Know every box in your fleet is exactly as you declared.
One control plane, every box, kept in sync.
ESS Orrery is software you install that holds the desired state of your whole fleet (any provider, any Linux box) and proves, continuously and read-only, that reality still matches it. Eleven checks surface drift the moment it appears. It measures and reports, it never changes your boxes.
pip install ess-orrery && ess-orrery doctor
hover a body to read it
See the whole fleet in sync, at a glance.
One dashboard for a mixed fleet. Any provider, any Linux box, from a solo operator's handful to an org across regions. Drift surfaces the moment reality diverges from what you declared. The deck below is illustrative.
The checks, in detail, live on the reconciler page. / See how it compares.
Desired state in. Drift out. Continuously.
Three things carry the whole product. Each has a page of its own.
Eleven read-only checks, run continuously
org-map, fleet-reach, secret-edges, declared-presence, floors, and managed-settings. A fact is not declared until its probe passes. Findings carry a severity and the run exits non-zero on drift, so a cron or CI can alert.
Explore the reconciler Trust by constructionRead-only, self-verifying, enforced below the model
ess-orrery doctor verifies its own install, then keeps watching for drift. The secret graph maps which secret feeds what, by a non-secret name, and never reads a secret's value. Rules live in code and architecture, not in a prompt you have to remember to honor.
See the security model Open coreAGPL core, commercial where it scales
The engine that holds your secrets and reaches every box is open and auditable, with zero runtime dependencies. The governed-autonomy trust layer and hosted plane are a separate commercial product, in development.
See pricing and licensingSee drift in Grafana, next to everything else.
ess-orrery reconcile --format prometheus emits Prometheus metrics, so drift shows up next to the metrics you already watch and alerts through the Alertmanager you already run. A ready-made dashboard ships in the repo at integrations/grafana/, import it as is. It is Prometheus exposition and a dashboard file, not a hosted service.
Run it against your own fleet.
Install the core, verify it, then reconcile against a profile you declare. Read-only, so the first run cannot break anything.
pip install ess-orrery && ess-orrery doctor