-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathindex.html
More file actions
227 lines (219 loc) · 14.9 KB
/
Copy pathindex.html
File metadata and controls
227 lines (219 loc) · 14.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>FosterStack — self-hosted build cache for Gradle and Maven, maintained after the Build Cache Node EOL</title>
<meta name="description" content="Infrastructure worth keeping. The Develocity Build Cache Node is deprecated after December 31, 2026. FosterStack is a self-hosted, MIT-licensed replacement — one remote build cache server for both Gradle and Maven, maintained, patched, and verifiable.">
<meta property="og:title" content="FosterStack — self-hosted build cache for Gradle and Maven">
<meta property="og:description" content="Infrastructure worth keeping. A self-hosted, MIT-licensed replacement for the deprecated Develocity Build Cache Node — one remote build cache server for Gradle and Maven, maintained, patched, and verifiable.">
<meta property="og:url" content="https://fosterstack.com/">
<meta property="og:type" content="website">
<link rel="canonical" href="https://fosterstack.com/">
<link rel="icon" href="/favicon.svg" type="image/svg+xml">
<link rel="icon" href="/favicon.ico" sizes="any">
<link rel="apple-touch-icon" href="/apple-touch-icon.png">
<style>
:root {
--bg: #ffffff; --fg: #16181d; --muted: #5b6472; --line: #e4e7ec;
--accent: #0d7a5f; --accent-fg: #ffffff; --card: #f6f8f9; --warn-bg: #fff7ed; --warn-line: #fdba74;
--mark: #0f4d66;
}
@media (prefers-color-scheme: dark) {
:root {
--bg: #101318; --fg: #e8eaf0; --muted: #98a2b3; --line: #262c36;
--accent: #2fbf95; --accent-fg: #08110e; --card: #171c23; --warn-bg: #241a10; --warn-line: #7c4a12;
--mark: #e8eaf0;
}
}
* { margin: 0; padding: 0; box-sizing: border-box; }
body {
background: var(--bg); color: var(--fg);
font: 16px/1.6 system-ui, -apple-system, "Segoe UI", Roboto, sans-serif;
-webkit-font-smoothing: antialiased;
}
main { max-width: 44rem; margin: 0 auto; padding: 0 1.25rem 4rem; }
header.site { max-width: 44rem; margin: 0 auto; padding: 1.25rem; display: flex; align-items: baseline; gap: .6rem; }
.logo { font-weight: 700; font-size: 1.05rem; letter-spacing: -.01em; }
.logo span { color: var(--accent); }
.logo .mark { width: 1.2em; height: 1.2em; vertical-align: -.24em; margin-right: .4em; }
.tag { color: var(--muted); font-size: .85rem; }
.notice {
background: var(--warn-bg); border: 1px solid var(--warn-line); border-radius: 8px;
padding: .7rem 1rem; font-size: .92rem; margin: 1.5rem 0 2.5rem;
}
h1 { font-size: 2rem; line-height: 1.2; letter-spacing: -.02em; margin-bottom: 1rem; }
.lede { font-size: 1.12rem; color: var(--muted); margin-bottom: 2rem; }
h2 { font-size: 1.25rem; margin: 3rem 0 .9rem; letter-spacing: -.01em; }
p + p { margin-top: .8rem; }
.cards { display: grid; grid-template-columns: repeat(auto-fit, minmax(15rem, 1fr)); gap: .8rem; margin-top: 1rem; }
.card { background: var(--card); border: 1px solid var(--line); border-radius: 10px; padding: 1rem 1.1rem; }
.card h3 { font-size: .98rem; margin-bottom: .35rem; }
.card p { font-size: .9rem; color: var(--muted); }
ul.trust { list-style: none; margin-top: .5rem; }
ul.trust li { padding: .45rem 0 .45rem 1.6rem; position: relative; }
ul.trust li::before { content: "✓"; position: absolute; left: .2rem; color: var(--accent); font-weight: 700; }
code, pre { font-family: ui-monospace, "SF Mono", Menlo, monospace; font-size: .88em; }
code { background: var(--card); border: 1px solid var(--line); border-radius: 5px; padding: .1em .35em; }
pre code { background: none; border: 0; padding: 0; color: inherit; font-size: 1em; }
button {
padding: .7rem 1.3rem; font-size: 1rem; font-weight: 600; cursor: pointer;
background: var(--accent); color: var(--accent-fg); border: 0; border-radius: 8px;
}
button:disabled { opacity: .6; cursor: default; }
table { width: 100%; border-collapse: collapse; font-size: .92rem; margin-top: 1rem; }
th, td { text-align: left; padding: .55rem .6rem; border-bottom: 1px solid var(--line); vertical-align: top; }
th { font-size: .8rem; text-transform: uppercase; letter-spacing: .04em; color: var(--muted); }
pre { background: #0f172a; color: #e2e8f0; padding: .9rem 1rem; border-radius: 8px;
overflow-x: auto; font-size: .9rem; line-height: 1.5; }
.cta-row { display: flex; gap: .6rem; flex-wrap: wrap; margin-top: 1.1rem; }
.btn { display: inline-block; padding: .55rem 1rem; border-radius: 8px; font-weight: 600;
text-decoration: none; background: var(--accent); color: #fff; }
.btn-secondary { background: transparent; color: inherit; border: 1px solid #cbd5e1; }
.muted-note { color: var(--muted); font-size: .93rem; margin-top: 1.1rem; }
footer { border-top: 1px solid var(--line); margin-top: 4rem; padding: 1.5rem 1.25rem 3rem; }
footer div { max-width: 44rem; margin: 0 auto; color: var(--muted); font-size: .82rem; }
a { color: var(--accent); }
</style>
</head>
<body>
<header class="site">
<div class="logo"><svg class="mark" viewBox="0 0 96 96" aria-hidden="true" focusable="false"><rect x="12" y="14" width="72" height="18" rx="5" fill="var(--mark)"/><rect x="12" y="39" width="48" height="18" rx="5" fill="var(--mark)"/><rect x="12" y="64" width="26" height="18" rx="5" fill="var(--accent)"/></svg>foster<span>stack</span></div>
<div class="tag">Infrastructure worth keeping.</div>
</header>
<main>
<div class="notice">
Gradle Inc. has deprecated the free Develocity Build Cache Node: it "will no longer be
distributed, supported or available after December 31, 2026." The migration path they
offer requires a commercial Develocity subscription.
