Inventory that knows ownership
Every credential points back to an owner, tenant, source, expiry, risk and operational state instead of living as an orphaned blob.
The certificates, SSH keys, secrets and tokens no human remembers are the ones that take down production, widen a breach, or fail the next audit. trstctl discovers, issues, rotates, revokes and retires every machine credential from one self-hosted control plane, with private keys sealed in an isolated signer.
The full console in your browser: sample data, no signup, no backend.
Every page in trstctl opens with the answer, then the real next action, then the exact evidence behind it. Missing evidence says unavailable; it is never dressed up as a reassuring zero.
Sources, schedules and runs feed one findings list. Certificate Transparency watch and drift against policy live here too, so an orphaned credential gets an owner instead of a shrug.
Open Discover in the demo
Inventory, estate health, CRL and CT, and renewal readiness as four lenses on one list. Work arriving in the next 90 days is counted in 15-day windows; expired work stays in the queue instead of hiding in the forecast.
Open Certificates in the demo
SPIFFE and attested identities, ephemeral credentials, SSH access and fleet agents, each tied to the machine that holds them and the attester that vouched for it.
Open Workloads in the demo
Leaks, overdue rotation, failed delivery, ownership and machine access are visible before anyone opens a value. Dynamic sources mint short-lived credentials on demand; sync sends them where they run.
Open Secrets in the demo
Code signing with provenance, keyless flows and the state of the key behind every signature, so a release is trusted for a reason you can show.
Open Software Trust in the demo
What to fix first, what could be affected, incidents with a remediation path, approvals, jobs and queues, and a change history you can replay.
Open Operations in the demo
Every credential points back to an owner, tenant, source, expiry, risk and operational state instead of living as an orphaned blob.
The control plane orchestrates. A separate signer process holds the keys and signs over a constrained channel. That separation is the product, not a deployment detail.
See where a credential is used, what it can reach, which systems depend on it, and what breaks if it expires or is revoked.
Non-human identity goes wrong at the worst time. trstctl is built so the answer is already in the inventory, the graph and the audit trail, not in a spreadsheet someone forgot to update.
“A certificate expires at 3 a.m. Sunday. Who renews it before prod goes down?”
Policy-driven rotation renews ahead of expiry, and every operation is idempotent: a retried renewal cannot mint a duplicate or turn into an outage.
“We’re breached. Which keys and certs can reach that host, and what do we kill first?”
The credential graph shows what each one can reach and what depends on it, so you revoke by blast radius instead of guessing.
“Audit wants every certificate issued last quarter, and who approved each one.”
Every issuance, approval and revocation is an immutable event you can replay. The audit trail is the product state, not a side spreadsheet.
“Some service is using a key nobody owns. Where did it even come from?”
Discovery ties every credential back to an owner, source, expiry and tenant. Orphaned secrets get an owner instead of a shrug.
“Is our SSH trust actually what we think it is across the whole fleet?”
trstctl inventories SSH host and user trust and flags drift, so what is really in authorized_keys matches what policy says should be there.
“Can we automate issuance without handing a robot the CA private keys?”
The signer is a separate, isolated process. The control plane orchestrates but never holds the keys. Automation without losing custody.
The lifecycle is explicit: every state change emits an event, every external action goes through an outbox, and every retry is idempotent.
Agents and connectors find certificates, SSH trust, keys, secrets and workload identities.
Profiles, policies, approvals and signer-backed CA custody turn requests into credentials.
Connectors write to the target only after the intent is recorded durably in the outbox.
Policy-driven renewal keeps expiry from becoming an outage, with retry-safe operations.
Revocation, decommission and audit close the loop instead of leaving stale trust behind.
Tenant isolation, event-sourced state, signer separation, memory discipline and backpressure are first-order architecture constraints.
Every tenant-scoped query is backed by PostgreSQL row-level security, not a best-effort application filter.
Read models and audit trails are projections of immutable events, so state can be rebuilt and inspected.
Bounded worker pools keep discovery, connectors, policy, API traffic and external calls from starving one another.
trstctl is for teams that need automation without losing custody, blast-radius control, or auditability.
Signing, parsing, certificate handling and secret material stay behind the dedicated internal crypto boundary.
Events are immutable and projections can be rebuilt. The audit trail is not a separate story from product state.
Database policy enforces the tenant line, so a missed condition is a test failure instead of a customer incident.
External calls are durable intents first, worker actions second. Retry semantics are built into the write path.
trstctl is not here to replace a great secrets engine or your in-cluster certificate automation. It is the inventory, lifecycle and audit layer across every kind of non-human identity, so the credentials no single tool owns stop falling through the cracks.
Vault is an excellent secrets engine. trstctl wraps the full lifecycle around all non-human identity, from discovery to audit, and keeps signing in a separate, isolated process rather than in-app.
Commercial CA managers are strong at X.509 at scale. trstctl treats X.509, SSH, secrets, API keys, tokens and SPIFFE as one inventory, self-hosted and source-available, with no per-certificate licensing.
Both are great for in-cluster certificate automation. trstctl spans clusters and the hybrid estate beyond Kubernetes, with an event-sourced audit trail you can replay and rebuild.
Run a local evaluation stack, deploy with Docker or Helm, then connect agents and CA and deployment integrations as your environment grows.
Start with discovery. Keep going until issuance, rotation, revocation and audit are boring.