ctlplne studio · operator-owned control planes

Control planes for the machine layer.

The identities, telemetry, and control loops that run your infrastructure are too important to rent back as a black box. ctlplne is a studio building self-hosted control planes that keep custody, audit, and explicit state on your side of the boundary.

Self-hostedby default, in every product
Operator-ownedkeys · telemetry · audit
2products live today
0vendor data custody
01 The thesis

The machine layer shouldn't be a black box you rent.

Every system the studio ships starts from the same three beliefs. They are the reason the products share a spine, not just a logo.

Custody beats convenience

The credentials, keys and telemetry that run your infrastructure are the last things you should hand to someone else's cloud. ctlplne systems are self-hosted, so custody never leaves your boundary. No phone-home, ever.

State should be explicit

Every change is an event on an append-only log; the read model and the audit trail are projections of it. You can replay, rebuild and inspect exactly what happened, rather than trust that it did.

Side effects stay bounded

External actions go through outboxes, idempotency and human gates. Automation that never quietly does the irreversible thing on your behalf.

02 The products

Two products, one operating model.

The first systems out of the studio target different infrastructure surfaces, but the contract is the same: self-hosted control, explicit state, bounded side effects, and evidence operators can trust.

machine identity

trstctl

Self-hosted control plane for non-human credentials: X.509 certificates, SSH certificates, secrets, API keys, tokens, SPIFFE workload identities and code-signing keys. It discovers, issues, deploys, rotates, revokes and retires them while private keys stay in an isolated signer.

live at trstctl.com
network observability

probectl

Self-hosted, multi-tenant network observability across five planes: active testing, BGP and routing intelligence, flow analytics, device telemetry, and eBPF host and layer-7. It is OpenTelemetry-native and keeps telemetry inside your network.

live at probectl.com
the pattern

One operating model

Both products share the same spine: a tenant-aware control plane, an isolated trust boundary, event-sourced state, bounded side effects, and evidence operators can audit. New systems from the studio extend the same contract.

the shared contract
livetrstctl.com
The trstctl console: three credentials need attention, each with its operational consequence spelled out, above a tool-health row covering Discover, Certificates, Workloads and Machines, Secrets, Software Trust and Operations.
The trstctl console, running in the browser demo at demo.trstctl.com. probectl's console joins this section once its own demo build is refreshed.
03 System contract

Designed for teams that need custody and proof.

The studio is grounded in the same promises the product READMEs make: self-hosting, tenant-aware control planes, auditability, and no quiet vendor custody over sensitive infrastructure data.

contractenforced in both products
deployment stanceself-hosted
data postureoperator owned
identity productctlplne/trstctl
observability productctlplne/probectl
documentationrepo sourced
licencesource-available
04 Principles

Four rules every system keeps.

01Sensitive data stays operator-owned.
02State changes leave an audit trail.
03External effects are bounded and replay-safe.
04Docs and source stay inspectable.
ctlplne.com

Control planes for infrastructure that cannot be a black box.

Explore the active products, read the docs, and keep the machine layer inside your own operating boundary.