> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tofunmiadewuyi.com/custos/llms.txt
> Use this file to discover all available pages before exploring further.

# Remove Custos from a host

> Uninstall custosd, purge local state, and revoke the host.

Use the built-in uninstaller first.

```bash theme={null}
sudo /usr/local/bin/custosd uninstall
```

`uninstall` notifies the control plane using the host's daemon identity, marks the host revoked,
stops the systemd service, removes the sshd hook, and removes the installed binary.

Add `--purge` to also remove the local daemon state and the `custos` system user:

```bash theme={null}
sudo /usr/local/bin/custosd uninstall --purge
```

If the control plane is unreachable, skip the decommission request and revoke the host manually from
the control plane afterwards:

```bash theme={null}
sudo /usr/local/bin/custosd uninstall --purge --skip-control-plane
```

<Warning>
  Only use `--skip-control-plane` when you intend to revoke the host by hand. Until it is revoked, the
  control plane still counts that machine as having an active host, and the machine cannot re-enroll.
</Warning>

## What the uninstaller removes

* `/etc/ssh/sshd_config.d/70-custos.conf`
* `/etc/systemd/system/custosd.service`
* `/usr/local/bin/custosd`
* `/usr/local/bin/custosd.prev`
* `/var/lib/custos` — only with `--purge`
* the `custos` system user — only with `--purge`

## Verifying by hand

To check for and remove any remaining local traces:

```bash theme={null}
sudo systemctl disable --now custosd 2>/dev/null || true
sudo rm -f /etc/ssh/sshd_config.d/70-custos.conf
if sudo sshd -t; then
  sudo systemctl reload ssh 2>/dev/null || sudo systemctl reload sshd
fi
sudo rm -f /etc/systemd/system/custosd.service
sudo systemctl daemon-reload
sudo rm -f /usr/local/bin/custosd /usr/local/bin/custosd.prev
sudo rm -rf /var/lib/custos /run/custos
sudo userdel custos 2>/dev/null || true
sudo groupdel custos 2>/dev/null || true
```

If app service users were added to the `custos` group for `custosd exec`, remove that membership
before deleting the group:

```bash theme={null}
getent group custos
sudo gpasswd -d <app-service-user> custos
```

## What is left behind

System logs and shell history are outside the daemon's state. To remove those too, delete the
relevant shell history entries and rotate or vacuum systemd journals according to your host's
logging policy.

<Warning>
  Be careful with `journalctl --vacuum-*`: it affects the whole system journal, not only Custos
  entries.
</Warning>

Audit records on the control plane are deliberately retained. A revoked host keeps its history.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.