Skip to main content

Two binaries

  • custoscp — the control plane: an HTTP API backed by Postgres. Source of truth for users, hosts, keys, grants, and secrets.
  • custosd — a per-host daemon. It hooks sshd’s AuthorizedKeysCommand so every SSH login is gated by Custos, and it holds a long-lived WebSocket to the control plane, dialing out, so hosts need no inbound ports. It receives authorized-key snapshots and sealed secret sets, and serves those secrets to local apps.
Alongside those is a web app, shipped as a container image on GHCR and pointed at your control plane. It is where day-to-day work happens — managing credentials and sets, issuing enrollment tokens, granting and revoking access, reading audit trails. Everything it does goes through the same HTTP API documented here, so anything in the web app can also be scripted.The image carries no installation-specific values: it writes its runtime configuration at container start, so the same tag serves every deployment. See Deploy the web app.