Hi everyone!
Provisioning infrastructure, deploying containers, and diagnosing issues just became wayyyy easier.
After a bunch of hard work from our team, I'm thrilled to announce the launch of Cycle's hosted MCP. 🥲
As more and more teams have begun using AI agents with Cycle, we wanted to double-down on the experience. It was important to us that AI tooling had the proper context to work with the platform: understanding fundamentals, avoiding anti-patterns, and optimizing calls to reduce token usage. In reality, I think we've spent more time optimizing the MCP than actually building it.
Check out our official announcement here.
Chris has also recorded a video for getting started.
We're eager to see what y'all can do with the MCP :)
The next update to NA control plane will be deployed on Tuesday, September 29, around 5:00 AM EST (09:00 UTC).
While the update rolls out, users may see brief network interruptions as the new IPsec algorithms take effect. These interruptions will only affect traffic between Cycle nodes that communicate over the public internet. Private networking and connections to non-Cycle services will not be affected.
Each interruption should last between 2 seconds and 1 minute and will recover on its own.
Hey team! I'd love to be able to choose Raid options for the drives on the server when provisioning a new server. For example, there are servers where we need more space and care less about data loss, and we would choose Raid 0 vs the Raid 1 default.
Hello!
We are teaming up with Cherry Servers for a live webinar, Sep 23, 2026, 1:00 PM – 2:00 PM GMT, where we will show you how you can deploy, manage and maintain bare metal servers or virtual machines on Cherry Servers using Cycle.
I'm sure it'll be mostly familiar with those already using the portal on a regular basis but if you are curious about Cherry Servers this could be of interest.
Hosted by Jake Warner, CEO and founder of Cycle.io and Lili Hellriegel, Head of Enterprise Solutions at Cherry Servers.Signup here!
Hi, we are using non-hosted zones with multiple records to load balance between VMs.
It seems a bit wrong to have multiple identical records, one can have TLS enabled and one can have it disabled, but this is incorrect, as both will likely have TLS, as the LB seems to enable TLS even if only one is enabled.
A suggestion that would be more logical for this, would be to have a single record, and then allow multiple targets instead. This way we only add a single @ record, enable TLS, and point it to app-1 and app-2, etc.
According to reports from Cycle customers, sometime after 3 pm EST today, the service AWS GuardDuty started to flag DNS traffic from Cycle servers to Cisco's OpenDNS resolver (208.67.222.222) as botnet command and control activity.
208.67.222.222
This report is a false positive and nothing on your infrastructure is pointing to a compromise based on this specific event in GuardDuty.
What's being reported is a high-severity alert for something that looks like this.
The discovery service in the environments use upstream resolvers for egress traffic:
8.8.8.8
8.8.4.4
1.1.1.1
1.0.0.1
9.9.9.9
These providers are deliberately rotated across.
We are confident this is a false positive due to the IP thats flagged being a trusted OpenDNS endpoint provided by Cisco. It is absolutely not botnet infrastructure.
As an organization going through our own SOC1/SOC2 audits regularly, it would be very helpful to have a SAML SSO login option so we can login with our identity provider (currently google workspace) and ensure that when we remove team members there it immediately reflects on Cycle.
Today when you update a core environment service like a Load Balancer, Discovery or VPN, you only get the option to restart to update to latest, but if something is not working you have no way to rollback to restore availability until a fix can be made.
So adding an option to be able to roll back to previous running version (not the last version but the one the environment was running before upgrade) to at least being able to quickly resolve issues would be amazing and make the updates a lot less scary, as even for HA services they would likely run in the same environment :)
Cycle has added support for CherryServers, a bare metal infrastructure provider with 7 data centers spread around the globe. Additionally, this update contains a number of security improvements both within CycleOS and the platform itself.
CherryServers Integration
Deploying bare metal infrastructure? Looking for a European-owned infrastructure provider? Cycle now supports CherryServers as a native integration.
Ceph Volume Deletes
We fixed a bug that prevented a disconnected Ceph volume from being properly deleted.Previously, Cycle only applied user/group scoping if the container's USER argument specified a numeric UID/GID. Now, we also support strings (usernames), furthering support for more images.
Container UID/GID Scoping
Previously, Cycle only applied user/group scoping if the container's USER argument specified a numeric UID/GID. Now, we also support strings (usernames), furthering support for more images.
Kernel 6.12.95
CycleOS has been recompiled with the 6.12.95 linux kernel, which containers a number of security patches. Most importantly, a patch for CVE-2026-64561, a KVM vulnerability which could allow an application to escape from a virtual machine.
Read the full release notes →
Hi all. I'm Heiðar, the new Developer Advocate at cycle and I have a question for the community.
With there seeming to be no end to the stability issues GitHub have been dealing with lately I wonder if any of you have been impacted?
I have years of experience operating and maintaining a private GitLab server and was for years pushing for that company to move to either GitLab.com or GitHub - but I'm now revising my stance on the topic. When critical parts of your SDLC have worse uptime and availability than the product that results from that delivery pipeline - it makes sense for business continuity to take back control.
What do you think?
