Orchestration · the engine under the rest

Built once.
Cloned, not rebuilt.

Every automation agency hits the same wall: the second client wants the same thing as the first, slightly different, and it gets rebuilt from scratch. That is the wall.

Our own orchestration layer, on our own server. Every other system on this site runs on top of it.

Built once, cloned per client One template of six workflows fans out to three clients. Each clone carries the same workflows and differs only in one configuration node, so a fix written once lands everywhere. BUILT ONCEThe templatesix workflows, one config nodeClinic AClient ConfigClinic BClient ConfigClinic CClient ConfigONE NODE DIFFERS — NOTHING ELSEA fix written once lands everywhere
Identical workflows. One node differs. That is the whole trick.

Every figure here is a build fact — counted, not claimed. No outcome numbers appear on this site until a client’s system produces one.

  • 6workflows, built once
  • 1node edited per client
  • ~$6/moorchestration, every client combined
  • ~15 hrsa build, because it is configuration
  • $40/morunning-cost ceiling, per client
  • 3open ports · 22 · 80 · 443
  • 1command to bring up a fresh box
  • 8–10clients on one box before it moves

Custom work does not scale, and everyone finds out the same way. The first build is interesting, the fourth is the first one again with different names, and by the sixth nobody remembers which client got the fix. Scoping each one fresh is how a fifteen-hour build turns into a month.

So the workflows are deliberately boring and deliberately identical. A fix written once lands everywhere it should, because there is only one place it can be written. That is what makes a build fifteen hours rather than a month, and it is the only reason the price can be fixed in advance rather than estimated.

How it works

One small server, one reverse proxy, one automation runtime, and nothing else exposed.

  1. 01

    A single small VPS all clients

    One box runs every client’s automations, which is why the whole orchestration line is about six dollars a month rather than six dollars per client. Brought up from one bootstrap script on a fresh machine, and the script is safe to run twice.

  2. 02

    Three open ports 22 · 80 · 443

    The firewall opens those and nothing else. The automation runtime’s own port is never published to the host — the proxy reaches it across a private network. Adding a port mapping “to test something” is how a private instance becomes a public one.

  3. 03

    Automatic HTTPS certificates renew themselves

    The proxy obtains and renews the certificate. The bootstrap refuses to continue if DNS does not already resolve to the box, because a certificate cannot be issued before it does — that single check is the most common reason a first deploy looks broken.

  4. 04

    One config node per client

    The workflows are identical across clients. The only thing that differs is one node carrying the numbers, hours, calendar and name. Cloning a client is editing that node, running the test checklist, and activating.

  5. 05

    The encryption key backed up off the box

    It encrypts every stored credential. Lose it and every connection has to be re-entered by hand. The bootstrap prints it once, deliberately never regenerates an existing one, and the day it is printed is the day it gets backed up somewhere else.

Single mode, and when that stops being true

One process, one file-backed database, no queue. Correct while the workflows are event-driven and light. The day executions start queueing behind each other, it moves — deliberately, between clients, never mid-onboarding.

The box, from the outside in Only ports 22, 80 and 443 are open. Traffic reaches a reverse proxy that handles TLS, which forwards over a private network to the automation runtime, whose own port is never published. Behind it, a single-mode file-backed database. A refusal marks the point at which queue mode becomes necessary. ONE SMALL VPS, ALL CLIENTSPorts 22 · 80 · 443nothing else is openReverse proxyautomatic TLS, renews itselfThe runtime, private networkits own port is never publishedSingle modeone process, event-driven, lightQUEUE MODE ONLY WHEN EXECUTIONS QUEUEAround eight to ten clients on this box,then a real database — deliberately,between clients, never mid-onboarding.
Nothing but the proxy is public. That is not a setting; it is the topology.

What you get

~$6/mo

Orchestration, shared

One box for every client. This is the line that stays flat as clients are added, and it is the whole argument for self-hosting rather than paying per execution.

Per client

Number, messages, AI

The phone number is about a dollar a month plus usage; the AI calls are five to twenty dollars a month depending on volume. These are the only lines that grow with each client.

$40/mo

The ceiling, per client

Above it we stop and re-architect rather than quietly absorbing the difference. A running cost that creeps is a retainer that stops being margin without anyone deciding that it should.

Every account is opened in the client’s name. If they leave, the system keeps running without us — that is the point of not building it on something only we can log into.

Want this one walked through against your own numbers? Email info@adapton.io and we will show you the parts that transfer and the parts that do not.

The limits

This is the layer everything else stands on, so the honest parts matter more here than anywhere.

  • The workflows were authored offline and validated for structure and error wiring — not against live node schemas. First import means opening each one and fixing anything the runtime flags. Budget an hour, once, not per client.
  • We do not go live on an untested path. A workflow that has never been run is a file, not a product.
  • A credential is never pasted into a workflow field. A token referenced by expression is a leak with extra steps.
  • The image version is pinned rather than tracking the latest build, because an unattended major upgrade can change node behaviour under a live phone line.
  • One box has a ceiling. Somewhere around eight to ten clients it needs a real queue and a real database, and that migration happens on purpose rather than under pressure.
The running-cost ceiling Orchestration is about six dollars a month shared across every client. Per client, a phone number is about a dollar a month plus usage and AI calls are five to twenty dollars. A refusal line marks forty dollars per client per month, above which the system is re-architected rather than absorbed. PER CLIENT, PER MONTHOrchestration~$6/mo, shared across every clientPhone number$1.15/mo plus usageAI calls$5–20/mo, by volume$40/month is the ceilingABOVE IT WE STOP AND RE-ARCHITECTA cost that creeps is margin leaving quietly.
Above the line we stop and re-architect. It is a number, not a preference.

Next step

Fifteen minutes. We ask three questions and do the arithmetic with your real numbers. If it is not worth automating we will say so on the call.

Send us the details

All case studies · info@adapton.io