One push. Every cloud you own.

Lakefront ships your services to your own Azure, AWS and GCP accounts, and moves them between regions and providers the moment one goes down.

Works with Azure · AWS · GCP · and your AI agents, via auth.md.

checkout-api · lakefront
checkout-apiLive
● Azure · East USAWSGCP
build → push → release47s
10:02:14 resolving framework… next.js
10:02:41 pushing → your registry
10:02:55 rolling out rev 0007
✓ live at checkout-api.lakefront.app

One surface, from your cloud to the edge.

Connections
Your clouds3 accounts · read-scoped, revocable
AAzureVisual Studio EnterpriseConnected
AAWSacme-production · us-east-1Connected
GGCPConnect an account+ Add

Run close to every customer.

Your services sit behind 300+ edge points of presence and route to the nearest healthy region, across all three providers. When a region drops, requests land somewhere else in milliseconds.

9 regionsacross 3 providers
300+ edge PoPsin front of them
Automaticregion & provider failover

Describe a service once. Run it on any cloud.

The same definition compiles to each provider’s native primitives. Start on Azure, add AWS next quarter, never rewrite a line. No Kubernetes to babysit, no YAML to memorize.

lakefront.service.ts
export default service({
  name: 'checkout-api',
  source: repo('acme/checkout'),
  cloud: 'azure',   // or aws · gcp
  regions: ['eastus', 'westeurope'],
  scale: { min: 1, max: 10 },
})

Your agents get a login of their own.

Each agent signs in as itself, asks for only the access it needs, and does the work. It never goes past your permissions, and it stops the moment you revoke it.

Every action is scoped and logged under the agent’s own name, using the openauth.md protocol that Cloudflare and Resend run.

One set of permissions, every provider.

Grant a person or an agent access once. Lakefront maps it to the right IAM roles in each cloud, so you stop reasoning about four permission models at midnight.

Federated, never a stored key

Access is brokered per request and expires on its own.

Scoped to the resource

Deploy this service, read those secrets, nothing wider.

Revoke in one click

Pull a grant and it’s gone from every provider at once.

Every action, logged

A single audit trail across Azure, AWS and GCP.

Access · alex@acme.so
One grant, every cloudFederated · expires in 7 days
Deploy servicesgranted
Read secretsscoped
Manage registrygranted
Delete resourcesrevoked

Push to main. That’s the deploy.

Connect a repo and every push builds an immutable image, runs your tests, and rolls out behind a health check. The CI/CD is already wired. You don’t author it.

Immutable images

Each deploy is a clean build in your own registry.

Health-checked rollouts

Traffic shifts only once the new revision passes.

Instant rollback

Any past revision is one click away, on any cloud.

A URL per pull request

Ship a real preview environment for every branch.

Pipeline · main
Push to mainTriggered by a git push · no YAML to write
Build image8s
Run tests21s
Push to registry14s
4Health-checked rollout4s

Owned by you. Run by us.

Lakefront is a control plane, not a host. Your services, data and bill stay inside the cloud accounts you already have, switch us off and everything keeps running.

Your data never leaves your account
No long-lived keys, ever
Leave anytime; it’s your code
Your cloud bill, zero markup
One audit trail, every cloud
Just containers and your registry

Your cloud. Our deploy button.

Free while you build. You only ever pay your own cloud.