Skip to content
@CryptOS-PKI

CryptOS PKI

An immutable, API-driven PKI operating system: TPM-bound CA keys, signed images and a fleet manager. Apache-2.0.

CryptOS mark      FleetOS mark

CryptOS-PKI 🛡️

🔐 An immutable, API-driven, high-assurance PKI operating system.

CryptOS-PKI is an open-source, Apache-2.0 licensed operating system for certificate authorities. One signed, immutable image boots as a Root, Intermediate or Issuing CA. The CA keys live in the TPM or on an encrypted state partition and never touch disk in the clear, and there's no SSH and no shell: the only way in is an mTLS gRPC API, driven by the cryptosctl CLI or the optional Fleet Manager. It's for teams that run their own internal PKI without AD CS and without a general-purpose server holding the CA key. It's alpha software, versioned 0.x until 1.0.0.

🏠 Home: cryptos-pki.com

🧩 Node and Fleet Manager

  • cryptos-node: the PKI engine: the CA, the gRPC API, the enrolment and revocation endpoints, and the cryptosctl CLI.
  • cryptos-appliance: the appliance image built around the engine: the hardened kernel, the signed Unified Kernel Image, the read-only SquashFS, the installer and A/B upgrades.
  • cryptos-manager: the Fleet Manager backend: node adoption, inventory and fleet topology over mTLS gRPC, an MCP endpoint for AI agents, and its own Helm chart.

🖥️ Web

  • cryptos-web: the Fleet Manager web frontend, in React and TypeScript, served by cryptos-manager.

📦 Release and lab

  • cryptos-release: the pinned release manifest, plus a deprecated Fleet Manager chart.
  • cryptos-lab: tooling for testing CryptOS on real and virtual hardware: VMware ESXi via govc today, bare metal planned.

🌐 Website

  • website: the source of the CryptOS website and documentation.

🤝 Contributing

🙏 Acknowledgements

CryptOS was originally written by @Bugs5382.

📄 Licence

Apache-2.0.

Popular repositories Loading

  1. cryptos-node cryptos-node Public

    Immutable, API-driven, high-assurance PKI operating system. Talos-style: no SSH, no shell, mTLS-only management.

    Go 2

  2. cryptos-manager cryptos-manager Public

    Fleet Manager backend for CryptOS-PKI: cross-node aggregation, inventory, and chain-of-trust visualization over mTLS gRPC.

    Go 1

  3. api api Public archive

    Shared .proto definitions and generated gRPC stubs for CryptOS-PKI.

    TypeScript

  4. .github .github Public

    Organization-level config + profile README for CryptOS-PKI.

  5. cryptos-web cryptos-web Public

    Fleet Manager web frontend for CryptOS-PKI. React + TypeScript, built with Vite, served by manager.

    TypeScript

  6. cryptos-release cryptos-release Public

    Helm chart for the CryptOS PKI Fleet Manager

    Shell

Repositories

Showing 9 of 9 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…