Coming November 2026 · Vagrant box registry · your Cloudflare account
HCP Vagrant shuts down on 31 December. Keep vagrant box add org/name working
Since 1 October 2026 HCP Vagrant accepts no new boxes, and existing ones stop on 31 December 2026 (HashiCorp’s notice). BoxHarbor moves your organization’s boxes to a registry in your own Cloudflare account, with the same names, versions and private access.
How it works
- Deploy the registry to your Cloudflare account with one command. It is a small Worker in front of an R2 bucket that you own.
- Run the migrator against your organization. It copies every box, version, provider and architecture from HCP Vagrant, checks each checksum, and can be restarted where it stopped.
- Set VAGRANT_SERVER_URL on your machines and CI. Your Vagrantfiles keep saying config.vm.box = "acme/base", and private boxes keep working with a token.
Try it now
A demo registry runs at boxes.factodus.com. With Vagrant 2.4 installed:
VAGRANT_SERVER_URL=https://boxes.factodus.com vagrant box add demo/tinyThe demo box holds only metadata, no disk image, so it downloads in a second and does not boot.
What it covers
| vagrant box add org/name, versions, constraints, box update | Yes, unchanged Vagrant 2.4 |
| Private boxes with a token | Yes |
| Public boxes without a token | Yes, per organization |
| Multiple providers and architectures (amd64, arm64) | Yes |
| Boxes of several GB | Yes, uploaded in parts |
| Upload new versions from CI or Packer | Yes, one command (Packer through shell-local) |
| Storage | Your R2 bucket: about $0.015 per GB a month, no download fees |
Price
$49 once per organization, no subscription. Storage is billed by Cloudflare to your account.
Waitlist members can reserve a founding price: $29.
Questions
Does my team have to change Vagrantfiles?
No. Vagrant looks up org/name on whatever server VAGRANT_SERVER_URL names, so the same box names resolve to your registry. We tested this with Vagrant 2.4.9: pinned versions, the latest version and checksums all work.
What about private boxes on HCP?
The migrator reads them with an HCP service principal (client ID and secret) or a Vagrant Cloud token, the same credentials Vagrant uses today.
Do you get a copy of my boxes?
No. The boxes go from HCP straight to the bucket in your account. We run nothing in between.
Why not just put the files on S3?
You can, with a URL in every Vagrantfile. You lose box names, versions, box update and private access. BoxHarbor keeps them.
When?
November 2026, well before HCP Vagrant stops on 31 December.
Vagrant, HCP and HashiCorp are trademarks of HashiCorp, Inc. Cloudflare and R2 are trademarks of Cloudflare, Inc. BoxHarbor is an independent product, not affiliated with or endorsed by either.