</div>
<h1>Your build cache shouldn't die with its vendor.</h1>
<p class="lede">
FosterStack is a self-hosted remote build cache server — a Develocity Build Cache Node
replacement that speaks the same Gradle remote build cache HTTP protocol, so migrating is
mostly a URL change. The same server implements the Apache Maven Build Cache Extension's
remote HTTP mode (Maven acceptance coverage is in progress), so a mixed Gradle and Maven
shop runs one deploy instead of two. Open source core, one-command deploy, and the thing
that matters: it stays patched, on a promise.
</p>
<h2 id="try">Try it now</h2>
<p>There is no signup, no waitlist, and no license key for the free tier. Pull the
image and point your build at it:</p>
<pre><code>docker run -d -p 8080:8080 ghcr.io/fosterstack/cache:latest
curl localhost:8080/healthz # -> ok</code></pre>
<p class="cta-row">
<a class="btn" href="https://github.com/fosterstack/cache#quickstart-docker">Quickstart</a>
<a class="btn btn-secondary" href="https://github.com/fosterstack/cache/blob/main/docs/migrate-from-bcn.md">Migrate off Build Cache Node</a>
<a class="btn btn-secondary" href="https://github.com/fosterstack/cache">Read the source</a>
</p>
<p class="muted-note"><strong>Where it stands:</strong> v0.1 — early. The cache core and
HTTP surface are tested, and the Gradle path is acceptance-tested against a real
multi-module build in CI; the release pipeline works and its evidence chain is being
rebuilt — the repository's SECURITY.md states exactly what is and is not proven today.
Nobody is running it in a production build pipeline yet except us. Bugs and questions go to
<a href="https://github.com/fosterstack/cache/issues">GitHub issues</a>, which is also
where the roadmap gets argued with.</p>
<h2>Stay in touch</h2>
<p>We do not collect email addresses. To follow the project,
<a href="https://github.com/fosterstack/cache">star the repository</a> or use
<strong>Watch → Custom → Releases</strong> on GitHub — that notifies you on a new
release and nothing else, and it is a subscription you control and can revoke without
asking us.</p>
<h2>What you get that a bare HTTP endpoint doesn't give you</h2>
<p>Yes — Gradle's remote cache protocol is just GET and PUT, and you could point it at any
object store. What you'd be rebuilding yourself is everything around that:</p>
<div class="cards">
<div class="card"><h3>Cache management</h3><p>Size-capped LRU eviction that keeps a busy CI cache healthy without hand-tending — set the cap, and the oldest-unused entries make room.</p></div>
<div class="card"><h3>Authentication</h3><p>HTTP Basic Auth over TLS, wired the way Gradle and Maven already expect credentials. Constant-time comparison, no credential ever logged.</p></div>
<div class="card"><h3>Metrics & status</h3><p>Prometheus metrics, a read-only status page with hit rates and size-vs-cap, and a Grafana dashboard in the repo — so you know the cache is earning its keep.</p></div>
<div class="card"><h3>Maintenance target</h3><p>Dependency CVEs remediated fast — target within 48 hours of disclosure. A stated intention until the paid tiers exist, and the release history is the track record either way.</p></div>
<div class="card"><h3>Acceptance-tested</h3><p>Every change runs against a real multi-module Gradle build in CI: a from-scratch second build must produce real remote-cache hits, or the change does not merge.</p></div>
<div class="card"><h3>30-minute migration</h3><p>A step-by-step guide for existing Build Cache Node deployments. Same protocol, same CI config shape — migrating is mostly a URL change.</p></div>
</div>
<h2>Built to be verified, not trusted</h2>
<p>We're a new vendor asking to sit in your build pipeline, so the burden of proof is on us.
