ctlplnestudio
ctlplne studio · operator-owned control planes

Control planes for the machine layer.

The identities, telemetry, and control loops that run your infrastructure are too important to rent back as a black box. ctlplne is a studio building self-hosted control planes that keep custody, audit, and explicit state on your side of the boundary.

ctlplne.core / production boundary nominal
identity
trstctl.ready
telemetry
probectl.ready
policy
gate.closed
audit
seal.active
> custody.boundary.locked
> event.fabric.online
> outbox.dispatch.bounded
> operator.evidence.ready
self-hostedby default, every product
operator-ownedkeys · telemetry · audit
2products live today
0vendor data custody
The thesis

The machine layer shouldn't be a black box you rent.

Every system the studio ships starts from the same three beliefs — the reason the products share a spine, not just a logo.

belief 01

Custody beats convenience

The credentials, keys, and telemetry that run your infrastructure are the last things you should hand to someone else's cloud. ctlplne systems are self-hosted, so custody never leaves your boundary — no phone-home, ever.

belief 02

State should be explicit

Every change is an event on an append-only log; the read model and the audit trail are projections of it. You can replay, rebuild, and inspect exactly what happened — not just trust that it did.

belief 03

Side effects stay bounded

External actions go through outboxes, idempotency, and human gates — automation that never quietly does the irreversible thing on your behalf.

The products

Two products, one operating model.

The first systems out of the ctlplne studio target different infrastructure surfaces, but the contract is the same: self-hosted control, explicit state, bounded side effects, and evidence operators can trust.

machine identity

trstctl

Self-hosted control plane for non-human credentials: X.509 certificates, SSH certs, secrets, API keys, tokens, and SPIFFE workload identities. It discovers, issues, deploys, rotates, revokes, and retires them while private keys stay in an isolated process.

network observability

probectl

Self-hosted, multi-tenant network observability across five planes: active testing, BGP/routing intelligence, flow analytics, device telemetry, and eBPF host/L7. It is OpenTelemetry-native and keeps telemetry inside your network.

the pattern

One operating model

Both products share the same spine: a tenant-aware control plane, an isolated trust boundary, event-sourced state, bounded side effects, and evidence operators can audit. New systems from the studio extend the same contract.

System Contract

Designed for teams that need custody and proof.

The ctlplne studio brand is grounded in the same promises the product READMEs make: self-hosting, tenant-aware control planes, auditability, and no quiet vendor custody over sensitive infrastructure data.

deployment stanceself-hosted
data postureoperator owned
identity productctlplne/trstctl
observability productctlplne/probectl
documentationrepo sourced
01Sensitive data stays operator-owned.
02State changes leave an audit trail.
03External effects are bounded and replay-safe.
04Docs and source stay inspectable.

Control planes for infrastructure that cannot be a black box.

Explore the active products, read the docs, and keep the machine layer under your own operating boundary.