Coming November 2026 · Vagrant box registry · your Cloudflare account

HCP Vagrant shuts down on 31 December. Keep vagrant box add org/name working

Since 1 October 2026 HCP Vagrant accepts no new boxes, and existing ones stop on 31 December 2026 (HashiCorp’s notice). BoxHarbor moves your organization’s boxes to a registry in your own Cloudflare account, with the same names, versions and private access.

How it works

  1. Deploy the registry to your Cloudflare account with one command. It is a small Worker in front of an R2 bucket that you own.
  2. Run the migrator against your organization. It copies every box, version, provider and architecture from HCP Vagrant, checks each checksum, and can be restarted where it stopped.
  3. Set VAGRANT_SERVER_URL on your machines and CI. Your Vagrantfiles keep saying config.vm.box = "acme/base", and private boxes keep working with a token.

Try it now

A demo registry runs at boxes.factodus.com. With Vagrant 2.4 installed:

VAGRANT_SERVER_URL=https://boxes.factodus.com vagrant box add demo/tiny

The demo box holds only metadata, no disk image, so it downloads in a second and does not boot.

What it covers

vagrant box add org/name, versions, constraints, box updateYes, unchanged Vagrant 2.4
Private boxes with a tokenYes
Public boxes without a tokenYes, per organization
Multiple providers and architectures (amd64, arm64)Yes
Boxes of several GBYes, uploaded in parts
Upload new versions from CI or PackerYes, one command (Packer through shell-local)
StorageYour R2 bucket: about $0.015 per GB a month, no download fees

Price

$49 once per organization, no subscription. Storage is billed by Cloudflare to your account.

Waitlist members can reserve a founding price: $29.

Get BoxHarbor when it is ready

Questions

Does my team have to change Vagrantfiles?

No. Vagrant looks up org/name on whatever server VAGRANT_SERVER_URL names, so the same box names resolve to your registry. We tested this with Vagrant 2.4.9: pinned versions, the latest version and checksums all work.

What about private boxes on HCP?

The migrator reads them with an HCP service principal (client ID and secret) or a Vagrant Cloud token, the same credentials Vagrant uses today.

Do you get a copy of my boxes?

No. The boxes go from HCP straight to the bucket in your account. We run nothing in between.

Why not just put the files on S3?

You can, with a URL in every Vagrantfile. You lose box names, versions, box update and private access. BoxHarbor keeps them.

When?

November 2026, well before HCP Vagrant stops on 31 December.

Vagrant, HCP and HashiCorp are trademarks of HashiCorp, Inc. Cloudflare and R2 are trademarks of Cloudflare, Inc. BoxHarbor is an independent product, not affiliated with or endorsed by either.