The answer is to make everything checkable:</p>
<ul class="trust">
<li>MIT-licensed core. Read the code before you run it.</li>
<li>One public container image. Free and paid users pull the identical bytes — scan exactly what you deploy.</li>
<li>When the paid tiers ship, a license key will unlock them in the same public image — no private registry, no gated downloads. (They are not built yet; the pricing below is direction, not a shelf.)</li>
<li>Security patches are never withheld from the free tier. Not delayed, not embargoed — never.</li>
<li>Signed commits, signed releases, public release notes. The repository's SECURITY.md states exactly what the release evidence does and does not prove today.</li>
</ul>
<h2>What we do not collect</h2>
<ul class="trust">
<li><strong>No telemetry, and no required FosterStack connection.</strong> The server
reports nothing to us — no usage data, no license check, no update ping — and today's
free core makes no outbound connections at all: it works identically on a machine with
no route to the internet. When the paid features ship, the only outbound traffic will
be what you configure (your identity provider for SSO, your peer replicas for HA) —
endpoints you choose, never FosterStack.</li>
<li><strong>This website collects no email addresses.</strong> There is no signup
form, no waitlist, and no newsletter. It sets no cookies, runs no analytics, and
loads nothing from a third party.</li>
<li><strong>The only personal data FosterStack LLC holds</strong> is the irreducible
minimum required to bill a paying customer — handled by Stripe — and whatever you
voluntarily put in an email to support. See §2 of the terms of service.</li>
</ul>
<p class="muted-note">Deliberately not claiming "we never collect any personal data":
billing a customer requires an email address, and a privacy claim that is convenient
but false is worse than none.</p>
<h2 id="pricing">Pricing</h2>
<p>Per product. Free is the full product.</p>
<table>
<tr><th>Free</th><th>Team</th><th>Business</th><th>Compliance</th></tr>
<tr>
<td>The full cache server, MIT-licensed, self-hosted. Every security patch, the
<code>-fips</code> image, and all release evidence, free.</td>
<td>$49/month — multi-user access control, SSO (OIDC), per-project usage analytics,
email support (1-business-day target).</td>
<td>$199/month — everything in Team, plus HA/replication and priority support with
the CVE-response target.</td>
<td>$499/month, billed annually — everything in Business, plus the FIPS 140-3
applicability statement, signed per-release attestation letters addressed to you,
security-questionnaire support up to 8 hours per year (async), and named-version
LTS. <a href="/regulated/">Who this is for.</a></td>
</tr>
</table>
<p><strong>No sales call. No per-seat tax. No enterprise pricing mystery.</strong></p>
<p style="color:var(--muted); font-size:.95rem">
The Compliance tier, plainly: the security evidence underneath — SBOMs, SLSA
provenance, signatures, VEX statements, and the FIPS 140-3 validated module
(CMVP certificate #5247) — is public and free, verifiable by anyone. What the tier
sells is the authored analysis — a FIPS applicability statement mapping the
validated module boundary onto this product — plus per-release attestation letters
signed by FosterStack LLC, and time on your security questionnaires. FosterStack
Cache is not "FedRAMP compliant" or "CMMC compliant"; those attach to your service
and your organization, never to a component you deploy. It is validated crypto and
publishable evidence <em>for</em> your compliance program.
</p>
<p style="color:var(--muted); font-size:.9rem; margin-top:.6rem">
Self-serve, credit card. Monthly tiers cancel anytime; Compliance is an annual
term. Priced so an engineering manager can expense it
without a procurement cycle.
</p>
<h2>Roadmap honesty</h2>
<p>Gradle and Maven both run against the same server today; we maintain the cache
server, while the Maven client side is Apache's own Build Cache Extension. A dependency cache —
the same server restoring <code>node_modules</code>, <code>~/.m2</code>, and
<code>~/.gradle/caches</code> by lockfile key, so ephemeral CI agents stop
re-downloading the world — is next on the list, npm first. What is
not on the list yet is a Helm chart and the paid tiers above — Team, Business, and
Compliance are described so you know where this is going, not sold as available; Free
is real and complete today. If you need something sooner,
<a href="https://github.com/fosterstack/cache/issues">open an issue</a> — that is what
moves the roadmap.</p>
</main>
<footer>
<div>
<p>FosterStack is not affiliated with, endorsed by, or sponsored by Gradle Inc.
"Gradle" and "Develocity" are trademarks of Gradle Inc., used here only to identify
compatibility. FosterStack contains no Gradle Inc. code; it is a clean-room implementation
of the documented remote build cache HTTP protocol. Apache Maven is a trademark of the
Apache Software Foundation; the Maven Build Cache Extension is Apache's project, not
ours.</p>
<p style="margin-top:.6rem">© 2026 FosterStack · <a href="/regulated/">For regulated markets</a> · <a href="https://github.com/fosterstack/cache">github.com/fosterstack/cache</a> · <a href="mailto:hello@fosterstack.com">hello@fosterstack.com</a></p>
</div>
</footer>
</body>
</html>