervisor overhead.

100% Native Rust Stack

Built with safe, multi-threaded async execution using Tokio, Rustls, and H2. No heavy legacy hypervisor tax or unsafe memory footprints.

In-Process L7 Firewall

Dynamic rate-limiting, geo-blocking, real-time IP banning, and instant anti-DDoS cookie challenges evaluated in-pipeline with microsecond latency.

Smart Connection Distributor

Master-worker process splitting with UNIX socket FD handoff (SCM_RIGHTS) and adaptive worker load balancing to prevent connection queue overflows.

ALPN Protocol Selection

Seamless negotiation of HTTP/1.1 and HTTP/2. Full WebSocket protocol upgrading and secure bidirectional tunnel proxying automatically initiated.

FPM & FastCGI Pooling

Direct communication with PHP-FPM sockets. Safe static try_files and dynamic upstream proxy pools executed with complete resource isolation.

HTTP Log & Metrics Rollups

Dual access logging (Standard & JSONL). Ingests real-time worker metrics into PostgreSQL for instant dashboard telemetry and hourly rollups.

Zero-Queue Load Balancing

Smart IPC Connection Distributor

Our custom Rust-based Smart Distributor mode divides execution between a Master and multiple Worker processes, communicating over UNIX socket feedback loops.

The Master process accepts TCP/TLS handshakes, evaluates global firewall rules, then transfers the live connection FD instantly to the least-loaded worker via SCM_RIGHTS handoffs.

0 req/s Inbound Request Rate
1,248 Handoff Transfer Success
Client Inbound Traffic 20 req/s
Worker Request Processing Latency 40ms
IO Edge Topology: Smart Distributor Mode
● DISTRIBUTING
Clients
Public Inbound
Master Process
control.sock active
BUFFER: 0
Worker #0
Load: 0 PID 24081
Worker #1
Load: 0 PID 24082
Worker #2
Load: 0 PID 24083
Worker #3
Load: 0 PID 24084
UNIX CONTROL PLANE FEEDBACK & SCM_RIGHTS HANDOFFS ● monitoring