Skip to content
HN On Hacker News ↗

Self-hosted Carbon — on-prem & air-gapped manufacturing ERP

▲ 54 points • 29 comments • by barbinbrad • 2w ago • HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is AI.

97 %

AI likelihood · overall

AI
0% human-written 100% AI-generated
SEGMENTS · HUMAN 0 of 1
SEGMENTS · AI 1 of 1
WORD COUNT 1,243
PEAK AI % 97% · §1
Analyzed
Sep 24
backend: pangram/v3.3
Segments scanned
1 windows
avg 1243 words each
Distribution
0 / 100%
human / AI fraction
Verdict
AI
Pangram v3.3

Article text · 1,243 words · 1 segments analyzed

Human AI-generated
§1 AI · 97%

On-prem/VPC/Air-gappedOpen-source ERP that runsinside your CMMC boundaryThe whole system of record — ERP, MRP, MES and QMS — on Postgres you own. On-prem, in your VPC, or fully air-gapped. Open source, so you can audit every line before it ever touches your most sensitive records.Carbon / ConsoleOn-prem · LiveCMMC · NIST 800-171Built for your CMMC boundaryKeep CUI inside a boundary you control. We provide the SSP, POA&M and SPRS inputs for Enterprise deployments, mapped to how Carbon runs on your infrastructure.Data ownershipYour records, your databaseBOMs, travelers, serial genealogy and costs live in a Postgres database you own — never copied to a vendor's cloud.Complete controlThe whole layer is yoursYou hold the network, the keys, the models and the backups — the whole layer is yours to secure, audit and control.Two hard tech unicorns run Carbon on their own servers.Defense · aerospace · regulated manufacturingBuilt for CMMCCMMC-compliant work stays inside your walls.Defense and aerospace manufacturers handling CUI can't ship their record of production to someone else's cloud. Self-hosting Carbon keeps that data inside your own CMMC boundary — and for Enterprise deployments we hand you the SSP, POA&M and SPRS inputs an assessor will ask for.Data residencyYour data never leaves your wallsCarbon runs against a Postgres database you own, on hardware you control. BOMs, travelers, serial genealogy and costs stay inside your perimeter — on-prem, in your VPC, or fully air-gapped.Open sourceAudit the code before you deploy itThe whole application is on GitHub — the Community edition under AGPL-3.0. Read every line, run a security review, and extend it to fit your process — no black box sitting on your most sensitive records.White-gloveA team that deploys with youFor regulated and enterprise programs we scope the install, migrate your legacy data, and back it with an SLA — so a self-hosted deployment isn't a self-serve one.Multi-entity · Multi-locationEvery site on one ledger you own.Run a single shop or a multi-national manufacturing engine from one Postgres database inside your perimeter. Per-entity currency, chart of accounts and tax; consolidated books; inter-site transfers — none of it leaving your network.→ Multi-entity accounting with intercompany transactions→ Consolidated books across every location you run→ One schema, one backup, one system to secureQuality & traceabilityTraceability that never leaves your network.Pull any serial number and get its full genealogy — material certs, operators, measurements, deviations — from a database that sits behind your own firewall. First article, NCR, CAPA and calibration on the same records as production.→ Serial and lot genealogy, forwards and back→ NCR to CAPA workflow with sign-off→ Certificates generated from your own live dataManufacturing executionThe floor, running on your servers.Digital travelers, operator terminals, barcode tracking and finite-capacity scheduling — all executing against the copy of Carbon you host. No cloud dependency between the floor and the record.→ Digital travelers with work instructions→ QR and barcode tracking on every unit→ Finite capacity scheduling that reactsDeploy it your wayOne codebase, from a laptop to a cluster.The same source runs from a single Docker host to a multi-region deployment in your own cloud. No proprietary runtime, no lock-in.01DockerThe whole stack — app, API, MCP server and Postgres — runs in Docker containers. Stand it up on a single box to evaluate, then scale out.02Your own cloudDeploy into your own VPC on AWS, GCP or Azure, against managed Postgres. You keep the network, the keys and the backups.03On-prem & air-gappedRun entirely inside your own network with no outbound calls — built for defense, ITAR-restricted and classified programs. Air-gapped licensing is an Enterprise feature.