Sushi Kitchen
寿司キッチン · the counter is open

Your own AI operating system.

92 open-source rolls, composed into 26 stacks that run with one command. Pick a composition or assemble your own. We host it, or the whole kitchen runs on your hardware and nothing phones home.

$ docker compose up
Port and Starboard, the head chefs
Port & Starboard
Head chefs | est. 2026
one hosts · one ships · both read the licence
01

Sushi Kitchen is a menu of open-source infrastructure. Ninety-two services, read and pinned, composed into stacks that stand up whole.

Local Chatcombo · 2 rolls · easyHosomaki Coreplatter · 5 rollsDev Workspacecombo · 3 rolls · easyKnowledge Workerplatter · 8 rollsSecurity Corecombo · 3 rolls · intermediateOmakaseplatter · 29 rolls · the whole counterLocal Chatcombo · 2 rolls · easyHosomaki Coreplatter · 5 rollsDev Workspacecombo · 3 rolls · easyKnowledge Workerplatter · 8 rollsSecurity Corecombo · 3 rolls · intermediateOmakaseplatter · 29 rolls · the whole counter
The counter

Twelve families. Ninety-two rolls.

Family sizes run uneven by a factor of five. Drawn to scale, one square per roll, rather than as twelve equal tiles.

futomaki
data platforms
15
gunkanmaki
infrastructure
12
hosomaki
core automation
10
inari
monitoring
9
otsumami
small utilities
9
chirashi
analytics
8
temaki
developer workspaces
8
uramaki
media and creative
6
nigiri
simple tools
4
sashimi
raw building blocks
4
shoyu
backup and integrations
4
dragon
networking and edge
3
Start from what you do

You do not have to know what a roll is to start. Find the problem you actually have, and the composition is already chosen.

  • Case study

    A kitchen that can hold a privilege

    Eight containers on four networks, two of which have no route to the internet at all. The queue sits on one of those. The workers sit on the other, outbound-only, and never accept a connection from anywhere.

    7 rolls · Privacy · Legal privilege
  • For consultants and researchers

    Everything you read, searchable by meaning

    Eight rolls that turn a folder of documents into something you can ask questions of, without any of it reaching a third party.

    8 rolls · Privacy · Business-confidential
  • For studios and publishers

    A publishing pipeline that stays yours

    Six rolls for turning raw material into finished work, with the archive and the models both on hardware you control.

    6 rolls · Privacy · Business-confidential

All solutions

02

Twenty-six systems are already built. Choose one and it arrives as a compose file — docker compose up, and the stack is running on your own server. No integration work, no glue to write.

Tonight's menu

Ready to serve.

Port and Starboard behind the counter
Behind the counter
Service No. 1 | every night
the compositions are cut to order
Combos · two to four rolls
Local Chat2 rolls
Ollama and Open WebUI — chat with local models.
Knowledge RAG3 rolls
AnythingLLM, reading your own documents.
Flow Builder2 rolls
Flowise — drag-and-drop agents, no code.
Dev Workspace3 rolls
VS Code Server, running in the browser.
Basic Monitoring3 rolls
Prometheus and Grafana across the stack.
Security Core3 rolls
Authentik for sign-on, secrets under management.
Platters · five to twenty-nine
Hosomaki Core5 rolls
The minimal foundation, for learning the shape.
Knowledge Worker8 rolls
Document analysis without enterprise complexity.
AI Agent Foundation5 rolls
Everything needed to build agents, no cloud.
Content Creation Studio5 rolls
Video, audio and images processed at scale.
Enterprise Starter12 rolls
Compliance and security, production-ready.
Omakase29 rolls
Every service on the menu, all at once.
One composition, drawn

Knowledge Worker, to scale.

Eight rolls, 11.8 GB of memory between them. Each block's area is its share of the total — a stack is never eight equal parts.

Qdrant
futomaki · 4 GB · 34%
AnythingLLM
hosomaki · 2 GB · 17%
Prometheus
inari · 2 GB · 17%
MinIO
futomaki · 1 GB
LiteLLM
hosomaki · 1 GB
Grafana
inari · 1 GB
cAdvisor
512 MB
Caddy
256 MB
Knowledge Worker
Platter | 8 rolls | 11.8 GB
block area ∝ memory · dot = family
03

Or start from nothing. Add the services you want and the Builder resolves what they need, one click at a time, then hands you the same compose file.

How it works

Four courses, one kitchen.

Omakase: you choose how far to go, and the kitchen handles the order of things.

01

Pick a composition

Combos that solve one problem, platters that stand up a whole scenario — each lists its rolls, its hardware, and its licence.

26 on the menu
02

Resolve requirements

Add a roll and what it needs resolves in one click. The Builder never hides a closed door.

one click
03

Hosted or self-host

A URL, credentials and a named privacy profile — or a bento box that never leaves your network.

your call
04

A running kitchen

Models, interfaces, storage, monitoring — the stack comes up as one unit, and stays yours.

one command
$ docker compose up
✓ 5 rolls up · 8 GB RAM
itadakimasu — your kitchen is running.
04

Every roll is read before it ships: its licence at the version you actually run, its configuration, its hardware floor, and which services it genuinely works with.

That analysis is the product. It is what turns ninety-two separate open-source projects into something you can implement this afternoon.

92
licences read
65
capabilities mapped
46
defaults chosen
3
privacy profiles
In practice

A kitchen that can hold a privilege.

A law practice in Harrison, New York runs its whole AI stack on its own hardware. Client documents are searchable, calls are transcribed, and the file room answers questions — with the network egress closed. Nothing goes out.

It was built by the attorney who read the ninety-two licences. That is the shortest honest answer to whether any of this actually works: it is already load-bearing for someone whose bar licence depends on it.

Simplicity

Building it is a manifest and one command.

A composition is a plain file: the rolls you chose, the versions they are pinned to, the profile they run under. Edit a line and run it again. Nothing to migrate and nothing to unpick — the operating system your business runs on stays private, open source, and configurable down to the port.

Open source, end to end

92 services, each licence read at the version you actually run.

Configurable, not bespoke

Swap a roll or change a profile and the rest of the stack stays intact.

Minutes, not quarters

From picking a composition to a running kitchen in one sitting.

The menu

Twenty-six compositions.

Seen end-on, the way a roll is cut — every family sized by the rolls it holds.

The catalog, end-on
Twelve families | 92 rolls
arc length ∝ roll count
The Port and Starboard stalls
Two doors, one menu
Port and Starboard | the same 92 rolls
Hosted or self-host

Pick your side of the counter.

Port
Portwe host it

A URL, credentials and a named privacy profile. Nothing to provision, nothing to patch.

Starboard
Starboardyou host it

A sealed bento box on your own hardware. No telemetry, no per-seat meter, nothing leaving the network.

83 of 92 rolls are open both ways, so the choice waits until you make it.

Port and Starboard serving the counter
Service
The counter, running | est. 2026
self-hosted · nothing phones home
Why own it

Build your own AI operating system in your own private sushi kitchen.

Private by architecture
The self-host path sends nothing out: no telemetry, no per-seat meter, no keys leaving your network.
92 pinned services
Every roll pinned to a version, and its licence read at that version rather than recalled from memory.
Composable, checkable
Rolls declare what they provide and what they need, so a build verifies before it ships.
One command
The bento box is a sealed artifact — versioned, re-downloadable, and happy offline.