Furcate OS · 0.1

Server edition, available now

Operate your own AI infrastructure.

Computing for AI that you own and run yourself: private, independent, and answerable to no control plane but your own. One operating system for every machine a site actually contains, from the rack to the sensor on the end of a wire. Not rented, not metered by a landlord, and not switchable off from outside the building.

Name
Furcate
Version
0.1
Kernel
Linux
Architectures
amd64 · arm64
Editions
Server available now · Desktop · Mobile available soon
Identity
a public key, produced by the machine and sealed to it
Licence
Apache-2.0 across every component that makes a trust claim

01

Independent by construction(4)

Owned, private, and answerable to no one outside the building.

The compute that runs your AI should not be someone else's to see, price, or switch off.

Rented AI compute is legible to whoever rents it: they can read what runs, meter it, raise the price, and cut it off. Furcate is the other arrangement: infrastructure you own and operate, where the machine's identity comes from its own silicon, the authority over it is a file you hold, and nothing outside the building can stop a machine inside it. Independence is not a setting. It is how the system is built.

  1. 01

    Yours

    There is no roll to be struck from.

    A machine's name is a public key it produced and sealed to itself. No registry issued it, and none can revoke it or close the account.

  2. 02

    Private

    No outside party is a dependency of operation.

    What runs on your machines is seen by your machines. No control plane you do not own sits in the path, and nothing phones home to run.

  3. 03

    Standalone

    A network may request a drain. Local policy decides.

    A site is administrable in person with the uplink cut. Halting, powering down, isolating and erasing are the operator's alone, over their own signing key.

  4. 04

    Open

    A claim nobody can read is not a claim.

    Everything that makes a trust claim (identity, attestation, policy, the ledger, the kill switch) is Apache-2.0, and the default build compiles the open half alone.

02

Editions(3)

One system, on a rack, on a desk, and in a pocket.

Three editions. One operator, one vocabulary, one set of keys.

A machine running Furcate declares what it is, what it runs and what it will refuse. That declaration is identical on a headless server, on a workstation with a graphical session, and on a handset. An operator who learned one has learned all three.

available now

Server

Headless. The unit a site is built from, and the edition running in production on the machines serving this page.

Surface
console, over SSH or serial
Role
node or site controller
Install
ISO · netboot · in place
available soon

Desktop

The same node, with a screen. Every part of the system opens on its own, several open beside each other, or the whole machine opens at once.

Surface
graphical session
Role
node or site controller
Install
ISO · in place
available soon

Mobile

Android. The handset is a node: identity from its own secure element, membership in your overlay, and inference answered by machines you run.

Surface
applications you chose
Role
worker
Repository
signed by a key you hold

03

The range(4)

From the machine that administers the site to the sensor on the end of a wire.

Physical infrastructure is not made of servers. It is made of everything.

A site is a controller, a rack, a robot arm, a battery, a camera and a temperature probe, and the ones with the least compute are the ones most often trusted with no identity at all. Furcate carries the same identity, policy and attestation model down the whole range, and reduces what it asks of a machine as the machine gets smaller.

  1. 01

    Controller

    Exactly one per site. Two is not a degraded version of one.

    Administers the site, holds the roster and the ledger, and serves the model it reasons with. Attested as capable rather than self-declared.

  2. 02

    Node

    Complete by itself. Needs nobody's permission to exist.

    A full machine carrying work: accelerators, storage, fabric. Its own identity, its own policy, its own ledger.

  3. 03

    Worker

    Never a site controller.

    Single-board computers, handsets and autonomous machines. The worker half of the system and nothing else, because shipping code a machine will not run is dead weight.

  4. 04

    Leaf

    Reports a device assurance class and never claims more.

    Microcontroller-class firmware for sensors and actuators. No operating system, no heap worth relying on, no clock it can prove.

A leaf attaches, it does not join

A microcontroller cannot run gossip or consensus, so a leaf attaches to a parent. Freshness comes from a monotonic counter rather than a timestamp, and its key lives in fuses rather than a secure element.

Signed at the edge of the wire

Readings are batched, hashed and signed on the device that took them, so a measurement arriving at the site controller is attributable to the sensor rather than to whatever was on the bus.

