> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tofunmiadewuyi.com/custos/llms.txt
> Use this file to discover all available pages before exploring further.

# Install the control plane

> Install custoscp, generate keys, migrate the database, and seed the first admin.

## Download

```bash theme={null}
VERSION="$(curl -fsSL https://custosd.tofunmiadewuyi.com/releases/custoscp/latest.txt)"
curl -fL -o custoscp.tar.gz "https://custosd.tofunmiadewuyi.com/releases/custoscp/${VERSION}/custos_${VERSION}_linux_amd64.tar.gz"
tar -xzf custoscp.tar.gz
sudo install -m 0755 ./custos /usr/local/bin/custoscp
```

For an ARM64 server, replace `amd64` with `arm64`. Use `latest.txt` rather than hard-coding a
version; it contains the current version string, and the tarball path includes that version.

## Generate keys

```bash theme={null}
custoscp gen-keys
```

Prints an env-format bundle:

| Variable | Used by |
| - | - |
| `CUSTOS_MASTER_KEY` | wrapping per-secret data keys at rest |
| `CUSTOS_SIGNING_PRIVATE_KEY` | signing snapshots and secret-set bundles |
| `CUSTOS_SERVER_TRANSPORT_PRIVATE_KEY` | the hybrid API payload encryption |
| `CUSTOS_SERVER_TRANSPORT_PUBLIC_KEY` | configured on clients — not read by the control plane |

<Warning>
  Treat the bundle as the crown jewels and keep it off terminal scrollback and shell history. Redirect
  it straight to a root-only file: `custoscp gen-keys > /root/custos-keys && chmod 600 /root/custos-keys`.
  Losing `CUSTOS_MASTER_KEY` means losing every stored secret.
</Warning>

## Configure

The control plane reads everything from process environment variables and does **not** load `.env`
files itself. Supply them through your shell, service manager, or deployment platform. Minimum:

* `CUSTOS_DATABASE_URL`
* `CUSTOS_LISTEN_ADDR`
* `CUSTOS_MASTER_KEY`, `CUSTOS_SIGNING_PRIVATE_KEY`, `CUSTOS_SERVER_TRANSPORT_PRIVATE_KEY`

Full annotated list in [Configuration](/custos/custos/control-plane/configuration).

## Migrate and seed

```bash theme={null}
custoscp migrate up
custoscp create-admin --email you@example.com
```

`migrate up` creates the schema and is required before `create-admin`. `create-admin` prints a
generated password unless you pass `--password`. Both accept `--database-url` if you would rather not
set `CUSTOS_DATABASE_URL` in the environment.

Migrations are embedded in the binary, so the binary and its schema always ship together.

## Run

```bash theme={null}
custoscp serve
```

For a production deployment, run it under systemd with secrets in the encrypted credential store —
see [Running under systemd](/custos/custos/control-plane/systemd).

## Health endpoints

| Path | Meaning |
| - | - |
| `GET /livez` | process liveness |
| `GET /readyz` | readiness; returns `503` when Postgres is unreachable |
| `GET /healthz` | alias for readiness, kept for existing deployments |

Point your load balancer at `/readyz` and your process supervisor at `/livez`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.