Four processes and a blob store.
Two processes run in the control plane, one runs on every host, and one runs inside every VM. Postgres, a blob store, and an OCI registry are the only services around them.
The orchestrator
The product surface and the only thing a person talks to. It owns sign-in and API keys, tasks and profiles, org secrets, the Slack, Linear, GitHub, and Google Cloud integrations, pull request review, automations, and the API the dashboard and CLI call. It is the deployment's login wall: the coordinator has no public address.
The coordinator
A stateless service in front of Postgres. It schedules sessions onto hosts, preferring the one that already holds a session's snapshot, evicts idle sessions, runs the pipeline that turns a pushed image into a base snapshot, stores and fans out every session event, and garbage-collects chunks nobody references. Run as many replicas as you like.
The host agent
One per machine that runs VMs. It dials the coordinator, registers its capacity, and runs the VMs; it owns the chunk cache on local NVMe, the NBD daemon that serves chunked disks, the page-fault handler that pages VM memory in lazily, and the egress proxy every VM's traffic goes through. Hosts never need an inbound port.
The in-guest daemon
The first process after init inside every VM. It starts the harness, runs commands, moves files, and opens shells. It is not in your image: the host stages it in a bundle and the init shim copies it in at boot.
Storage is what makes the rest cheap.
Disk and memory state live as immutable chunks named by the hash of their content, with versioned manifests pointing at them. An image's base snapshot is written once and shared by every session of that image; a session's manifest gains entries only for the chunks it wrote. That gives three levels of copy-on-write for free: on disk, in memory through the hardware's memory management unit, and on fork, which is a manifest copy of a few kilobytes.
A VM reads its disk through an NBD device served from its manifest and pages memory in lazily from chunks, with the chunks a session touched in its first seconds prefaulted before the CPUs start. A snapshot writes only the delta and destroys the VM. Restoring on a different host fetches the delta.