Skip to content

Infrastructure

Regions, nodes and the path a request actually takes

A2Cloud runs on its own compute with Cloudflare in front. Below is the current shape of the platform, plus the hop-by-hop path traffic follows.

INFRASTRUCTURE

A2Cloud infrastructure

Regions, nodes and edge locations, reported from the same data source the panel reads. Swap the data source and this view becomes live.

DEMO DATASET — API NOT CONNECTED
REGIONS

04

Regional deployments

REPORTING NODES

16 / 17

Responding to health checks

COMPUTE AVAILABLE

46%

Average across regions

EDGE LOCATIONS

04

Request entry points

REGIONS

Active node capacity

IN-BOMIN

Mumbai

Operational
NODES6 / 6 online
CAPACITY42%
Kolkataverified
IN-DELIN

Delhi

Operational
NODES4 / 4 online
CAPACITY58%
Kolkataverified
IN-BLRIN

Bengaluru

Maintenance
NODES3 / 4 online
CAPACITY21%
Kolkataverified
SG-SINSG

Singapore

Operational
NODES3 / 3 online
CAPACITY64%
Singaporeverified

EDGE NETWORK

Request entry points & Anycast edge

Full topology spec

EDGE-BOM

Mumbai

EDGE-DEL

Delhi

EDGE-SIN

Singapore

EDGE-FRA

Frankfurt

NETWORK FLOW

Request transmission architecture

Hop-by-hop isolated routing

HOP 01
User Request

Client initiates TLS handshake; origin remains concealed.

HOP 02
Edge Ingress

Anycast routing, DDoS mitigation & TLS termination upstream.

HOP 03
Cloud Region

Traffic sent down outbound tunnel directly to hypervisor.

HOP 04
Compute Nodes

Isolated Linux VPS or container workload with NVMe storage.

Architecture

What happens between a request and your code

Five hops, and only the first one is on the public internet. Select a stage to see what it does.

STAGE 01 // CLIENT SIDEProtocol: HTTPS / TLS 1.3

User

A request leaves the client browser or API client. Nothing about A2Cloud internal architecture is exposed to it beyond your public hostname.

01 / 05 hops

SECURITY & ROUTING SPEC

SecurityEncrypted in transit
AddressingPublic DNS only
VisibilityZero origin IP exposure
Enforced at kernel & Anycast edge

Security

Defaults that do not need to be corrected later

Security work is mostly about removing the ways something can be reached by accident. These are the controls the platform applies for you.

We describe what the platform enforces. We do not publish uptime, breach or certification claims we cannot evidence.

Isolation

Infrastructure isolation

Instances run as separate containers with enforced CPU, memory and disk limits. One workload cannot starve another.

Ingress

Secure networking

HTTP services can be delivered down an outbound tunnel, so the origin never has to accept inbound traffic. Private networking keeps internal traffic off the public path.

Observability

Monitoring

Per-instance CPU, memory, disk and network history is recorded, along with an audit trail of power and configuration changes.

Identity

Access controls

SSH key authentication with password login disabled, IP allowlists on management endpoints, and per-user API tokens you can revoke.

A2Recon

Developer security tooling

A2Recon maps what you are exposing across ranges you own, and flags changes as they appear.

A2Shield

Edge protection

A2Shield fronts public endpoints with Cloudflare, so filtering happens upstream of your workload rather than on it.

Get started

Ready to build on A2Cloud?

Deploy infrastructure, experiment in A2Labs, and build on the same platform. No sales call, no account review queue.

Open source panel · A2Panel is AGPL-3.0 licensed