# Clone the source and bring up the whole stack git clone https://github.com/crbnos/carbon.git cd carbon docker compose up -d # App, API, MCP server and Postgres — all on your box.→ Full deployment guides live in the documentation.Your stack, top to bottomOwn the database, the models, and the files.PostgresOne database, and it's yoursERP, MRP, MES and QMS share a single Postgres schema with row-level security. No sync jobs between systems, no vendor data lake — just your database.Your LLMBring your own agentsEvery table is a REST endpoint and a built-in MCP server exposes the whole backend. Point Claude, ChatGPT or a local model at your live data — inside your perimeter, on your keys. API keys and MCP are a Business feature, so self-hosting them needs a commercial license.Your storageFiles stay where you put themAttachments, drawings and certificates live in object storage you control, behind signed URLs and access control — never a public bucket.Nothing held back for the cloud.Self-hosted Carbon is the same codebase that runs the managed cloud — the Community edition free under AGPL-3.0, Enterprise features unlocked with a commercial license.ERP — quotes, orders, purchasing, inventory and job costingMRP — demand, supply planning, BOM and routing versionsMES — digital travelers, operator terminal, live schedulingQMS — first article, NCR/CAPA, calibration and genealogyREST API and MCP server across every module (commercial license to self-host)SSO / SAML, granular permissions and row-level securityMulti-entity, multi-location, consolidated accountingITAR-ready, CMMC and NIST 800-171 aligned deploymentOpen source coreRead it. Run it. Extend it.The whole application is on GitHub — a typed TypeScript monorepo on Postgres. The Community edition is licensed AGPL-3.0 and free to self-host; Enterprise modules and air-gapped licensing require a commercial license. Audit it against your security requirements before a single record ever lands in it.Star on GitHubDeveloper surfaceTypeScriptReactPostgresRLSDockerREST + MCPAGPL-3.0 coreCommon questions.Is Carbon open source?Yes. The Community edition — the core ERP, MRP, MES and QMS — is on GitHub under AGPL-3.0 and free to self-host. A private fork is fine under AGPL-3.0. You need a commercial license to use Enterprise features, or to keep your changes private from the people who use your modified version (AGPL-3.0 requires you to offer them the source). Either way, every line is in the public repository, so you can audit it before you deploy.Does Carbon help with CMMC compliance?Yes. Self-hosting Carbon keeps your CUI inside your own boundary, which is the foundation of a CMMC and NIST 800-171 program. When you run Carbon on our bring-your-own-cloud (BYOC) infrastructure, we guarantee the deployment is audit-ready and provide the compliance artifacts an assessor asks for — a System Security Plan (SSP), a Plan of Action & Milestones (POA&M), and the SPRS score inputs — mapped to how Carbon runs in your cloud.Can Carbon run fully air-gapped?Yes, with an Enterprise license. Carbon runs on Docker against a Postgres database you control, and air-gapped licensing lets it run inside a restricted network with no outbound calls — built for classified and ITAR-restricted programs.Is the self-hosted version the same as the cloud?It is the same codebase. The managed cloud at app.carbon.ms is this repository, operated by us. Self-hosting gives you the same ERP, MRP, MES and QMS on infrastructure you own; the same REST API and MCP server need a commercial license when self-hosting, and other Enterprise features unlock with one too.Can I bring my own AI models?Yes. The whole backend is exposed over a REST API and a built-in MCP server, so you point your own agents — Claude, ChatGPT, a local model — at your own data. API keys and the MCP server are a Business feature, so self-hosting them needs a commercial license. Nothing leaves your perimeter unless you send it.Do you help with deployment?For regulated and enterprise programs we offer white-glove deployment, migration and an SLA. Talk to sales and we'll scope it with your team.Run it on your infrastructureYour factory. Your servers.Start from the source today, or have our team scope a deployment for your program.CompanyProductLegal