Skip to content

Operate infrastructure from one place

Operate applications and infrastructure with people, automation, and AI agents through one governed control plane.

Opfield gives people and AI agents one governed place to publish applications, connect private services, operate Docker and databases, manage TLS, and control who can change each resource. Start in the web interface or connect Codex, Claude Code, and other compatible agents through authenticated MCP. The same scopes, approvals, Tasks, and audit history apply either way.

Opfield Dashboard with ingress, managed database, and node health

Give your coding agent infrastructure context

Section titled “Give your coding agent infrastructure context”

Install the Opfield skill to teach a compatible agent how Opfield resources, permissions, asynchronous Tasks, delivery, verification, and rollback fit together:

Terminal window
npx skills add the-square-labs/gateway-skills --skill using-gateway

The skill provides operating knowledge; Opfield MCP provides authenticated access to your installation. Follow AI agent skills to install the skill and connect Codex or Claude Code without sharing API tokens.

Opfield is the control center, while your servers continue to run the actual applications and data services. Managed Nodes connect outbound through Opfield Relay, receive only the operations assigned to their role, and report the real result back. Opfield keeps permissions, resource relationships, operation history, and recovery state in one place.

The most important resource chains are:

Publish an application

A domain receives HTTPS traffic, and a Route sends each request to the right application.

%%{init: {"themeVariables": {"fontSize": "20px"}}}%%
flowchart LR
    domain["Domain"] --> certificate["TLS"] --> route["Route"] --> upstream["Application"]

Build and deploy from Git

Opfield turns source code into a versioned artifact and deploys it as a workload.

%%{init: {"themeVariables": {"fontSize": "20px"}}}%%
flowchart LR
    repository["Git"] --> worker["Build Worker"] --> artifact["Artifact"] --> workload["Workload"]

Connect an application to a database

A private binding gives the application its own database identity without exposing the database publicly.

%%{init: {"themeVariables": {"fontSize": "20px"}}}%%
flowchart LR
    application["Application"] --> binding["Private binding"] --> identity["Database identity"]

Turn health signals into alerts

Opfield turns service health and events into notifications for people, status pages, and SIEM systems.

%%{init: {"themeVariables": {"fontSize": "20px"}}}%%
flowchart LR
    events["Health and events"] --> notifications["Notifications"] --> consumers["Status / SIEM"]

This portal combines four kinds of material:

  • Guides: goal-oriented instructions for configuring a capability.
  • Journeys: complete happy paths spanning multiple Opfield areas.
  • Runbooks: operational diagnosis, recovery, updates, and disaster preparation.
  • Reference: stable terminology, ports, feature status, plans, and security boundaries.

Roadmap-only capabilities are labeled explicitly and must not be treated as available runtime features.


This documentation portal and the Opfield product site are built from Git and published as immutable deployments with Opfield Pages. The production site therefore exercises the same build, release-tag, preview, and rollback path documented here.