🔐 An immutable, API-driven, high-assurance PKI operating system.
CryptOS-PKI is an open-source, Apache-2.0 licensed operating system for certificate
authorities. One signed, immutable image boots as a Root, Intermediate or Issuing CA.
The CA keys live in the TPM or on an encrypted state partition and never touch disk in
the clear, and there's no SSH and no shell: the only way in is an mTLS gRPC API, driven
by the cryptosctl CLI or the optional Fleet Manager. It's for teams that run their own
internal PKI without AD CS and without a general-purpose server holding the CA key. It's
alpha software, versioned 0.x until 1.0.0.
🏠 Home: cryptos-pki.com
- cryptos-node: the PKI engine: the CA, the gRPC API, the enrolment and revocation endpoints, and the
cryptosctlCLI. - cryptos-appliance: the appliance image built around the engine: the hardened kernel, the signed Unified Kernel Image, the read-only SquashFS, the installer and A/B upgrades.
- cryptos-manager: the Fleet Manager backend: node adoption, inventory and fleet topology over mTLS gRPC, an MCP endpoint for AI agents, and its own Helm chart.
- cryptos-web: the Fleet Manager web frontend, in React and TypeScript, served by cryptos-manager.
- cryptos-release: the pinned release manifest, plus a deprecated Fleet Manager chart.
- cryptos-lab: tooling for testing CryptOS on real and virtual hardware: VMware ESXi via
govctoday, bare metal planned.
- website: the source of the CryptOS website and documentation.
- Contributing guide, with the DCO sign-off
- Code of Conduct
- Security policy
CryptOS was originally written by @Bugs5382.