This release brings Cycle developers more automation and control. Scheduled Functions let the scheduler service launch instances on a cron schedule automatically, without any external service. Traffic splitting unlocks phased rollouts, A/B testing, and experimentation through simple weighting interface. In addition, we've also added the ability to create TLS certificates via HTTP challenge, improved server network monitoring, and shipped a kernel update.
Scheduled Functions
Define a cron expression in your function config, and Cycle's scheduler service will automatically launch an instance on that schedule.
Traffic Splitting
You can now split traffic across different destinations, making A/B testing, phased rollouts, and experimentation easier than ever.
TLS Certificates via HTTP Challenge
Cycle now supports both HTTP and DNS challenges for automated TLS certificate provisioning. The HTTP challenge method is particularly useful for deployments where you only control a CNAME record for traffic routing.
Network Neighbors
The 'Live Monitor' launched in the previous update now includes information about network neighbors and their state.
Updated Kernel and Container Runtime
CycleOS is now built with kernel 6.12.95, which contains a fix for a critical KVM vulnerability. (CVE-2026-53359).
Hi Team :) This is mostly for VMs but also applicable to containers.
So a lot of actions require a restart in cycle, and some things of course needs an OS reboot to go into affect, like changing CPU, MEM and other hardware options.
But quite a few do not, like expanding an external disk or updating a server deployment tag. and it would be nice to avoid having to schedule maintenance windows for updating simple things, or simply a warning that changes will happen on next reboot would also be good, so my request is to only restart/warn when changing something that requires it, and this avoids the hard restart as well for a lot of things.
I understand this is a bigger ask, and I do not know the implication under the hood, as well as adding both UI and determining if a features requires it, but I think it could provide a lot of value especially to VMs that often do not run something in HA mode, but can't be restarted on a whim like a database.
Hi everyone,
I've just released a Typescript/Javascript API for accessing the Cycle Internal API. This client makes it super easy for those already in the nodejs ecosystem to take advantage of it.
Check it out here.
and install it with:
npm install @cycleplatform/internal-api-client
Why would I want to do that?
Great question! The Internal API is a powerful little socket mounted into every container running on Cycle. It provides quick, direct access back to the platform to learn about its environment and even make changes to it.
Some of the things you can do include:
import { getClient } from "@cycleplatform/internal-api-client"; const client = getClient(); const { data, error } = await client.GET("/v1/environment/scoped-variables"); if (error) { console.error(error);} else { console.log(data);}
import { getClient } from "@cycleplatform/internal-api-client"; const client = getClient(); const { data, error } = await client.POST("/v1/monitoring/metrics", { body: [ { metric: "queue.depth", type: "gauge", labels: { queue: "ingest", region: "us-east" }, tags: ["worker"], points: [ { time: new Date().toISOString(), values: [42], }, ], }, { metric: "jobs.processed", type: "counter", points: [ { time: new Date().toISOString(), values: [128], }, ], }, ],}); if (error) { console.error(error);} else { console.log(data);}
config.runtime.host.power_management
import { getClient } from "@cycleplatform/internal-api-client"; const client = getClient(); const { data, error } = await client.POST("/v1/server/power/reboot"); if (error) { console.error(error);} else { console.log(data);}
Thanks!
As part of our new branding and design, we've rolled out a new version of the Cycle community. In addition to the new design, we've made several improvements both behind the scenes and for our users.
We plan on expanding on the community to make it the go-to place for Cycle users to ask questions, share knowledge, and find like-minded developers and devops engineers to network with. We expect to add new features constantly. If you have any ideas, please use the community to suggest them!
Looking forward to seeing you all here.
Hey folks, We use SFTP connections in our deployments and initially had SFTP enabled on all our servers but run into problems when the server goes into protection / lockdown mode due to bot activity on the port. We can enable and disable sftp by reconfiguring the servers in our deploy steps, but ultimately it would be neat if we could leave SFTP on and just not allow any traffic to the port unless they're on the allowlist. IPs seems like one way to do it, though developers often want to use SFTP to move files around themselves for hotfixes or development, and developer IPs change and so we'd need to go in and add our IP manually on any servers we need into relatively regularly.
Currently our nodes have a couple of IPs attached (not floating) to each, then when spinning up a new environment and assigning a load balancer (ha or not) it will fail as it does not check if that node has enough available IPs.
Load Balancer should check before starting instances if there are enough free IPs on that servers pool.
We have fixed IPs per server, and should a LoadBalancer be shuffled around, the IP will also change. This would mean the hardcoded IPs in the VPN configuration now are invalid.
Ability to add a hostname and let the cycle LBs figure out how to route traffic to the VPN server using the Hosted Zones records.
Considering suggestion in my prev request is to open multiple tabs in browser, this is hard to look for both, when both tabs reserving space for left part of dashboard. It would be nice to have button "hide" or "shrink" the configuration pane
I'd like to have an ability to use ssh from my own laptop, sending bash commands. But currently there is only possible to connect to the machine and execute withing attached terminal
I'd like to see logs in descending order, there is no order selection for logs in containers.
Also - scroller is not responsive, you can drug browser scroll all the way down, then it's stuck, and you have to scroll by mouse wheel. At least that how it works in firefox
We run basic, anonymous analytics by default to measure site traffic. By clicking "Accept," you allow additional cookies for advanced app improvements and tailored advertising. Choose what you share by clicking "Customize."