Enterprise

Multi-tenancy built foraudit and compliance.

When multiple teams share infrastructure, security shifts from basic deployment to granular access control, auditable activity, and predictable spending.

Project workflow01 / 03
01
SourceSix organization roles
02
ControlFull audit trail
03
ReleaseScoped access tokens
Hubfly space projectNetwork · volumes · domains · team access
One project model

Access control

Six roles mapped to real team responsibilities.

The developer restarting a container during on-call isn't necessarily the person who should manage billing or delete organization resources.

Owner

Key
owner
Capabilities
Full administrative authority over organization members, team billing, budget caps, and resource deletion

Admin

Key
admin
Capabilities
Invite team members, create projects, configure infrastructure, add custom domains, and manage registries

Developer

Key
developer
Capabilities
Deploy applications, update environment variables, trigger builds, and manage Compose stacks

Operator

Key
operator
Capabilities
Inspect container metrics and logs, restart or stop services, and open interactive terminal sessions

Billing

Key
billing
Capabilities
Manage payment details, view invoices, process account top-ups, and configure budget alerts

Viewer

Key
viewer
Capabilities
Read-only visibility across projects, container states, and deployment health

Role hierarchy

Owner

Full org control

Admin

Manage teams and apps

Developer

Operator

Billing

Viewer

Read-only

Governance

Built to satisfy security and compliance audits.

01

Comprehensive audit logging

Every sensitive event records the user, target resource, action performed, IP address, user agent, API request ID, and timestamp.

02

Project-scoped API tokens

Personal access tokens carry explicit permissions and can be pinned to specific project IDs, keeping automated CI tokens isolated.

03

Personal vs organization accounts

Workloads belong either to personal developer accounts or shared organization spaces, ensuring staging tests stay separate from production.

04

Team budget caps

Assign monthly, term, or one-time spending limits to project groups so workloads freeze cleanly when budgets are reached.

05

Detailed itemized invoices

Each billing period generates clean itemized statements broken down per container, volume, domain, and GPU instance.

06

Kernel-level tenant separation

Multi-tenant isolation is enforced at the kernel level via Linux namespaces, dropped capabilities, and UID remapping.

Production readiness

Engineered for mission-critical workloads.

Scale-to-zero is ideal for development and staging, but production applications need high availability. Dedicated tiers, load balancing, and edge security keep your core apps running smoothly.

01

Load balancer groups

Distribute traffic using weighted targets and round-robin, least-connections, or IP-hash algorithms with automatic health checks.

02

Dedicated 24×7 tiers

Guaranteed CPU and memory with sleep mode disabled for production APIs, databases, and continuous WebSocket services.

03

Edge firewall and rate limiting

IP allow/deny rules, configurable rate limiting, bot filtering, and automatic circuit breakers positioned in front of your services.

04

Automated image scanning

Trivy and Govulncheck inspect container images on push, reporting exact vulnerability fixes before promotion.

Complete control over your cloud spending.

Usage is metered in 2-minute micro-buckets and logged through an immutable double-entry ledger. Promotional credits draw down first, and when balances reach zero, paid workloads pause automatically instead of building up unapproved debt.

Explore how billing works

Metering window

2 minutes

Ledger

Double-entry, immutable

Credit order

Promo before cash

At $0 balance

Paid workloads stop

Enterprise

Bring your organization onto Hubfly space.

Tell us about your team structure, security requirements, and compliance controls — we'll demonstrate how Hubfly space fits your needs.