operator-owned infrastructure systems
Control planes for the machine layer.
ctlplne builds self-hosted systems for infrastructure teams that need custody, audit, and explicit state across machine identity, network telemetry, and the operational loops between them.
ctlplne.core / production boundary nominal
identity
trstctl.ready
telemetry
probectl.ready
policy
gate.closed
audit
seal.active
> custody.boundary.locked
> event.fabric.online
> outbox.dispatch.bounded
> operator.evidence.ready
selfhosted by default
yourskeys and telemetry
2active products
proofover quiet magic
Stack
Two products, one operating model.
The first ctlplne systems target different infrastructure surfaces, but the contract is the same: self-hosted control, explicit state, bounded side effects, and evidence operators can trust.
machine identitytrstctl
Self-hosted control plane for non-human credentials: X.509 certificates, SSH certs, secrets, API keys, tokens, and SPIFFE workload identities. It discovers, issues, deploys, rotates, revokes, and retires them while private keys stay in an isolated process.
network observabilityprobectl
Self-hosted, multi-tenant network observability across five planes: active testing, BGP/routing intelligence, flow analytics, device telemetry, and eBPF host/L7. It is OpenTelemetry-native and keeps telemetry inside your network.
control-plane studioctlplne
The umbrella for operator-owned systems built around custody, auditability, and production-grade control loops. Source and product work live in the ctlplne GitHub organization.
System Contract
Designed for teams that need custody and proof.
The ctlplne brand is grounded in the same promises the product READMEs make: self-hosting, tenant-aware control planes, auditability, and no quiet vendor custody over sensitive infrastructure data.
deployment stanceself-hosted
data postureoperator owned
identity productctlplne/trstctl
observability productctlplne/probectl
documentationrepo sourced
01Sensitive data stays operator-owned.
02State changes leave an audit trail.
03External effects are bounded and replay-safe.
04Docs and source stay inspectable.
Control planes for infrastructure that cannot be a black box.
Explore the active products, read the docs, and keep the machine layer under your own operating boundary.