Infrastructure
Regions, nodes and the path a request actually takes
A2Cloud runs on its own compute with Cloudflare in front. Below is the current shape of the platform, plus the hop-by-hop path traffic follows.
INFRASTRUCTURE
A2Cloud infrastructure
Regions, nodes and edge locations, reported from the same data source the panel reads. Swap the data source and this view becomes live.
04
Regional deployments
16 / 17
Responding to health checks
46%
Average across regions
04
Request entry points
REGIONS
Active node capacity
Mumbai
Delhi
Bengaluru
Singapore
EDGE NETWORK
Request entry points & Anycast edge
EDGE-BOM
Mumbai
EDGE-DEL
Delhi
EDGE-SIN
Singapore
EDGE-FRA
Frankfurt
NETWORK FLOW
Request transmission architecture
Hop-by-hop isolated routing
User Request
Client initiates TLS handshake; origin remains concealed.
Edge Ingress
Anycast routing, DDoS mitigation & TLS termination upstream.
Cloud Region
Traffic sent down outbound tunnel directly to hypervisor.
Compute Nodes
Isolated Linux VPS or container workload with NVMe storage.
Architecture
What happens between a request and your code
Five hops, and only the first one is on the public internet. Select a stage to see what it does.
User
A request leaves the client browser or API client. Nothing about A2Cloud internal architecture is exposed to it beyond your public hostname.
SECURITY & ROUTING SPEC
Security
Defaults that do not need to be corrected later
Security work is mostly about removing the ways something can be reached by accident. These are the controls the platform applies for you.
We describe what the platform enforces. We do not publish uptime, breach or certification claims we cannot evidence.
Infrastructure isolation
Instances run as separate containers with enforced CPU, memory and disk limits. One workload cannot starve another.
Secure networking
HTTP services can be delivered down an outbound tunnel, so the origin never has to accept inbound traffic. Private networking keeps internal traffic off the public path.
Monitoring
Per-instance CPU, memory, disk and network history is recorded, along with an audit trail of power and configuration changes.
Access controls
SSH key authentication with password login disabled, IP allowlists on management endpoints, and per-user API tokens you can revoke.
Developer security tooling
A2Recon maps what you are exposing across ranges you own, and flags changes as they appear.
Edge protection
A2Shield fronts public endpoints with Cloudflare, so filtering happens upstream of your workload rather than on it.
Get started
Ready to build on A2Cloud?
Deploy infrastructure, experiment in A2Labs, and build on the same platform. No sales call, no account review queue.
Open source panel · A2Panel is AGPL-3.0 licensed