ESS Orrery
Why Orrery

What no single tool
ships together.

Conformance for a plain VPS. A secret-to-consumer graph. Governed autonomy enforced in code. An install that proves itself. One operating standard for a whole fleet. Five things a solo or small operator needs together, that no single existing tool ships as one.

pip install ess-orrery && ess-orrery doctor
I

Between your IaC and your monitoring.

Infrastructure-as-code (Ansible, Terraform, Puppet) applies desired state. Monitoring (Prometheus, Datadog) watches whether things are up. Orrery sits in between: it continuously checks that a box still matches the desired state you declared, and surfaces the drift neither side watches for. Conformance tools assume a cluster someone else already manages. Secrets managers assume you already run one. Agent-governance products assume a platform team. Orrery starts from a plain box a solo operator can actually run, and fills the seam between those categories.

01

A plain VPS, not a cluster

The reconciler runs read-only over plain ssh into any Linux box: a Hetzner VPS, a DigitalOcean droplet, a Raspberry Pi. No control plane assumed on the far end.

02

A secret graph, by identity only

Every secret mapped to the consumers that reference it, confirmed without ever reading a value. That graph is what makes rotation safe later, and it is not something Infisical or Doppler ships.

03

Governed autonomy, in code

Standing rules for an AI operator are only real if they live below the model. The checks refuse unsafe input structurally, they do not ask a model to behave.

04

An install that proves itself

ess-orrery doctor verifies the installation actually stands, then the reconciler keeps watching afterward, so nothing is trusted blind a month later.

05

One way to run every project

Declare, prove, gate, roll up: the same four beats on every stack and every CI host, so a whole fleet is held to one standard. A hard-won behavior can be locked so it never silently regresses.

II

Eleven checks, and they are the whole spine.

The reconciler holds each fact as a declaration plus a probe, and runs the probe continuously: a thing is not "declared", it is declared and its probe passes. Findings carry a severity from OK through INFO and WARN up to DRIFT, the core signal, disagreement between declared and observed, and FAIL, a broken invariant. All eleven ship today, read-only: they measure and report, they never change a box.

org-map

One source of truth

A bucket-to-account table is copied, in three different encodings, into the tools that consume it: a Python dict, a bash associative array, a bash case function. This check reads the truth and each consumer's own live encoding and reports exactly where they disagree.

Operational
fleet-reach

The reach matrix, live

The profile declares which edges from this box should be open and which should stay closed. Actual ssh reach is probed both ways: a depended-on link that is down is a failure; a deliberately closed link that has reopened is drift.

Operational
secret-edges

The secret graph

Every declared secret is checked by its identity, a vault path or an env var name, never its value, against a fail-closed allowlist before anything is scanned. Confirmed edges pass; a consumer that stopped referencing a secret is drift.

Operational
declared-presence

What must exist, does

Required members are confirmed present; a missing one fails the run. A path marked planned-absent, a hardening step not yet taken, stays informational while absent and only warns if it reappears.

Operational
floors

Nothing quietly shrinks

A count, files in a directory or lines in a file, is held between a declared floor and ceiling. Dropping below the floor is a real incident; climbing far above it flags the floor itself as stale and due for recalibration.

Operational
managed-settings

The guard cannot be moved

Every enforcement file must stay root-owned and no more writable than declared, so the rules that gate an AI operator's actions cannot be quietly loosened from inside. A file marked planned reports informational until it lands.

Operational
behavior-lock

Behavior stays locked

A hard-won behavior is captured as a golden and held there. Any later run whose output no longer matches the golden fails the gate, so a fixed bug or a shipped guarantee cannot silently regress. Floors and ceilings let a value improve without sliding back.

Operational
content-address

Artifacts stay byte-exact

A protected file is pinned to the content address of its known-good bytes. If the file drifts from that hash, the check flags it, so an artifact that must not change quietly cannot.

