Your first top-up gets $5 in bonus credit — one-time, for every new account. Get Started
Krova CloudKrova Cloud
Secure by architecture

Run any app in its own microVM. Boots in seconds.

Every Cube is an isolated Firecracker microVM with its own kernel and no public IP — full root SSH, any size you want, billed by the minute at up to 69% less than Lightsail, DigitalOcean, Vultr and Linode.

No subscription — prepaid credit, billed by the minute. Your first top-up gets $5 in bonus credit (one-time).

Boots in secondsOwn kernel per CubeNo public IPFull root SSHBilled by the minute
HOST SERVERKVM ISOLATION BOUNDARYJAILER · uid · chroot · pid-nsYOUR CUBEubuntu 24.04 · own kernelroot@cube:~#full root · per-hour billingNO PUBLIC IP

From nothing to root, in one command

No VPCs, no security groups, no IAM. Create a Cube in the dashboard or from your terminal, and you're SSH'd into your own isolated server in seconds.

bash
$ krova cubes create web-1 --cpu 2 --ram 4 --disk 40 --image ubuntu-24.04
  ✓ Cube provisioned  ·  booted in 0.9s
$ krova ssh web-1
root@web-1:~#

What is a Cube?

A Cube is a lightweight microVM — built on Firecracker, the same isolation technology behind AWS Lambda and Fargate. Each Cube boots its own kernel in complete isolation from every other Cube — never the shared kernel a container hands every tenant on the box.

Firecracker gives you the isolation of a virtual machine with the speed of a container. Krova Cloud is the platform on top: one-click or one-API-call provisioning, per-minute billing, custom domains with automatic HTTPS, snapshots, and team access — without running the hypervisor yourself.

Explore the Cube →See how isolation works →

Everything ships with every Cube

Simple but not simplistic. Real VMs, real isolation, real control — nothing to bolt on.

Full root SSH access

  • Your SSH key baked in at creation
  • Run any software — no restrictions
  • Full systemd, package managers, kernel modules

Networking & domains

  • Custom domains with one CNAME + automatic HTTPS
  • Managed ingress — no certificates to handle
  • TCP port forwarding with IP whitelists

Snapshots & backups

  • Live snapshots — no downtime
  • Restore to roll back instantly
  • Pre-deletion backups for exact replicas

Teams & permissions

  • Spaces to organize by project or team
  • Granular per-Cube access control
  • Per-Space credit balance and billing

Power off & start

  • Power off to stop compute billing instantly
  • Start again in seconds (cold boot)
  • Auto power-off when credits run out

API & automation

  • Full v1 REST API for the whole lifecycle
  • Scoped API keys + idempotency
  • Outbound webhooks on every change
For developers

Provision a Cube from your own code

A fully-typed TypeScript SDK, a CLI, an MCP server for Claude & Cursor, webhook verification, an n8n node, and a public REST API — all open-source and published on npm. Spin up a Cube per user, per agent, or per build.

A full-root microVM, at half the bill

Pick any size — these are popular starting points. Every figure is current and real, and you're billed by the minute.

Micro
1 vCPU · 2 GB RAM · 20 GB disk
$5 /mo
Popular
2 vCPU · 4 GB RAM · 40 GB disk
$10 /mo
Large
4 vCPU · 8 GB RAM · 80 GB disk
$19 /mo
XXL
8 vCPU · 16 GB RAM · 100 GB disk
$33 /mo
FeatureKrova CloudAWS LightsailDigitalOceanVultrLinode
Per-instance public IPNonePublic IPv4Public IPv4Public IPv4Public IPv4
SizingAny vCPU/RAM/diskFixed plansFixed plansFixed plansFixed plans
Hardened per-cube sandboxJailer + own kernel
BillingBy the minuteHourly, monthly capPer-secondHourly, monthly capHourly, monthly cap
8 GB RAM / month$20$44$48$40$48

Just need a website, not a server?

Krova Nest is managed, cPanel-style web hosting — one-click WordPress, email, automatic SSL and backups, billed from the same wallet as your Cubes.

Explore Krova Nest

Frequently asked questions

Do I need a credit card to sign up?

No — signing up is free and requires no payment information. To run Cubes you load prepaid credit; your first top-up gets $5 in bonus credit (one-time), which is enough to run a small Cube around the clock for weeks. Adding that first card also unlocks the Starter tier automatically.

Do Cubes share a kernel like containers?

No — and this is the core difference. A container shares the host's single Linux kernel with every other tenant on the machine, so one kernel-level bug can expose all of them. Each Cube is a Firecracker microVM that boots its own separate kernel, isolated by the CPU's hardware virtualization (KVM) — the same isolation technology behind AWS Lambda. Cubes never share a kernel with each other or with the host.

Does my Cube have a public IP address?

No. Unlike a typical VPS — where every instance is handed a public IP the whole internet can scan and probe — a Cube has no public IP of its own. It lives on a private, NAT'd network. Nothing is reachable from outside unless you explicitly map a port, and every port mapping can be locked to an IP allowlist. Web traffic on your custom domains enters through Krova Cloud's own managed ingress tier, which terminates HTTPS and forwards to your Cube over an internal, mutually authenticated connection — so the machine running your app is never addressed directly from the internet.

