What no single tool
ships together.
Conformance for a plain VPS. A secret-to-consumer graph. Governed autonomy enforced in code. An install that proves itself. One operating standard for a whole fleet. Five things a solo or small operator needs together, that no single existing tool ships as one.
pip install ess-orrery && ess-orrery doctor
Between your IaC and your monitoring.
Infrastructure-as-code (Ansible, Terraform, Puppet) applies desired state. Monitoring (Prometheus, Datadog) watches whether things are up. Orrery sits in between: it continuously checks that a box still matches the desired state you declared, and surfaces the drift neither side watches for. Conformance tools assume a cluster someone else already manages. Secrets managers assume you already run one. Agent-governance products assume a platform team. Orrery starts from a plain box a solo operator can actually run, and fills the seam between those categories.
A plain VPS, not a cluster
The reconciler runs read-only over plain ssh into any Linux box: a Hetzner VPS, a DigitalOcean droplet, a Raspberry Pi. No control plane assumed on the far end.
A secret graph, by identity only
Every secret mapped to the consumers that reference it, confirmed without ever reading a value. That graph is what makes rotation safe later, and it is not something Infisical or Doppler ships.
Governed autonomy, in code
Standing rules for an AI operator are only real if they live below the model. The checks refuse unsafe input structurally, they do not ask a model to behave.
An install that proves itself
ess-orrery doctor verifies the installation actually stands, then the reconciler keeps watching afterward, so nothing is trusted blind a month later.
One way to run every project
Declare, prove, gate, roll up: the same four beats on every stack and every CI host, so a whole fleet is held to one standard. A hard-won behavior can be locked so it never silently regresses.
Eleven checks, and they are the whole spine.
The reconciler holds each fact as a declaration plus a probe, and runs the probe continuously: a thing is not "declared", it is declared and its probe passes. Findings carry a severity from OK through INFO and WARN up to DRIFT, the core signal, disagreement between declared and observed, and FAIL, a broken invariant. All eleven ship today, read-only: they measure and report, they never change a box.
One source of truth
A bucket-to-account table is copied, in three different encodings, into the tools that consume it: a Python dict, a bash associative array, a bash case function. This check reads the truth and each consumer's own live encoding and reports exactly where they disagree.
OperationalThe reach matrix, live
The profile declares which edges from this box should be open and which should stay closed. Actual ssh reach is probed both ways: a depended-on link that is down is a failure; a deliberately closed link that has reopened is drift.
OperationalThe secret graph
Every declared secret is checked by its identity, a vault path or an env var name, never its value, against a fail-closed allowlist before anything is scanned. Confirmed edges pass; a consumer that stopped referencing a secret is drift.
OperationalWhat must exist, does
Required members are confirmed present; a missing one fails the run. A path marked planned-absent, a hardening step not yet taken, stays informational while absent and only warns if it reappears.
OperationalNothing quietly shrinks
A count, files in a directory or lines in a file, is held between a declared floor and ceiling. Dropping below the floor is a real incident; climbing far above it flags the floor itself as stale and due for recalibration.
OperationalThe guard cannot be moved
Every enforcement file must stay root-owned and no more writable than declared, so the rules that gate an AI operator's actions cannot be quietly loosened from inside. A file marked planned reports informational until it lands.
OperationalBehavior stays locked
A hard-won behavior is captured as a golden and held there. Any later run whose output no longer matches the golden fails the gate, so a fixed bug or a shipped guarantee cannot silently regress. Floors and ceilings let a value improve without sliding back.
OperationalArtifacts stay byte-exact
A protected file is pinned to the content address of its known-good bytes. If the file drifts from that hash, the check flags it, so an artifact that must not change quietly cannot.
OperationalHeadroom stays reachable
A cgroup that must stay recoverable is checked so it can still reclaim memory and its ceiling is actually reachable, catching the case where a brake would stall a slice instead of letting a runaway die.
OperationalUnits own their processes
A unit that declares it owns a process tree is checked to actually own it, so a service that has quietly lost the processes it should manage is caught before that gap bites.
OperationalCredentials still work
A declared credential is checked that it can still do what its consumers need, by capability, never by reading the secret, so a token that has gone stale or lost a permission is found before a job fails on it.
OperationalThree tenets, made concrete.
A principle is cheap until it shows up as code. Here is where each one actually lives.
It verifies its own install.
ess-orrery doctor is the self-check. The build sequence puts a blank-box install ahead of every later feature, because the install target is the real test, not a description of one.
Enforced in code, not asked of a model.
fleet-reach refuses to probe a host string that does not look like a safe ssh alias. secret-edges refuses to scan or echo anything that fails its identity allowlist first. The guard is structural, never a prompt asking something to behave.
Measure, do not read.
org-map does not trust that consumers agree with a table, it parses each one's actual live encoding and reports where they diverge. Documentation is the thing under test, including the status below, about Orrery itself.
How it is actually built.
Measure, do not read applies to Orrery's own claims too. What follows is stated as plainly as a drift finding: what runs today, what is in progress, and what is not built yet. Honest status is not a caveat here, it is the point.
Desired vs observed
Eleven read-only checks; a fact is declared and its probe passes, continuously.
Curated memory, under git
Replicated and restore-verified, not a folder of notes hoping to stay in sync.
Admission control, below the model
Rules gate tool calls and operator actions in code and architecture, never asked of a model.
The operator deck
A themed terminal deck plus a strong CLI over the same engine.
Verifies its own install
ess-orrery doctor confirms the installation actually stands, cold, on a blank box.
Per-directory isolation
Context resolves per working directory, so one installation cannot bleed into another's identity.
Metrics for Grafana
ess-orrery reconcile --format prometheus emits metrics; a ready-made dashboard ships in integrations/grafana/.
Box enrollment
One command to enrol a box with a role; the reach matrix becomes generated, not hand-kept.
Continuous fleet watch
Report-only reconciliation across the whole fleet, running on its own schedule instead of on demand.
Linked secret rotation
Does not exist. It would wrap OpenBao (MPL-2.0) and walk the secret-edges graph to rotate a credential everywhere it is consumed. The graph is real and running today; the fan-out apply and rollback across consumers is not, and will not ship until breakglass recovery is proven first.
Hosted control plane
Does not exist yet. The governed-autonomy trust layer and approvals, run for you rather than self-hosted.
Graphical fleet view
Does not exist yet. Today's operator surface is the CLI and the terminal deck; a screen-based fleet view is a later, separate scope.
Open at the core.
The core holds your secrets and reaches every box, so it is open and auditable: security is not a black box here. The layer that scales and governs is where the business lives.
ESS Orrery
Free to run, study, and modify. Zero runtime dependencies, read-only, identity-free: the reconciler and its eleven checks, per-directory context isolation, a self-verifying install, the CLI, and the themed terminal deck.
Governed autonomy
The trust layer for handing off consequential work safely: enforced standing rules, durable memory, plan-then-approve, a hosted control plane, and the graphical fleet view. Not part of this repository.
A commercial license is available from Evening Star Productions for anyone who cannot meet the AGPL terms (offering a modified version to others over a network under the same license). Full model and licensing detail on the pricing page.