Hosting
Cloud Foundry
Open-source application platform for deploying and operating code across private and public infrastructure.
What it is
Cloud Foundry is an Apache-licensed, openly governed application-platform ecosystem. Developers push supported application code through the cf CLI and platform API; operators provide routing, buildpacks, container scheduling, identity, logs, quotas and service integrations. The software has no license fee, but a production foundation still requires infrastructure, load balancers, DNS/TLS, databases, blob stores, monitoring, backups, updates and skilled operations—or a separately priced commercial distribution or managed provider. Certification verifies required core components for a specific program year; it is not the same as generic API compatibility or an uptime guarantee.
Key features
cf push workflow
Stages supported source or artifacts with buildpacks and schedules application instances.
Organizations and spaces
Scopes applications, routes, services, quotas and role-based access for multiple teams.
Service broker model
Provisions and binds managed services through the Open Service Broker API.
UAA identity
Provides OAuth-based platform identity with configurable LDAP and SAML federation.
Strengths and trade-offs
What works well
- Developer abstraction: A consistent cf push workflow hides much of the infrastructure configuration from application teams.
- Open governance and source: Foundation projects use open contribution, design and governance processes.
- Infrastructure choice: Cloud Foundry can be deployed on multiple IaaS environments or consumed through commercial offerings.
- Platform controls: UAA identity, RBAC, orgs, spaces, quotas, routing, logs and service brokers provide multi-team governance.
Where it falls short
- Free software has real operating cost: Production topology, infrastructure, upgrades, security and recovery need a platform team.
- Provider experience varies: Buildpacks, services, extensions, support, certification and pricing differ among distributions.
- State remains external: Databases and bound services need their own durability, credential and restore strategy.
- Not general compute: The opinionated application model is a poor fit for workloads needing unrestricted hosts or unusual system dependencies.
Who it is for
Enterprises and public-sector platform teams that want a standardized developer PaaS and can operate it or select a supported provider.
Our verdict
Cloud Foundry remains a capable open application-platform abstraction, but its business case depends on portfolio scale; price the whole foundation and operators, validate the chosen distribution, and restore-test platform state plus every external service before standardizing on cf push.
Closest alternatives we track
Same category, ordered by verified starting price.
What we checked
- Public APIOffers a documented API you can build against.Yes
- Mobile appHas a native app for iOS or Android, not just a mobile website.No
- Open source / self-hostableSource is open and the tool can be run on your own infrastructure.Yes
- SSO (SAML)Supports SAML single sign-on on at least one plan.Yes
“Not checked” means exactly that — we have not verified it, and we do not guess.
Evidence and freshness
Status: Official sources reviewedReviewed: 2026-08-24
- Cloud Foundry — Project home ↗
Checked 2026-08-24 · Supports: open-source application platform, cf push workflow, supported language examples, community project quality control, infrastructure-flexibility positioning
- Cloud Foundry — Governance ↗
Checked 2026-08-24 · Supports: open license design development and contribution model, open governance, Foundation role, Governing Board and Technical Oversight Committee responsibilities
- Cloud Foundry Docs — Documentation index ↗
Checked 2026-08-24 · Supports: PaaS definition, deployment and administration scope, BOSH backup and restore, API CLI buildpacks routing logging services and UAA, operator responsibility breadth
- Cloud Foundry Docs — Concepts ↗
Checked 2026-08-24 · Supports: open-source app platform, private distribution and public-instance models, cloud framework and service choice, application deployment and scaling scope
- Cloud Foundry Docs — Security ↗
Checked 2026-08-24 · Supports: UAA OAuth identity, RBAC, LDAP and SAML federation, container isolation, release and stemcell patching, encrypted configuration, operator hardening recommendations
- Cloud Foundry — Provider FAQ ↗
Checked 2026-08-24 · Supports: Apache 2 licensing, annual certification, required core components, formal verification distinction, provider extensions, certification not equal to all-source inclusion, delivery-model variety
Limit: Official Cloud Foundry Foundation and documentation sources were reviewed; ToolCompare did not deploy a foundation, select or purchase a distribution, calculate infrastructure or staffing cost, test cf push/APIs/UAA/SAML/buildpacks/service brokers, inspect a current certification submission, patch stemcells, induce component failures, benchmark applications, or restore BOSH and external-service state. Provider features, certification and lifecycle support vary.