A ctlplne studio product Alpha · trstctl is pre-1.0 and in active development. What that means →
Non-human identity lifecycle platform · self-hosted air-gap ready alpha

TLS certificates are going to 47 days. Every machine credential is now a renewal problem.

trstctl runs the lifecycle for all of them, self-hosted, with private keys sealed in an isolated signer. For platform and security teams with more certificates than people, for MSPs that hold their customers’, and for estates with no path to the internet: defense, critical infrastructure, sovereign and regulated networks, OT.

The full console in your browser: sample data, no signup, no backend.

Bots out-request humans
automated clients began 2025 sending half of all requests for web pages through Cloudflare, seven points more than people, and every one of them holds a credential · Cloudflare Radar
Keys isolated
private keys never join the control plane
Self-hosted
no cloud control plane, no phone-home license
TLS certificatesCA/Browser Forum SC-081v3 · maximum validity
  1. 398 daysuntil Mar 2026
  2. 200 daysfrom Mar 2026
  3. 100 daysfrom Mar 2027
  4. 47 daysfrom Mar 20298.5× the renewals
100-day certificates in
—days
—hrs
—min
—sec

What 47 days changes →

  • X.509 certificatesIssuance, inventory, renewal, revocation, CRL and CT.
  • SSH certificatesHost and user trust, rollout, drift against policy.
  • SecretsVersioned store, dynamic sources, delivery, leak scanning.
  • API keys & tokensOwnership, rotation state, audit trail, blast radius.
  • SPIFFE workload identitiesAttested SVIDs and ephemeral credentials for machines.
  • Code-signing keysSigning, provenance and the health of the key behind it.
  • AI & MCP agents newestShort-lived, policy-gated identities for the agents that call your APIs and sign their requests, issued through the same broker as every other machine.
Where the deadline actually lands

Your edge provider renews your public certificates for you. Nobody renews the rest.

A CDN keeps the public edge on short lifetimes automatically. Behind it sit origin certificates, internal services, mTLS clients, SSH trust, secrets, tokens, workload identities and now agents, on the same short-lived trajectory with no one to automate them. That is the part trstctl runs.

For MSPs

Run it for every customer you manage.

One control plane or dedicated deployments, each customer isolated by construction, usage metered per customer as invoice evidence, and managed-service and resale rights in the license. The 47-day schedule multiplies by your whole book of business; trstctl is built to carry that.

01 The console

Six tools. Each one answers a question you already have.

Every page in trstctl opens with the answer, then the real next action, then the exact evidence behind it. Missing evidence says unavailable; it is never dressed up as a reassuring zero.

Where did trstctl look, what did it find, and what should happen next?

Sources, schedules and runs feed one findings list, with CT watch and policy drift, so every credential gets an owner.

Open Discover in the demo
The Discover page of the trstctl console.

Inventory that knows ownership

Every credential points back to an owner, tenant, source, expiry, risk and operational state instead of living as an orphaned blob.

Graph context for risk

See where a credential is used, what it can reach, which systems depend on it, and what breaks if it expires or is revoked.

02 Answers

Built for the questions you ask at 3 a.m.

Non-human identity goes wrong at the worst time. The answer should already be in the inventory, the graph and the audit trail.

“We’re breached. Which keys and certs can reach that host, and what do we kill first?”

The credential graph shows what each one can reach and what depends on it, so you revoke by blast radius instead of guessing.

“Audit wants every certificate issued last quarter, and who approved each one.”

Every issuance, approval and revocation is an immutable event you can replay. The audit trail is the product state, not a side spreadsheet.

“Can we automate issuance without handing a robot the CA private keys?”

The signer is a separate, isolated process. The control plane orchestrates but never holds the keys. Automation without losing custody.

03 Lifecycle

From discovery to retirement without a side spreadsheet.

The lifecycle is explicit: every state change emits an event, every external action goes through an outbox, and every retry is idempotent.

  1. 01

    Discover

    Agents and connectors find certificates, SSH trust, keys, secrets and workload identities.

