Skip to main content
Use the built-in uninstaller first.
uninstall notifies the control plane using the host’s daemon identity, marks the host revoked, stops the systemd service, removes the sshd hook, and removes the installed binary. Add --purge to also remove the local daemon state and the custos system user:
If the control plane is unreachable, skip the decommission request and revoke the host manually from the control plane afterwards:
Only use --skip-control-plane when you intend to revoke the host by hand. Until it is revoked, the control plane still counts that machine as having an active host, and the machine cannot re-enroll.

What the uninstaller removes

  • /etc/ssh/sshd_config.d/70-custos.conf
  • /etc/systemd/system/custosd.service
  • /usr/local/bin/custosd
  • /usr/local/bin/custosd.prev
  • /var/lib/custos — only with --purge
  • the custos system user — only with --purge

Verifying by hand

To check for and remove any remaining local traces:
If app service users were added to the custos group for custosd exec, remove that membership before deleting the group:

What is left behind

System logs and shell history are outside the daemon’s state. To remove those too, delete the relevant shell history entries and rotate or vacuum systemd journals according to your host’s logging policy.
Be careful with journalctl --vacuum-*: it affects the whole system journal, not only Custos entries.
Audit records on the control plane are deliberately retained. A revoked host keeps its history.