GPU compute,
signed unsigned
complexity.

A Kubernetes-native AI/ML platform. Deploy inference endpoints and training jobs on GPU clusters with scale-to-zero, zero-trust networking, and no vendor lock-in — every layer is open source and replaceable.

unsigned deploy — session ● live
$ unsigned deploy --model llama-3.1-70b --gpu a100 --precision bf16 --replicas 0:8
Resolving model registry...
Image pulled from Harbor (cached)
GPU pool: 8x A100-80GB MIG (3g.40gb partitions)
Autoscaler: KEDA + Kueue (0 → 8 replicas)
Network: Cilium eBPF + WireGuard mTLS
Endpoint: llama-70b.unsigned.gg

Deployed. Scale-to-zero active. First request wakes in ~4s.
$
idle cost $0 pod-to-pod WireGuard mTLS rollback git revert precision bf16 / int8 API OpenAI-compatible exit path fork the stack endian little, like nature intended
0x01

Infrastructure that gets out of your way.

/01

Scale to zero, scale to thousands

KEDA + Kueue autoscaling with MIG-isolated GPU partitions. Pay nothing when idle. Burst to full cluster capacity on demand. No cold-start tax beyond the first request. Replica counts are unsigned — there is no going below zero.

/02

Zero-trust by default

Cilium eBPF dataplane with WireGuard-encrypted pod-to-pod traffic. Network policies enforced at the kernel level. mTLS everywhere, no sidecars.

/03

Full observability stack

Prometheus, Grafana, Loki, and Jaeger pre-configured. GPU utilization, inference latency, and cost dashboards out of the box. Alert on what matters.

/04

Secrets & policy as code

Vault for secrets management, OPA Gatekeeper for admission control, External Secrets Operator syncing credentials. Nothing hardcoded, ever.

/05

GitOps everything

ArgoCD manages the full stack. Every change is a pull request. Every deployment is auditable. Rollback is a git revert.

/06

OpenAI-compatible endpoints

NVIDIA Dynamo + Triton inference serving. Drop-in replacement for the OpenAI API — bring your own models or pull from the registry. One endpoint, any framework.

0x02

Production-grade, opinionated stack.

Every component is open source. The platform is the integration, not the lock-in.

Edge & network plane
IngressTraefik
API GatewayKong
NetworkCilium eBPF
EncryptionWireGuard mTLS
Control plane
OrchestrationKubernetes
GitOpsArgoCD
IaCTerraform
AuthKeycloak
SecretsVault + ESO
PolicyOPA Gatekeeper
Inference plane
GPU ServingDynamo + Triton
AutoscalingKEDA + Kueue
RegistryHarbor
Observability plane
MetricsPrometheus + Grafana
LogsLoki
TracingJaeger
0x03

From request to inference.

Every layer is replaceable. No proprietary glue. Fork the stack and run it yourself.

Request Flow Client │ ▼ Traefik (TLS termination, rate limiting) │ ▼ Kong (API gateway, auth, quota enforcement) │ ▼ Cilium (eBPF network policy + WireGuard encryption) │ ├─── Control Plane API (Go, manages deployments/scaling) │ │ │ ▼ │ Keycloak (OIDC, RBAC, tenant isolation) │ └─── Inference Plane │ ▼ KEDA (scale 0 → N from queue depth / HTTP RPS) │ ▼ Kueue (GPU quota, fair scheduling, preemption) │ ▼ Dynamo + Triton (model serving, batching, MIG isolation) │ ▼ A100 / H100 GPU (MIG-partitioned, scale-to-zero)
0x04

Pay for compute, not complexity.

There is no rate card, because there is nothing for sale. unsigned is the platform we run cerebral on, and these are our own books — kept open on purpose. GPU clusters are not cheap; running them well is the craft. Every layer is open source, and what we fix goes back upstream. Villains keep secrets. We publish the bill.

  • GPU-seconds metered, per-second
  • Idle fleet costs $0 — scale-to-zero
  • Egress isn't a profit center here
  • Observability is load-bearing, not an add-on
  • Nobody pays per seat — there are no seats
  • Every layer open source — we can leave too
Fleet ledger — last verified 2026-07-11

The whole operation: 4 boxes · cpu pool 4 · gpu pool 0 · k8s v1.34.5. Published because we have nothing to sell you — transparency is cheaper than marketing.

A100 80GB · MIG 3g.40gb + full
H100 80GB · MIG + full
CPU · general purpose

0x05 · Access

There is no list.

unsigned is not a platform company. It's the platform we built for ourselves, documented like a dataroom. If you're a founder auditing how we operate: the architecture above, the books above, and /learn are the real thing, not the brochure.

Ask Anything

opens your mail client — questions answered, nothing sold

$ cat access-policy.txt
customers: 0x0 — none, by design
operators: cerebral
auditors & the curious: welcome
sales inquiries: returns ENOSYS