CertiStack Community Edition documentation
Product Overview & Pricing
Looking for product architecture comparisons, evidence benchmarks, or commercial licensing? ← Return to CertiStack Home.
This documentation describes the public Community Edition only. It documents what the software does today; it is not a promise of certification, service levels, or future commercial functionality.
Start here
- Quickstart — from an empty controller host to a signed, verified report in ten commands.
- Getting started — install and verify a release, set up SSH access, configure credentials, run and verify a plan, upgrade and roll back.
- Frequently asked questions — short answers to what people ask first.
- Controller deployment model — management-host container/VM, temporary node worker, and security boundary.
- Architecture — recovery flow, isolation, probes, reports, and cleanup behavior.
- Troubleshooting — operational diagnostics and common failure modes.
Reference
- CLI reference — every command and flag, the exit
statuses, and the checks
doctorruns. - Configuration reference — every environment variable, the environment file, precedence, and the files CertiStack keeps on the controller and the node.
- Test-plan reference — supported YAML schema and validation rules.
- Example plans — a single VM, a three-tier Linux application, and a Windows domain, plus how to choose probes.
- Reports and verification — what a signed report contains, how keys and keyrings work, and how to verify a report with or without CertiStack.
Operations
- Automation and scheduling — run validations nightly with
systemdorcron, verify the result, and get told when it fails. - Lab campaigns — the campaign runner, test-only shortcuts, fault drills, and capacity guards.
- Terraform prerequisites — infrastructure inputs for the supplied example.
- Release readiness — supported matrix, required lab evidence, campaign safety controls, and the production release decision.
- Release evidence checklist — operator record for tying a candidate, matrix, signed reports, package gates, and final approval to the same release boundary.
- Lab acceptance runbook — the stop/go template, network, storage, and matrix-qualification path before a release campaign.
- Changelog — what changed in each release.
Project policy
- Edition boundary — public Community Edition versus the commercial Enterprise Edition.
- License — the GNU Affero General Public License v3.0, with the licensing FAQ.
- Security policy — how to report a vulnerability privately, the threat model, and how to verify a release.
- Contributing and the code of conduct — how to propose a change.
- Getting help — where to ask questions, file bugs, and find commercial support.
- Codebase guide — the package-by-package map for contributors.