Do I actually need a public IP?

For almost everything people run on a server, no — and not having one is a security win. What makes your app reachable is your domain and the ports you choose to expose, not a fixed address bolted to the whole machine. Web apps and APIs are reachable worldwide over HTTPS through Krova Cloud's managed ingress, which issues and renews your certificates automatically, and anything else — SSH, a database, a game server, any TCP service — is reachable through a port mapping you open on demand and can lock to an IP allowlist. You get inbound access to exactly what you expose, without a public address the whole internet can scan, brute-force, and target. Fewer doors, and all of them yours.

Is it protected against DDoS attacks?

Every host sits behind provider-grade, network-level DDoS mitigation, and the design of the platform removes most of the attack surface to begin with: your Cube has no public IP to target, inbound traffic is default-deny until you open a port, and web traffic reaches your app only through our managed ingress tier rather than the machine itself. There is no surge pricing and no bandwidth penalty if you are attacked. If you want application-layer (L7) filtering on top — WAF rules, bot management, rate limiting — you can put your own CDN or reverse proxy in front of your domain; Krova Cloud works behind one, and that service would be on your own account and billing, not resold by us.

How does billing work — what if I only run a Cube for 5 minutes?

Rates are quoted per hour, but you're billed by the minute. Run a Cube for 5 minutes and you pay for 5 minutes, not a full hour — there's no rounding up. Power off a Cube and compute charges (vCPU + RAM) stop immediately; only the disk it occupies on the host keeps billing, at the same per-GB rate. Credit is consumed as you go, and you can watch the balance in real time.

Is there a subscription or monthly plan?

No. Krova Cloud is prepaid pay-as-you-go — there's nothing to subscribe to. You load credit whenever you like and it's drawn down per minute as your Cubes run. Add a card to enable one-click top-ups and optional auto-recharge (we top you back up when your balance gets low). Tiers (which set how many Cubes you can run and how big) unlock automatically as you spend — they're limits, not bills, and cost nothing. Need more headroom? Email support and we'll review your use case and lift your limits where it makes sense.

What happens when my credit runs out?

When your balance can't cover the next hour, every running Cube is automatically powered off — its disk is kept, so you can start it again once you top up. We email you a low-balance warning about five days before you'd run out, based on your current usage, and again when the balance reaches zero. Storage still costs us money while your balance sits at zero, so if a space stays unfunded for seven days we permanently delete its backups and the disks of its powered-off Cubes. We send reminders before that happens, and adding credit at any point before the deletion date keeps everything.

Can I create and manage Cubes with an API?

Yes. Krova Cloud has a full v1 REST API: create a Cube, power it off, start it, snapshot, restore, attach custom domains, open TCP ports, and more — each authenticated with a scoped API key. You create Cubes one request at a time (concurrency limits rise with your tier, and the top tier has no fixed cap), so standing up a whole batch is a simple loop. A machine-readable OpenAPI spec is published at /api/v1/openapi.json.

Can I run Docker inside a Cube?

Yes. Cubes are full virtual machines with their own kernel. You can install and run Docker, Podman, or any other software you would on a regular Linux server.

What happens when I power off a Cube?

The Cube shuts down gracefully and its disk is kept exactly as you left it — nothing on it is lost. Compute charges (vCPU + RAM) stop immediately; only the disk component of the Cube's hourly rate continues, since the rootfs still occupies host disk. Starting it again is a normal cold boot, the same as powering on any server.

How is this different from AWS EC2?

Krova Cloud is designed for simplicity. There's no VPC to configure, no security groups to set up, no IAM policies to write. You create a Cube, get an SSH connection, and you're done. Billing is transparent and by the minute.

Is my data safe?

Each Cube is an isolated microVM with its own kernel — not a container — and its Firecracker process runs inside a per-cube jailer sandbox (its own unprivileged user, chroot, and PID namespace), so even a hypervisor escape lands in an isolated sandbox rather than as root on the host. Your data is fully isolated from other users, and snapshots and backups live on separate, redundant storage. We still recommend keeping your own regular backups for anything you can't afford to lose.

Why not just run Firecracker or containers myself?

Firecracker is open source, so you could — but on its own it's a low-level hypervisor. You'd still have to build provisioning, networking, custom-domain TLS, snapshots, billing, and team access, and operate the hosts yourself. Krova Cloud is that entire platform on top of Firecracker — the same microVM technology behind AWS Lambda and Fargate — so you get VM-grade isolation in one click instead of weeks of plumbing. And unlike a shared-kernel container, where a single kernel bug can expose every tenant on the host, each Cube runs its own kernel with KVM-enforced VM isolation — which is what makes it safe for untrusted, multi-tenant workloads.

Why is Krova Cloud cheaper than AWS, DigitalOcean, or Linode?

We don't operate hyperscale data centers, run a sales team, or maintain a dozen sibling services. We run a lean operation — lightweight microVMs on efficient infrastructure — and pass the savings on, typically less than half the price of an equivalent VPS. Same real, dedicated resources. A very different bill.

Stop exposing servers. Start building.

Create your free account, make your first top-up — it gets $5 in bonus credit — and SSH into your first Cube in under a minute.