Operational
memory-headroom

Headroom stays reachable

A cgroup that must stay recoverable is checked so it can still reclaim memory and its ceiling is actually reachable, catching the case where a brake would stall a slice instead of letting a runaway die.

Operational
session-ownership

Units own their processes

A unit that declares it owns a process tree is checked to actually own it, so a service that has quietly lost the processes it should manage is caught before that gap bites.

Operational
vault-capability

Credentials still work

A declared credential is checked that it can still do what its consumers need, by capability, never by reading the secret, so a token that has gone stale or lost a permission is found before a job fails on it.

Operational
III

Three tenets, made concrete.

A principle is cheap until it shows up as code. Here is where each one actually lives.

01 / integrity

It verifies its own install.

ess-orrery doctor is the self-check. The build sequence puts a blank-box install ahead of every later feature, because the install target is the real test, not a description of one.

02 / enforcement

Enforced in code, not asked of a model.

fleet-reach refuses to probe a host string that does not look like a safe ssh alias. secret-edges refuses to scan or echo anything that fails its identity allowlist first. The guard is structural, never a prompt asking something to behave.

03 / discipline

Measure, do not read.

org-map does not trust that consumers agree with a table, it parses each one's actual live encoding and reports where they diverge. Documentation is the thing under test, including the status below, about Orrery itself.

IV

How it is actually built.

Measure, do not read applies to Orrery's own claims too. What follows is stated as plainly as a drift finding: what runs today, what is in progress, and what is not built yet. Honest status is not a caveat here, it is the point.

Operational today7
reconcilerLive

Desired vs observed

Eleven read-only checks; a fact is declared and its probe passes, continuously.

spineLive

Curated memory, under git

Replicated and restore-verified, not a folder of notes hoping to stay in sync.

guardsLive

Admission control, below the model

Rules gate tool calls and operator actions in code and architecture, never asked of a model.

deck + cliLive

The operator deck

A themed terminal deck plus a strong CLI over the same engine.

installLive

Verifies its own install

ess-orrery doctor confirms the installation actually stands, cold, on a blank box.

contextLive

Per-directory isolation

Context resolves per working directory, so one installation cannot bleed into another's identity.

prometheusLive

Metrics for Grafana

ess-orrery reconcile --format prometheus emits metrics; a ready-made dashboard ships in integrations/grafana/.

In progress2
profilesIn progress

Box enrollment

One command to enrol a box with a role; the reach matrix becomes generated, not hand-kept.

reconcilerIn progress

Continuous fleet watch

Report-only reconciliation across the whole fleet, running on its own schedule instead of on demand.

Not built yet3
vaultNot built

Linked secret rotation

Does not exist. It would wrap OpenBao (MPL-2.0) and walk the secret-edges graph to rotate a credential everywhere it is consumed. The graph is real and running today; the fan-out apply and rollback across consumers is not, and will not ship until breakglass recovery is proven first.

hostedNot built

Hosted control plane

Does not exist yet. The governed-autonomy trust layer and approvals, run for you rather than self-hosted.

guiNot built

Graphical fleet view

Does not exist yet. Today's operator surface is the CLI and the terminal deck; a screen-based fleet view is a later, separate scope.

V

Open at the core.

The core holds your secrets and reaches every box, so it is open and auditable: security is not a black box here. The layer that scales and governs is where the business lives.

The core

ESS Orrery

AGPL-3.0-or-later

Free to run, study, and modify. Zero runtime dependencies, read-only, identity-free: the reconciler and its eleven checks, per-directory context isolation, a self-verifying install, the CLI, and the themed terminal deck.

The commercial layer

Governed autonomy

Commercial license

The trust layer for handing off consequential work safely: enforced standing rules, durable memory, plan-then-approve, a hosted control plane, and the graphical fleet view. Not part of this repository.

A commercial license is available from Evening Star Productions for anyone who cannot meet the AGPL terms (offering a modified version to others over a network under the same license). Full model and licensing detail on the pricing page.

In service to Life