Belov Cloud: Managed Hosting That Heals Itself
Services & Technologies
Full-stack managed hosting platform — Next.js 15, React 19, TypeScript, PostgreSQL 18, Drizzle ORM, live Stripe billing with volume-tiered pricing, Docker, a custom Caddy build (xcaddy) with the Souin edge cache + Coraza WAF + OWASP CRS, MariaDB, Redis object cache, a zero-dependency Node control agent over WireGuard, Cloudflare for SaaS, CrowdSec, headless Chrome + pixelmatch visual regression, and OpenAI-driven AI-ops for diagnosis, triage and visual judging.
Client
Internal Project
Year
2026
About the Project
Belov Cloud is a boutique managed hosting platform for WordPress and Node/Next.js applications, built from the operating system up rather than assembled from off-the-shelf panels. It is not a reseller account with a logo on it: the marketing site, the customer and admin panel, the billing, the control-plane API, and the workers that operate a fleet of live WordPress sites all live in one codebase and run on infrastructure we provision, tune and heal ourselves.
The premise is simple and slightly unfashionable. Most managed hosts optimize for volume — thousands of sites, a support queue, and an overage line on the invoice. Belov Cloud optimizes for care. It is deliberately small and hand-tended, and the thing that makes that scale is an always-on AI copilot that detects, diagnoses and fixes problems on its own, minute by minute, without waiting for a customer to notice and open a ticket.
Every site is migrated in for free, runs behind an edge cache and a self-hosted web application firewall, is watched both by HTTP probes and by pixel-level visual monitoring, and is billed on a flat per-site price with no per-visit overages and no bill shock.
Location
Global service — control plane in the EU (Hetzner, Germany), data-plane nodes in the US and expandable by region
Competence
Infrastructure engineering, full-stack SaaS development, AI-ops and autonomous remediation, WordPress performance and caching, edge security and WAF operations, multi-tenant isolation, migration engineering, Stripe subscription billing
Industry
Managed Hosting / Cloud Infrastructure / WordPress / SaaS
Our Goals
The goal was to build the host we actually wanted to put client work on — and to prove that a small team, with the right automation, can deliver a level of care that big platforms structurally cannot.
That meant the platform had to:
- Detect a broken site and fix it before anyone reports it, without a human on call.
- Move existing sites off WP Engine, Kinsta, GoDaddy, Cloudways or any other host for free, without breaking anything that worked before.
- Be fast by default, not fast after a customer installs three caching plugins and hopes.
- Include real security — a WAF and IP-level defense — on every plan, not as an enterprise upsell.
- Run WordPress and Node/Next.js apps side by side, on one dashboard, one bill, one on-call.
- Charge a flat, predictable price with a hard spend cap, so a traffic spike never becomes an invoice.
- Never let one tenant’s site touch another’s data, cache, or filesystem.
And underneath all of it, one non-negotiable rule: every claim on the marketing site had to be something we had measured on the actual node. If we could not verify it with a command, it did not ship as copy.
Solution
Belov Cloud runs on two deliberately separated planes. The control plane is the brain — the marketing site, the customer and admin panel, the API, PostgreSQL, and the workers that monitor and heal sites. The data plane is the muscle — nodes that host the actual customer sites. The control plane never hosts a customer site, and it talks to nodes only over a private WireGuard link, never the public internet.
Each node runs Docker plus a small zero-dependency Node agent. Every site gets its own container, its own database and database user, its own volume, and its own Redis key prefix — all keyed off an opaque internal ID minted by the control plane, never off a customer-controlled domain. A custom Caddy build fronts everything: one request path, WAF → full-page cache → reverse proxy to the site’s container.
On top of that sits the part that makes the whole model work: a monitoring and healing loop that runs every minute, an AI layer that diagnoses and triages, and a set of remedies that are all reversible by construction. The platform is designed so that the automation can be wrong without being dangerous.
The commercial layer is equally real: live Stripe with volume-tiered per-site pricing, self-serve checkout mounted inside our own panel rather than a hosted page, full dunning and suspend/resume lifecycle, promo codes, and a 60-day money-back guarantee.
Self-Healing That Is Safe To Leave Unattended
Every minute, the monitor pulls node metrics and probes each managed site, classifying it as healthy, slow, 5xx, TLS-broken, or down. When something fails, autopilot runs a reversible remedy and then verifies the result: reissue the TLS certificate, flush the object and page cache, restart the container, or — for a PHP fatal — parse the error, identify the offending plugin, and deactivate it via WP-CLI. It never deletes anything.
The guardrails matter more than the remedies. A second confirmation probe a few seconds later means one blip never restarts a healthy site. A three-minute cooldown and an hourly flapping budget mean a genuinely broken site gets escalated to a human instead of being restarted forever. Certificates are backed up before reissue and restored if the new fetch fails. An AI triage step picks the first remedy to try — but only from the set that is valid for that symptom, and any unexpected answer or API error falls straight back to the deterministic default. The AI can improve the outcome; it cannot invent a destructive one.
Every detection, heal and verification is written to a per-account activity feed in plain English, so the customer sees what happened and when — including the times nothing was wrong.
