Furcate OS · 0.1
Server edition, available now
Operate your own AI infrastructure.
Computing for AI that you own and run yourself: private, independent, and answerable to no control plane but your own. One operating system for every machine a site actually contains, from the rack to the sensor on the end of a wire. Not rented, not metered by a landlord, and not switchable off from outside the building.
- Name
- Furcate
- Version
- 0.1
- Kernel
- Linux
- Architectures
- amd64 · arm64
- Editions
- Server available now · Desktop · Mobile available soon
- Identity
- a public key, produced by the machine and sealed to it
- Licence
- Apache-2.0 across every component that makes a trust claim
01
Independent by construction(4)
Owned, private, and answerable to no one outside the building.
The compute that runs your AI should not be someone else's to see, price, or switch off.
Rented AI compute is legible to whoever rents it: they can read what runs, meter it, raise the price, and cut it off. Furcate is the other arrangement: infrastructure you own and operate, where the machine's identity comes from its own silicon, the authority over it is a file you hold, and nothing outside the building can stop a machine inside it. Independence is not a setting. It is how the system is built.
- 01
Yours
A machine's name is a public key it produced and sealed to itself. No registry issued it, and none can revoke it or close the account.
- 02
Private
What runs on your machines is seen by your machines. No control plane you do not own sits in the path, and nothing phones home to run.
- 03
Standalone
A site is administrable in person with the uplink cut. Halting, powering down, isolating and erasing are the operator's alone, over their own signing key.
- 04
Open
Everything that makes a trust claim (identity, attestation, policy, the ledger, the kill switch) is Apache-2.0, and the default build compiles the open half alone.
02
Editions(3)
One system, on a rack, on a desk, and in a pocket.
Three editions. One operator, one vocabulary, one set of keys.
A machine running Furcate declares what it is, what it runs and what it will refuse. That declaration is identical on a headless server, on a workstation with a graphical session, and on a handset. An operator who learned one has learned all three.
Server
Headless. The unit a site is built from, and the edition running in production on the machines serving this page.
- Surface
- console, over SSH or serial
- Role
- node or site controller
- Install
- ISO · netboot · in place
Desktop
The same node, with a screen. Every part of the system opens on its own, several open beside each other, or the whole machine opens at once.
- Surface
- graphical session
- Role
- node or site controller
- Install
- ISO · in place
Mobile
Android. The handset is a node: identity from its own secure element, membership in your overlay, and inference answered by machines you run.
- Surface
- applications you chose
- Role
- worker
- Repository
- signed by a key you hold
03
The range(4)
From the machine that administers the site to the sensor on the end of a wire.
Physical infrastructure is not made of servers. It is made of everything.
A site is a controller, a rack, a robot arm, a battery, a camera and a temperature probe, and the ones with the least compute are the ones most often trusted with no identity at all. Furcate carries the same identity, policy and attestation model down the whole range, and reduces what it asks of a machine as the machine gets smaller.
- 01
Controller
Administers the site, holds the roster and the ledger, and serves the model it reasons with. Attested as capable rather than self-declared.
- 02
Node
A full machine carrying work: accelerators, storage, fabric. Its own identity, its own policy, its own ledger.
- 03
Worker
Single-board computers, handsets and autonomous machines. The worker half of the system and nothing else, because shipping code a machine will not run is dead weight.
- 04
Leaf
Microcontroller-class firmware for sensors and actuators. No operating system, no heap worth relying on, no clock it can prove.
A leaf attaches, it does not join
A microcontroller cannot run gossip or consensus, so a leaf attaches to a parent. Freshness comes from a monotonic counter rather than a timestamp, and its key lives in fuses rather than a secure element.
Signed at the edge of the wire
Readings are batched, hashed and signed on the device that took them, so a measurement arriving at the site controller is attributable to the sensor rather than to whatever was on the bus.
04
What it operates(12)
Every part carries a capability and a refusal.
An AI site is a power problem, a placement problem and a trust problem before it is a scheduling problem.
A rack of accelerators is a thermal envelope, a breaker, a jurisdiction, a set of keys and a bill. Furcate OS makes each of those a property of the operating system, measured on the machine and enforced there.
- 01
Identity
A node's name is a public key, produced by the machine's own silicon and sealed to it.
- 02
Authority
Policy is a file you hold. Deny by default, deny beats allow regardless of order, delegation that cannot outlive its parent.
- 03
Placement
Workloads spread across node, chassis, rack, UPS and feed.
- 04
Fabric
An operator-owned overlay. A peer joins on a signature from a key held off the coordinator.
- 05
Power and energy
Draw read at the supply, priced against the site's grid and tariff, with every efficiency lever costed separately.
- 06
Thermal
Temperatures, fans and the headroom left, per domain, with the tightest domain first.