04

What it operates(12)

Every part carries a capability and a refusal.

An AI site is a power problem, a placement problem and a trust problem before it is a scheduling problem.

A rack of accelerators is a thermal envelope, a breaker, a jurisdiction, a set of keys and a bill. Furcate OS makes each of those a property of the operating system, measured on the machine and enforced there.

  1. 01

    Identity

    No registry issued it. None can revoke it.

    A node's name is a public key, produced by the machine's own silicon and sealed to it.

  2. 02

    Authority

    Halt, power off, isolate and crypto-erase are refusable by nothing. No token ever issued grants them.

    Policy is a file you hold. Deny by default, deny beats allow regardless of order, delegation that cannot outlive its parent.

  3. 03

    Placement

    Refuses rather than placing replicas where losing one thing loses all of them.

    Workloads spread across node, chassis, rack, UPS and feed.

  4. 04

    Fabric

    Removing a machine from the map cannot isolate it.

    An operator-owned overlay. A peer joins on a signature from a key held off the coordinator.

  5. 05

    Power and energy

    Reports nothing where nothing was metered.

    Draw read at the supply, priced against the site's grid and tariff, with every efficiency lever costed separately.

  6. 06

    Thermal

    Never averages a hot rack into a cool room.

    Temperatures, fans and the headroom left, per domain, with the tightest domain first.

  7. 07

    Attestation

    Never claims a property the hardware does not support.

    Assurance graded unmanaged, pinned, imaged, measured, with each level naming its own next step.

  8. 08

    Storage and tenants

    No tenant is admitted without an exit.

    Disks, capacity after what is already spoken for, who has been given what, and how each of them would leave.

  9. 09

    Workloads

    Does not restart what systemd already supervises.

    Watched by name, read-only, with criticality declared rather than inferred.

  10. 10

    Publishing

    A deploy is an action on a site, ruled on before it happens.

    Sites built, placed and served, with releases named by the hash of the bytes served. Rollback is a pointer move.

  11. 11

    Ledger

    What the machine declined is as auditable as what it did.

    Every decision chained, whether it was permitted or refused.

  12. 12

    Inference

    Weights are verified against the source before they run.

    Models this machine can answer, served locally or asked of the fleet.

05

Inference

Serving is a property of the system, not a package on top of it.

The machine that runs the model also knows what the model costs.

Weights are pulled and verified against the source, served on an OpenAI-compatible endpoint, and reached at an address the machine tells you. One gateway serves every local model and loads each on demand. That is what an application's fast, balanced and best rungs need: one address, several model ids.

Furcate also serves a model for itself. The site controller reasons about its own fleet from its own registry, on a machine that has never joined a network.

Serving a model on the machine in front of you
$ furcatectl model pull qwen3.5-8b pulling qwen3.5-8b 4.6 GiB verified against source digest local /var/lib/furcate/models/qwen3.5-8b $ furcatectl model serve qwen3.5-8b --gpu --context 32768 serving qwen3.5-8b device gpu ctx 32768 slots 4 $ furcatectl model gateway gateway http://10.42.0.11:8080/v1 6 models, loaded on demand $ furcatectl model status qwen3.5-8b answering 37 req p50 210 ms 29 W above idle

06

The console

One command. It reads; it never acts.

Reading a machine and changing one are different privileges.

furcate opens the console, inside a session that survives the connection. furcate with anything after it is furcatectl: the same words, the same arguments.

No key on the console changes the machine. Every action carries an operator signature over a nonced order, and the operator key is sealed to hardware on a node that is not the site controller.

The Server edition, over SSH on an 80-column terminal
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ FURCATE node c05d-a1 site stockholm-1 measured 14:22:07 ─────────────────────────────────────────────────────────────────────────────── ● power ▊▊▊▊▊▊▊▍·········· 61 W package, read at the supply ● thermal ▊▊▊▊▍············· 44 °C headroom 36 ▲ storage ▊▊▊▊▊▊▊▊▊▊▊▊▋·· 86 % past four fifths · facility ·················· no rating no meter upstream ○ overlay 7 peers last spoke 2 s ago ─────────────────────────────────────────────────────────────────────────────── ● measured ○ present ▲ moving the wrong way ■ needs a human · not measured

A dot is not a zero

An unmeasured quantity draws a dotted track and the words no rating. A full meter and an empty one are both claims about a machine nobody measured.

