Control plane
Spaces
Isolated, persistent sandboxes that run your application and its tools.
What is a space?
A space is a full application sandbox. It runs in its own Firecracker microVM, has persistent storage, and is published at a unique hostname. Fork keeps the runtime isolated from other spaces while the control plane handles identity, routing, authorization, and metered services.
The public application is always the top-level page. Fork adds the Agent launcher for people who are allowed to control the space; visitors continue to see the application itself.
Space lifecycle
- Create: clone a template, import a ZIP, or start from scratch.
- Build: use the Fork Agent or a connected local agent inside
/workspace. - Run: Fork routes the public hostname to the application and keeps its data volume.
- Recover: inspect automatic checkpoints or restore a selected snapshot.
- Delete: removal also purges workspace-scoped encrypted secret bindings.
Addresses and domains
Every ready space has a canonical Fork hostname. Organization administrators and space owners can also attach custom domains; Fork verifies DNS ownership and provisions TLS. See Custom domains.