Where Beelab fits
Four ways to run your stack.
Here is where Beelab sits.
No scorecard. No winners and losers. Each category solves a real problem for a real buyer. Below is a flat map of what each one is, on the same axes, so you can place Beelab in your head.
On this page
- AWS
- Google Cloud
- Microsoft Azure
- CoreWeave
- Lambda
- RunPod
- Tinybox
- AWS EKS
- Google GKE
- Sidero Omni
- Rancher
- Umbrel
- Start9
- Cosmos
- Cloudron
- Coolify
- Dokploy
- CapRover
- Beelab
Rented capacity, by the second.
- AWS
- Google Cloud
- Microsoft Azure
- ModelRent compute, storage, networkOwn the hardware, run the same workloads
- BillMetered, per second, monthly invoiceOne-time install, optional Care monthly
- HardwareTheir racks, their regionsYour premises, validated enterprise PC families
- CatalogThe largest managed services menu in marketVendor-neutral gateway to AWS, Google Cloud, or Azure when a spike actually needs it
GPUs by the hour.
- CoreWeave
- Lambda
- RunPod
- Tinybox
- ModelLease GPU capacity for training and inferenceEveryday AI on an Apple Silicon mesh you own
- BillPer hour or per minute, occasionally per boxOne vendor-neutral router in front, your keys
- ScopeGPU silicon. The platform around it is yours to buildIdentity, observability, backup, GitOps already in the box
- ExampleTinybox ships one physical GPU box you keep, for inference and trainingRoutes to AWS Bedrock, Vertex AI, Azure OpenAI, OpenAI, or Anthropic on demand
Someone else runs the control plane.
- AWS EKS
- Google GKE
- Sidero Omni
- Rancher
- ModelManaged Kubernetes control planeUpstream Kubernetes on hardware you own, no fork
- BillPer cluster, per node, per callKubernetes clusters that coexist on the same rack (Talos for production, k3s for the lab and developer tier), scales 1 to N
- WhereInside the vendor cloud, or on hardware you bringNo per-node fee, no vendor control plane to renew
- OperatorVendor owns the cluster, you own the appsYou. Beelab Care is an optional monthly retainer if you want hands-off
One-box personal cloud.
- Umbrel
- Start9
- Cosmos
- ModelOne enterprise PC or Pi as a personal cloudFederation of role-bounded VMs, every node has one job
- CatalogFriendly app store of self-hosted appsMultiple Kubernetes clusters coexist, multi-VLAN segmentation, identity layer in front
- AudienceOne box, one user, one home networkZero internet-exposed ports (Cloudflare Tunnel + Authentik SSO + MFA, Tailscale admin, key-only SSH)
- SurfaceA dashboard, not a platformIf a one-box home dashboard is what your week looks like, those platforms will serve you better
App-layer platform on a single host.
- Cloudron
- Coolify
- Dokploy
- CapRover
- ModelSelf-hosted multi-app PaaS on a host you provideThe full Sovereign Platform layer beneath the apps
- IdentityBuilt-in OIDC SSO and LDAP across apps (Cloudron)Proxmox cluster (1 to N nodes) plus multiple Kubernetes clusters (Talos for production, k3s for DevOps)
- RuntimeDocker by default, plus the multi-node and Kubernetes options listed on each project's own roadmap (check the upstream changelog for the current state)Observability, multi-path encrypted backup, an Apple Silicon AI mesh, and PARSO-SAMAD self-assessed compliance
- ScopeDeploys and manages the apps; the infrastructure beneath is yours to provisionIf a single-host PaaS is enough for your apps, Cloudron / Coolify will serve you well. Beelab is the platform when one host stops being enough
The Sovereign Platform with AI built in, on hardware you own.
Automated. Secure. Scalable. Reproducible.
Facts about what is deployed today, no SLA promises, no roadmap items mixed in as if shipped.
- i.
Multi-node Proxmox cluster, scales 1 to N
Federation of role-bounded VMs, every node has one job, quorum reshuffles on add or remove.
- ii.
Kubernetes clusters that coexist
Talos Linux runs production as immutable upstream Kubernetes. k3s runs the lab and developer tier with Cilium eBPF and Longhorn. Both vanilla upstream, no fork, scales 1 to N.
- iii.
80+ apps, you pick the catalog
Identity, observability, backup, git, registry, plus the apps you actually use (Bitwarden, Immich, Nextcloud, Paperless, Forgejo, NetBox, Grafana, Ghost, Open WebUI), each pre-authed behind Authentik single sign-on.
- iv.
Vendor-neutral AI on an Apple Silicon mesh
A gateway in front of Ollama on an Apple Silicon mesh on Tailscale, up to N MCP connectors of your choice (vendor or community, from the public MCP registry with thousands of servers and growing), Qdrant and pgvector handle RAG, first-class burst to AWS Bedrock, Vertex AI, Azure OpenAI, OpenAI, or Anthropic with your own keys.
- v.
Zero internet-exposed ports
Public domains route through Cloudflare Tunnel, behind Authentik SSO and MFA on every app, admin access through Tailscale, key-only SSH, OPNsense with VLAN segmentation across management, compute, DMZ, IoT, and guest tiers.
- vi.
Multi-path encrypted backup, on-prem first
Proxmox Backup Server snapshots, Restic file-level backups, a weekly mirror to a second SSD, and a quarterly encrypted offsite copy to a provider you pick (Backblaze B2 default, AWS S3 Glacier or GCP Coldline alternates).
- vii.
PARSO-SAMAD self-score, 10 pillars
Portable, Automated, Recoverable, Secure, Observable, Scalable, Auditable, Maintainable, Accessible, Durable. Self-scored before every release. Internal framework, not a third-party certification.
Not sure if Beelab is the right shape for what you run?
Email Samad directly. Better to find out it is not the right answer before you buy than after.
Brand names belong to their owners.