Shape carries state

Every screen reads on a terminal with no colour and to someone who cannot separate red from green. This is an interface for deciding whether to power down a machine.

07

Energy

Read at the supply, priced against the grid it actually came from.

A site's energy figures are only worth what the meter behind them is worth.

Furcate gives a fleet a location, a grid and a tariff, then reads draw at the supply and prices it. Energy charges and demand charges are computed and reported separately, because a power cap that stretches the same work over twice the time saves nothing on the first and a great deal on the second.

4–9×

A declared power multiplier, wrong by this much against draw read at the supply.

8.1×

A site's carbon understated by generation intensity where consumption intensity was the figure that counted.

1.08J / token

Measured on a running node, package energy across a known interval.

228kWh / yr

What two always-on machines draw at idle, before a single request arrives.

Where nothing was metered

A site with no facility meter cannot compute a PUE, so Furcate records the overhead as unaccounted and reports no figure. A PUE of 1.0 claims the overhead was measured and was nil.

08

Custody(4)

Four things nothing may do.

Nothing outside the building can stop a machine inside it.

Halting, cutting power, isolating and erasing keys require the operator's own signing key. No network, no vendor and no code path reaches it. A network may request a drain; local policy decides.

The operator key lives as hardware-sealed ciphertext on a node that is not the site controller. The controller holds only the public half.

  1. 01

    halt

    Stop the work on a machine.

  2. 02

    power_off

    Cut the machine.

  3. 03

    isolate

    Remove a machine's reach.

  4. 04

    crypto_erase

    Destroy its keys.

09

Install(3)

Three ways in. Server edition, available now.

Install it, boot it over the network, or take over a machine already working.

Setup asks the small number of questions a machine cannot answer for itself and derives the rest. Hostname, architecture, secure element, addresses: looked up rather than typed.

  1. 01

    Installer

    Download the Server edition: 0.1, amd64, 2.8 GB, published with its digest.

    An image that installs Furcate onto bare hardware, carrying its packages on the medium. No answer server and no network at install time.

  2. 02

    Netboot

    A bare machine boots, installs and comes back as a node with an identity, a policy it enforces and a console you can read.

  3. 03

    In place

    A Linux machine already in service becomes a Furcate node without a reinstall. Workloads, data and identity intact.

Taking over a machine already in service
$ sudo furcate convert identity sealed to this machine system furcate 1.0.121 installed and verified services furcated, furcate-wg enabled this machine is Furcate $ sudo furcate # the console opens. setup is offered, never imposed. $ sudo furcate revert # reversible. identity, keys, chain data and configuration are kept, # so converting again returns the same machine rather than a new one.

Proven in place

The machines converted for the first release were carrying live production workloads on hardware-rooted identities, with attestation chains running against them. Nothing stopped, and every sealed key came through byte-identical. The conversion verifies that rather than assuming it.

10

Updates

One command. Nothing it does can break the system.

An update replaces a signed image. It never edits a machine.

Everything that makes a machine that machine (its identity, its sealed key, its chain data, its configuration) is outside anything an update carries. Components are taken independently, a failure rolls back only itself, and the exit status is the number of components that failed, so a fleet can act on it.

Updating a node
$ furcate update system 12 packages upgraded ok furcate 1.0.115 → 1.0.121 ok previous image kept $ echo $? 0 # the number of components that failed

11

Open(4)

The boundary is a directory, and a test holds the code to it.

Anything that makes a trust claim is Apache-2.0.

A node attesting its own identity, a ledger claiming to be tamper-evident, a kill switch claiming to be authorised: those are worth nothing unless anyone can audit them. Identity, attestation, policy, the ledger, the kill switch and the CLI are open.

  1. 01

    Open

    Identity, attestation, policy, the ledger, the kill switch, membership and the operator CLI.

  2. 02

    Closed

    Optimisation, forecasting and the advisor. None of it is load-bearing for a claim.

  3. 03

    Enforced

    The boundary is a directory, and a test fails the build if anything crosses it.

  4. 04

    Default build

    Compiles the open half only. That is visible in what runs, not asserted in a licence file.