Free Migration That Respects What Already Worked
Migration is where most hosting promises quietly break. Belov Cloud exports the source database mysqldump-first, byte-exact, which sidesteps a well-known WordPress corruption mode where placeholder escapes get rewritten during a naive export. On hosts with no dump binary or a disabled exec, it falls back to a resumable pure-PHP row streamer. A truncated dump is never restored: the attempt is bounded and accepted only if it carries a completion marker.
The migrated site then lands on the source host’s own PHP version, clamped to a supported range, so nothing that worked on the old host breaks on the new one. Multisite networks are detected up front and routed to a white-glove path instead of being silently flattened. Sites arrive on a staging domain that is blocked from indexing at the edge, get verified, and only then go live with a proper search-replace against the host the site was actually installed at.
Speed As A Default, Measured Not Claimed
Three cache layers, each verified on the node. OPcache removes PHP recompile cost on every request. A per-site Redis object cache — one prefix per tenant, fail-open by construction — caches database query results. And a Souin full-page cache inside Caddy serves anonymous HTML straight from the proxy without touching PHP at all.
Measured TTFB on the node: 5.4 ms for a cached anonymous hit, 3.5 ms for static assets, roughly 60 ms for a fully dynamic, logged-in render. The golden WordPress image was rebuilt from Apache/mod_php to Caddy + php-fpm with on-demand workers, which dropped idle memory from around 570 MiB per site to about 88 MiB — the difference between a node that hosts a handful of sites and one that hosts many.
Cache coherency is handled by an always-on must-use plugin baked into the image: on any content change it sends per-URL purges to the edge, so edits go live instantly instead of waiting out a TTL — and because purges are per-URL and per-tenant, one site’s purge can never touch another’s cache. Logged-in visitors, carts, checkouts, REST and admin paths bypass the cache entirely.
One deliberate omission is worth naming: PHP JIT is force-disabled, and the image build refuses to produce an artifact with it on. It was segfaulting php-fpm and producing intermittent 502s that the monitor could not see. Chasing a benchmark number was not worth an invisible failure mode on live sites.
Security On Every Plan, Not On The Enterprise Tier
Per-tenant managed WAF is an enterprise-only product at the big CDNs, so we built ours. The edge Caddy image is compiled with Coraza and the embedded OWASP Core Rule Set, running in blocking mode with WordPress-specific exclusions — SQLi, XSS, traversal and scanner traffic get a 403 while legitimate admin, REST and UTM-tagged traffic passes untouched. Per-path and per-field exclusions let a site declare the specific endpoints and form fields that must not be inspected, which is what makes running CRS in blocking mode survivable on real WordPress.
CrowdSec adds behavioural IP-level defense on top, parsing per-site access logs and SSH journals and pushing bans into a firewall ipset. Cloudflare for SaaS gives every customer domain edge TLS and DDoS protection through a single CNAME, with no Cloudflare account of their own and no exposed origin.
Tenancy isolation is enforced structurally rather than by convention: container, database, database user, volume and cache prefix are all derived from an opaque internal ID, the agent returns the authoritative names on provision, and the control plane stores and replays them instead of ever re-deriving a name from a customer-supplied domain.
Visual Monitoring And The AI Judge
HTTP checks tell you a site responded. They do not tell you the homepage now renders as a blank white column. Every ten minutes a worker screenshots each managed site with headless Chrome, diffs it against a stored baseline with pixelmatch, and when the difference exceeds threshold, asks a vision model one question: is this a real regression, or an intended change the owner just published?
Only regressions raise an alert; intended changes are recorded and acknowledged. If the judge is unavailable, the system alerts anyway — the safe default is a false alarm, never a missed outage.
We didn’t rent a control panel and put our logo on it. We built the host — the image, the edge, the firewall, the billing, and the thing that fixes your site at 4am.
One Platform For WordPress And Node
Pure WordPress hosts cannot run your application. Application platforms cannot run WordPress. Belov Cloud runs both from the same panel, the same subscription and the same on-call: managed WordPress with caching, SSL, plugins and WooCommerce watched and self-healed, alongside Git-deployed Node and Next.js apps with health-gated releases, instant rollback, build logs, and managed Postgres, MySQL and Redis. Static sites deploy without a container at all, as atomic symlinked releases served straight from the edge.
Around that sits everything a real hosting business needs and prototypes usually skip: multi-account team memberships, one-click staging with push-to-live, WordPress Multisite with per-subsite domains and slot billing, an admin console with per-node placement and cross-node moves, a documented node-evacuation disaster-recovery runbook, and an AI support chat grounded in an editable knowledge base with a hard daily spend cap and one-click escalation to a human.
Results
Belov Cloud went from an empty repository to a live, revenue-taking managed hosting platform — with real customer WordPress sites on a production node, live Stripe checkout, a self-hosted WAF in blocking mode, and unattended autopilot healing — in a matter of weeks, built as a single coherent system rather than a stack of integrations.
The platform now runs migrated production sites across different plugin stacks, database sizes and legacy configurations, with cached responses served in single-digit milliseconds and a memory footprint per site low enough to make boutique economics work. Failures that used to mean a phone call — an expired certificate, a fatal plugin update, a container that stopped answering — are detected within a minute, remediated automatically, verified, and written to an activity feed the customer can read.
For clients, the result is a host that behaves like an agency: the migration is done for them, the security is on by default, the price does not move when traffic does, and someone — or something — is always watching. For us, it is proof of the thesis behind the whole project: with the right automation, careful hosting does not have to be a luxury service that cannot scale.