  2. 02

    Issue

    Profiles, policies, approvals and signer-backed CA custody turn requests into credentials.

  3. 03

    Deploy

    Connectors write to the target only after the intent is recorded durably in the outbox.

  4. 04

    Rotate

    Policy-driven renewal keeps expiry from becoming an outage, with retry-safe operations.

  5. 05

    Retire

    Revocation, decommission and audit close the loop instead of leaving stale trust behind.

04 How it is built

Four things you cannot bolt on later.

Keys never join the control plane

A separate signer process holds them and signs on request. That separation is the product, not a deployment detail.

Every change is a permanent event

Issuance, renewal and revocation are immutable events. The audit trail is the product’s own memory, replayable on demand.

Each tenant is fenced by the database

PostgreSQL row-level security enforces the tenant line, so a missed check fails a test instead of a customer.

Post-quantum moves leave a receipt patent pending

Proof-carrying algorithm succession moves an estate to a new signing algorithm with a verifiable record at every step.

event tracesample
09:41:22Z request POST /api/v1/identities
09:41:22Z idempotency key claimed · operation locked
09:41:23Z policy profile=prod-web · approved=true
09:41:23Z event identity.created appended
09:41:23Z signer separate process · key handle only
09:41:23Z event identity.issued appended
09:41:24Z outbox deploy nginx-pool-7 · pending
09:41:24Z result certificate crt_7c91 · audit linked
05 If you already run something

Where trstctl fits next to the tools you have.

trstctl is not here to replace a great secrets engine or your in-cluster certificate automation. It is the inventory, lifecycle and audit layer across every kind of non-human identity, so the credentials no single tool owns stop falling through the cracks.

Next to a secrets engine

A secrets engine is excellent at secrets. trstctl wraps the full lifecycle around all non-human identity, from discovery to audit, and keeps signing in a separate, isolated process rather than in-app.

Next to a CA manager

Commercial CA managers are strong at X.509 at scale. trstctl treats X.509, SSH, secrets, API keys, tokens and SPIFFE as one inventory, self-hosted and source-available, with no per-certificate licensing.

Next to in-cluster certificate automation

In-cluster tooling is great at in-cluster certificates. trstctl spans clusters and the hybrid estate beyond Kubernetes, with an event-sourced audit trail you can replay and rebuild.

06 Air-gapped

Runs where the internet doesn’t.

Everything the lifecycle needs runs inside your network. The parts that do not are named here, not hidden.

Inside the gap

An egress guard that fails closed. An offline install bundle with checksums. An offline license. Offline-verifiable evidence. Telemetry off, with no collector to send to.

The air-gapped install →

What needs a path out

A public certificate authority, cloud DNS for validation, cloud certificate stores, transparency-log monitoring, cloud AI. Each is a destination you configure; nothing leaves otherwise.

~ / local evaluationready
$ git clone https://github.com/ctlplne/trstctl
$ cd trstctl
$ docker compose -f deploy/docker/docker-compose.yml up --build
 
✓ control plane serving /healthz /readyz /metrics
✓ signer isolated separate process
✓ PostgreSQL RLS active tenant floor
✓ event log online projections tailing
07 Deploy

Self-host it. Keep the keys close.

Run a local evaluation stack, deploy with Docker or Helm, then connect agents and CA and deployment integrations as your environment grows.

Business Source License 1.1: run it in production free, with no signed license; each release converts to MPL 2.0 four years after it ships. Licensing →

live demo source-available PostgreSQL-backed NATS JetStream events Docker / Helm / operator agents OpenAPI 3 + SDKs

Status: alpha

trstctl is pre-1.0 and in active development. The docs keep a standing list of what is served and what is not yet, and the demo runs on sample data. Expect rough edges, and file what you find. Current limitations → · Report an issue →

trstctl.com

Run the alpha. Tell us what breaks.

Start with the demo, then discovery. It is alpha software: expect rough edges, file what you find, and keep going until issuance, rotation, revocation and audit are boring.