On this page

Customer infrastructure

MIOSA can orchestrate products across infrastructure operated by MIOSA or controlled by the customer.

The product keeps one resource model and control plane while placement determines where work executes.

Provider accounts, regions, pools, host inventory, placement policy, and verification receipts belong to the organization.

Workspace-specific environment variables, secrets, projects, and workload defaults remain workspace scoped and are applied only after organization capacity is selected.

Choose an infrastructure model

MIOSA-managed

MIOSA operates compute, networking, host lifecycle, capacity, and placement.

OpenComputers

Connect an individual workstation or owned server through an outbound agent session.

Bring Your Own Cloud

Install a governed MIOSA worker region inside a customer AWS account or Google Cloud project.

Hybrid placement

Keep governed workloads in customer infrastructure and use other capacity only where policy permits.

OpenComputers and Bring Your Own Cloud are different products.

OpenComputers connects individual machines.

Bring Your Own Cloud creates a governed cloud capacity region that remains orchestrated by the MIOSA control plane.

Control plane and customer cloud

MIOSA remains the orchestration authority.

The customer controls its cloud account, identity policies, network, provider resources, and provider bill.

MIOSA controls desired capacity, placement, immutable runtime generations, host acceptance, scheduling, drain, and reconciliation.

Provider foundations

ProviderCurrent packageCurrent boundary
AWSTerraform and CloudFormationPrivate networking, scoped identity, immutable host templates, artifact inputs, and fail-closed acceptance
Google CloudTerraformSeparate keyless actuator and worker identities, network, firewall, immutable host image, artifact access, and acceptance handoff

Activation sequence

  1. Create the customer-cloud region in MIOSA.
  2. Apply the reviewed provider package in the customer account or project.
  3. Register the provider outputs with MIOSA.
  4. Run identity, network, quota, image, and artifact preflight.
  5. Boot one acceptance worker.
  6. Verify KVM, storage, runtime generation, authenticated session, and workload execution.
  7. Record the evidence.
  8. Record separate Sandbox, Computer, and Deployment verification receipts for every workload type that will use the pool.
  9. Explicitly enable placement.

Infrastructure creation does not make a region live.

Placement begins only after the full acceptance contract passes.

Shared responsibility

ResponsibilityCustomerMIOSACloud provider
Account or project ownershipOwnsValidates accessHosts account services
IAM and network policyApproves and ownsRequests scoped capabilitiesEnforces
Worker runtimeSupplies capacityVersions, verifies, and reconcilesRuns infrastructure
Workload placementSets policySchedules and recordsProvides compute
Provider billingPaysReports MIOSA usage separatelyBills resources
Host healthReceives incidentsVerifies runtime census and acceptanceReports infrastructure state

Product contract

Your product should not need a different workflow for every provider.

MIOSA resolves the target, checks policy and capacity, dispatches work, and reports one status and evidence shape.

Use OpenComputers for individual owned machines.

Use customer-cloud regions for governed pools of AWS or Google Cloud capacity.

Use MIOSA-managed compute when the customer does not require a cloud-account boundary.

See also

Was this helpful?