TLS certificates are now 200 days — and falling to 47 by 2029. What it means for your renewals
non-human identity control plane

Non-human identity is where your next outage hides.

The certificates, SSH keys, secrets, and tokens no human remembers are the ones that take down production, widen a breach, or fail the next audit. trstctl discovers, issues, rotates, revokes, and retires every machine credential from one self-hosted control plane — with private keys sealed in an isolated signer.

The full console in your browser — sample data, no signup, no backend.

6credential families
keys isolatedprivate keys never join the control plane
0cloud control plane required
X.509 + SSHCertificate issuance, inventory, revocation, and trust distribution.
Secrets + API keysOwnership, rotation state, audit trail, and blast-radius context.
SPIFFE identitiesWorkload identity lifecycle across agents and clusters.
Human-safe opsIdempotent mutations, approvals, outbox delivery, and rollback evidence.
01 / COVERAGE

One register for credentials that humans do not remember.

Certificates, SSH trust, service tokens, API keys, and workload identities usually sprawl across teams and tools. trstctl treats them as one lifecycle with one inventory and one audit trail.

Inventory that knows ownership

Every credential points back to an owner, tenant, source, expiry, risk, and operational state instead of living as an orphaned blob.

Issuance behind a hard boundary

The control plane orchestrates. The signer process holds keys and signs over a constrained channel. That separation is the product, not a deployment detail.

Graph context for risk

See where a credential is used, what it can reach, which systems depend on it, and what breaks if it expires or is revoked.

02 / ANSWERS

Built for the questions you ask at 3 a.m.

Non-human identity goes wrong at the worst time. trstctl is built so the answer is already in the inventory, the graph, and the audit trail — not in a spreadsheet someone forgot to update.

“A certificate expires at 3 a.m. Sunday — who renews it before prod goes down?”
Policy-driven rotation renews ahead of expiry, and every operation is idempotent — a retried renewal can’t mint a duplicate or turn into an outage.
“We’re breached — which keys and certs can reach that host, and what do we kill first?”
The credential graph shows what each one can reach and what depends on it, so you revoke by blast radius instead of guessing.
“Audit wants every certificate issued last quarter — and who approved each one.”
Every issuance, approval, and revocation is an immutable event you can replay. The audit trail is the product state, not a side spreadsheet.
“Some service is using a key nobody owns. Where did it even come from?”
Discovery ties every credential back to an owner, source, expiry, and tenant — orphaned secrets get an owner instead of a shrug.
“Is our SSH trust actually what we think it is across the whole fleet?”
trstctl inventories SSH host and user trust and flags drift, so what’s really in authorized_keys matches what policy says should be there.
“Can we automate issuance without handing a robot the CA private keys?”
The signer is a separate, isolated process — the control plane orchestrates but never holds the keys. Automation without losing custody.
03 / LIFECYCLE

From discovery to retirement without a side spreadsheet.

The lifecycle is explicit: every state change emits an event, every external action goes through an outbox, and every retry is idempotent.

01

Discover

Agents and connectors find certificates, SSH trust, keys, secrets, and workload identities.

02

Issue

Profiles, policies, approvals, and signer-backed CA custody turn requests into credentials.

03

Deploy

Connectors write to the target only after intent is recorded durably in the outbox.

04

Rotate

Policy-driven renewal keeps expiry from becoming an outage, with retry-safe operations.

05

Retire

Revocation, decommission, and audit close the loop instead of leaving stale trust behind.

04 / ARCHITECTURE

Built around the things you cannot bolt on later.

Tenant isolation, event-sourced state, signer separation, memory discipline, and backpressure are first-order architecture constraints.

Storage isolation at the floor

Every tenant-scoped query is backed by PostgreSQL row-level security, not a best-effort application filter.

Event log as source of truth

Read models and audit trails are projections of immutable events, so state can be rebuilt and inspected.

Bulkheads for every subsystem

Bounded worker pools keep discovery, connectors, policy, API traffic, and external calls from starving one another.

event trace · sample
09:41:22Z request POST /api/v1/identities
09:41:22Z idem key accepted · operation locked
09:41:23Z policy profile=prod-web · approved=true
09:41:23Z event identity.created appended
09:41:23Z signer UDS call · key handle only
09:41:23Z event identity.issued appended
09:41:24Z outbox deploy nginx-pool-7 · pending
09:41:24Z result certificate id=crt_7c91 · audit linked
05 / SECURITY POSTURE

Make the safe path the default path.

trstctl is for teams that need automation without losing custody, blast-radius control, or auditability.

Cryptography behind one boundary

Signing, parsing, certificate handling, and secret material stay behind the dedicated internal crypto boundary.

Audit you can replay

Events are immutable; projections can be rebuilt. The audit trail is not a separate story from product state.

Tenant isolation by construction

Database policy enforces the tenant line, so a missed condition is a test failure instead of a customer incident.

No silent side effects

External calls are durable intents first, worker actions second. Retry semantics are built into the write path.

06 / IF YOU ALREADY RUN SOMETHING

Where trstctl fits next to the tools you have.

trstctl is not here to replace a great secrets engine or your in-cluster certificate automation. It is the inventory, lifecycle, and audit layer across every kind of non-human identity — so the credentials no single tool owns stop falling through the cracks.

vs. HashiCorp Vault

Vault is an excellent secrets engine. trstctl wraps the full lifecycle around all non-human identity — discover, issue, rotate, revoke, retire, audit — and keeps signing in a separate, isolated process rather than in-app.

vs. Venafi / a CA manager

Commercial CA managers are strong at X.509 at scale. trstctl treats X.509, SSH, secrets, API keys, tokens, and SPIFFE as one inventory — self-hosted and source-available, with no per-certificate licensing.

vs. cert-manager / smallstep

Both are great for in-cluster certificate automation. trstctl spans clusters and the hybrid estate beyond Kubernetes, with an event-sourced audit trail you can replay and rebuild.

~ / local eval
$ git clone https://github.com/ctlplne/trstctl
$ cd trstctl
$ docker compose -f deploy/docker/docker-compose.yml up --build
control plane serving /readyz
signer isolated UDS boundary
PostgreSQL RLS active tenant floor
event log online projection tailing
07 / DEPLOY

Self-host it. Keep the keys close.

Run a local evaluation stack, deploy with Docker or Helm, then connect agents and CA/deployment integrations as your environment grows.

live demo source-available PostgreSQL-backed NATS JetStream events Docker / Helm agent workers OpenAPI + gRPC
trstctl.com

Control the credentials your infrastructure already depends on.

Start with discovery. Keep going until issuance, rotation, revocation, and audit are boring.