tcp-reachable

Is the database up?

Opens a real connection to the host and port your app will use. Not a ping — a connection.

http-ok

Does it actually serve?

Requests the health endpoint and requires a 2xx. A 503 is a failure, not a warning.

env-present

Is the environment complete?

Names every missing key. Presence only — Muster never reads or stores what a secret contains.

migration-at-head

Are migrations applied?

Runs the status command, never the migrate command. A check that mutates your database is not a check.

command-exit-zero

Your own precondition.

Any command you name has to exit 0. The escape hatch for the thing only you know.

resource-exists

Is it really provisioned?

Asks the OpenTofu state, not the cloud console — state is what the apply actually wrote.

disk-persistent

Will the data survive?

Compares the device behind your data path against the root disk. Invisible until the instance is replaced.

backup-configured

Has the backup ever restored?

The timer being enabled is not the bar. Muster runs the restore and requires it to verify.

Your deploy said it worked.
Your customer says otherwise.

muster verify — acme-storefront on ubuntu@203.0.113.10
postgres127.0.0.1:5433 accepted a connection
postgres-persistenton /dev/nvme1n1, mounted at /mnt/data
postgres-backuprestore verified: 24 tables
migrationsat head
env-completeSESSION_SECRET is missing — the app boots and quietly does nothing
healthwaiting — blocked upstream

Blocked at env-complete. Traffic was not cut over.

The file it named, already open.

The gate said which key was missing. The workspace opens on the file that declares it — editor, terminal and your own coding agent, against the machine the check just ran on.

Re-run6 of 6 gates satisfiedcutover · clear

One gate. Two mornings.

Without the gate
  • 502 Bad Gateway
  • 502 Bad Gateway
  • Session store unreachable
  • Everyone signed in, signed out
  • Rollback started once someone noticed
With the gate
  • Cutover refused at the gate
  • Previous version still serving
  • No request reached the broken build
  • One missing key to fix
  • Deploy retried, green, on the next run

Almost nothing breaks because the code was wrong. It breaks because a key was missing, the database was not up, migrations had not run, or the disk holding your data dies with the instance.

Muster reads your app, works out the infrastructure it needs, and verifies every one of those preconditions on the machine itself before traffic is cut over. What it could not verify comes back as not verified — named, with the reason. It is never counted as a pass.

Reads your appChecks your serverBlocks the deploy

No card required. Read-only — it observes your server, it never changes it.

It runs your preconditions in order.

Each answer decides whether the next question is even asked. The database has to be reachable before migrations are worth checking; migrations have to be at head before health means anything.

Then it refuses.

Not by convention, and not with a warning someone can merge past. The cutover is downstream of the gate, so a failed check physically cannot reach it.

0
customers served the broken build
6
gates that all had to hold

Three things, in order

The order is the point. Each answer decides whether the next question is even asked.

01

It reads your app

Point Muster at the code. It works out the services, databases, queues, environment keys and migrations — and tells you every single thing it had to guess, so nothing is decided behind your back.

02

It checks your server

On the machine itself — through the agent you install, or over SSH. Is the database reachable? Are migrations applied? Is the data on a disk that survives the instance? Has the backup ever been restored?

03

It blocks the deploy

Each answer gates the next. Nothing reaches your customers until every precondition holds — not by convention, but because the check physically cannot get there.

Your cloud. Your code. Your keys.

Muster runs against your account, not ours. It never stores a cloud key, an SSH key, or the value of any secret — it verifies that your environment variables are present, never what they contain. The infrastructure code it writes is yours: plain OpenTofu you can read, keep, and take with you if you stop paying us.

Then it stays.

The agent runs on your server, not on ours. It asks us for work rather than waiting to be asked, so there is no inbound port to open and no key of yours for us to hold. Every check runs on the machine your app runs on.

  • Nothing listensIt polls out over HTTPS. No firewall rule, no public port, no route in.
  • Nothing of yours is storedIt verifies that a variable is present. It never reads what is in it.
  • It reports what it seesProcess names, ports and status - so a check asks after the service your server actually runs, not the one a repository guessed at.

Priced per environment. Never per check.

Run every check your app needs. How many there are is never the price — the number of preconditions is a fact about your architecture, not about what you owe us. What you pay for is how much Muster watches, and how long it keeps the record.

Free

Free

One app on one server. Every gate, run as often as you like.

1 app · 7 days of history

  • ✓Every readiness gate Muster has, none held back
  • ✓Unlimited checks — the number of them is never the price
  • ✓Names what it could not verify instead of assuming it passed
  • ✓Monthly cost estimate for the infrastructure it infers
  • ✓7 days of check history
Start free

Starter

$29/mo

For a team running a handful of services in one environment.

5 apps · 30 days of history

  • ✓Everything in Free, across five apps
  • ✓Re-walked continuously, not only when you deploy
  • ✓Alerted when a gate changes state, not once per run
  • ✓30 days of check history
Choose Starter

Team

$129/mo

For more than one environment, and for keeping the record of what happened.

unlimited apps · history kept for good

  • ✓Everything in Starter, on as many apps as you run
  • ✓History kept for the life of the account
  • ·Staging and production as separate environmentssoon
  • ·A blocked cutover summarised by email the day it firessoon
  • ·Policy rules: gates you require before any app may cut oversoon
  • ·Slack routingsoon
  • ·Per-client groupingsoon
Choose Team

Governance

$349/mo

For the change-management evidence an auditor asks for. Being built — talk to us first.

unlimited apps · history kept for good

  • ✓Everything in Team
  • ·SSOsoon
  • ·Audit-log retentionsoon
  • ·An exportable change-management evidence packsoon
  • ·Signed records of what was verified, and whensoon
Talk to us

Every price is on this page. The free tier takes no card, does not expire, and holds back none of the gates. Anything marked soon is work we have not finished — it is on the card so you can see where a tier is going, and it is not part of what you would be paying for today.

Find out before your customer does.

Watch your first app free