- 07
Attestation
Assurance graded unmanaged, pinned, imaged, measured, with each level naming its own next step.
- 08
Storage and tenants
Disks, capacity after what is already spoken for, who has been given what, and how each of them would leave.
- 09
Workloads
Watched by name, read-only, with criticality declared rather than inferred.
- 10
Publishing
Sites built, placed and served, with releases named by the hash of the bytes served. Rollback is a pointer move.
- 11
Ledger
Every decision chained, whether it was permitted or refused.
- 12
Inference
Models this machine can answer, served locally or asked of the fleet.
05
Inference
Serving is a property of the system, not a package on top of it.
The machine that runs the model also knows what the model costs.
Weights are pulled and verified against the source, served on an OpenAI-compatible endpoint, and reached at an address the machine tells you. One gateway serves every local model and loads each on demand. That is what an application's fast, balanced and best rungs need: one address, several model ids.
Furcate also serves a model for itself. The site controller reasons about its own fleet from its own registry, on a machine that has never joined a network.
06
The console
One command. It reads; it never acts.
Reading a machine and changing one are different privileges.
furcate opens the console, inside a session that survives the connection. furcate with anything after it is furcatectl: the same words, the same arguments.
No key on the console changes the machine. Every action carries an operator signature over a nonced order, and the operator key is sealed to hardware on a node that is not the site controller.
A dot is not a zero
An unmeasured quantity draws a dotted track and the words no rating. A full meter and an empty one are both claims about a machine nobody measured.
Shape carries state
Every screen reads on a terminal with no colour and to someone who cannot separate red from green. This is an interface for deciding whether to power down a machine.
07
Energy
Read at the supply, priced against the grid it actually came from.
A site's energy figures are only worth what the meter behind them is worth.
Furcate gives a fleet a location, a grid and a tariff, then reads draw at the supply and prices it. Energy charges and demand charges are computed and reported separately, because a power cap that stretches the same work over twice the time saves nothing on the first and a great deal on the second.
4–9×
A declared power multiplier, wrong by this much against draw read at the supply.
8.1×
A site's carbon understated by generation intensity where consumption intensity was the figure that counted.
1.08J / token
Measured on a running node, package energy across a known interval.
228kWh / yr
What two always-on machines draw at idle, before a single request arrives.
Where nothing was metered
A site with no facility meter cannot compute a PUE, so Furcate records the overhead as unaccounted and reports no figure. A PUE of 1.0 claims the overhead was measured and was nil.
08
Custody(4)
Four things nothing may do.
Nothing outside the building can stop a machine inside it.
Halting, cutting power, isolating and erasing keys require the operator's own signing key. No network, no vendor and no code path reaches it. A network may request a drain; local policy decides.
The operator key lives as hardware-sealed ciphertext on a node that is not the site controller. The controller holds only the public half.
- 01
halt
Stop the work on a machine.
- 02
power_off
Cut the machine.
- 03
isolate
Remove a machine's reach.
- 04
crypto_erase
Destroy its keys.
09
Install(3)
Three ways in. Server edition, available now.
Install it, boot it over the network, or take over a machine already working.
Setup asks the small number of questions a machine cannot answer for itself and derives the rest. Hostname, architecture, secure element, addresses: looked up rather than typed.
- 01
Installer
An image that installs Furcate onto bare hardware, carrying its packages on the medium. No answer server and no network at install time.
- 02
Netboot
A bare machine boots, installs and comes back as a node with an identity, a policy it enforces and a console you can read.
- 03
In place
A Linux machine already in service becomes a Furcate node without a reinstall. Workloads, data and identity intact.
Proven in place
The machines converted for the first release were carrying live production workloads on hardware-rooted identities, with attestation chains running against them. Nothing stopped, and every sealed key came through byte-identical. The conversion verifies that rather than assuming it.
10
Updates
One command. Nothing it does can break the system.
An update replaces a signed image. It never edits a machine.
Everything that makes a machine that machine (its identity, its sealed key, its chain data, its configuration) is outside anything an update carries. Components are taken independently, a failure rolls back only itself, and the exit status is the number of components that failed, so a fleet can act on it.
11
Open(4)
The boundary is a directory, and a test holds the code to it.
Anything that makes a trust claim is Apache-2.0.
A node attesting its own identity, a ledger claiming to be tamper-evident, a kill switch claiming to be authorised: those are worth nothing unless anyone can audit them. Identity, attestation, policy, the ledger, the kill switch and the CLI are open.
- 01
Open
Identity, attestation, policy, the ledger, the kill switch, membership and the operator CLI.
- 02
Closed
Optimisation, forecasting and the advisor. None of it is load-bearing for a claim.
- 03
Enforced
The boundary is a directory, and a test fails the build if anything crosses it.
- 04
Default build
Compiles the open half only. That is visible in what runs, not asserted in a licence file.