1. Install the daemon
The installer is the normal path. It resolves the latest release, downloads the right Linux/architecture tarball, installs/usr/local/bin/custosd, creates the custos system user,
creates /var/lib/custos, writes the systemd unit, and wires sshd’s AuthorizedKeysCommand.
Self-hosted release artifacts
For a private source repo, publish only the daemon release artifacts to a public static base and point both the installer and the control plane at it:latest.txt plus versioned files such as
v1.2.3/custosd_v1.2.3_linux_amd64.tar.gz and v1.2.3/custosd_v1.2.3_checksums.txt. The daemon
release workflow bakes this base into dist/install.sh when the CUSTOS_RELEASE_BASE Actions
variable is set.
Manual binary download
Downloading the binary alone is for manual testing and debugging. It is enough to runenroll, but
it configures neither sshd nor systemd.
custosd binary on the host, run the installer step from it directly:
sshd refuses an
AuthorizedKeysCommand unless the binary and every parent directory are root-owned
and not group- or world-writable. That is why the binary must live in /usr/local/bin and not, say,
~/bin. The installer handles this; a hand-rolled layout has to respect it.2. Create an enrollment token
As an admin, on the control plane, create a token carrying the Unix accounts this host will manage:token. It is single-use, consumed in the same transaction that creates the host.
The accounts you declare here are copied to the host on enroll and stamped into every snapshot it
receives.
3. Enroll
/etc/machine-id. A second enroll
from the same machine is rejected with 409 until the existing host is revoked.
4. Start
/etc/ssh/sshd_config.d/70-custos.conf and never edits the main sshd
config.
Next
- Grant SSH access to make the host usable.
- Machine secrets to deliver app secrets to it.