maruina/azath

Homelab KMS for Talos Linux disk encryption and Synology volume unsealing. AES-256-GCM with Telegram approval gates.

★ 0Forks 0GoGitHub ↗Compare
gogrpchomelabkmssynologytalos

README

azath

Homelab KMS for Talos Linux disk encryption and Synology encrypted volume unsealing. azath seals secrets with AES-256-GCM and gates every successful unseal behind a Telegram approval, so a stolen client cannot auto-unseal without you.

In the Malazan world, Azath Houses are silent wardens — ancient structures that seal away forces too dangerous to leave unbound.

What is azath

azath is a small gRPC KMS that implements the Talos KMS protocol and serves encrypted passphrases to Synology clients. It runs as two servers (LAN + VPS) sharing a master key and device list, with Caddy terminating TLS in front of loopback-only gRPC listeners. Every unseal requires a Telegram approval (or a short-lived approval cache hit); disabling a device in config and redeploying stops all sealing and unsealing for that device.

Command Purpose Status
azath serve gRPC Seal/Unseal server for the Talos KMS protocol implemented
azath config validate <path> Validate server config implemented
azath config new-device --name <name> --config <path> Append a configured device and print its generated UUID implemented
azath seal Seal one secret against an azath endpoint planned
azath client Unseal one sealed blob and run one command planned

For the threat model, shared-state requirements, and server/client model, see docs/architecture/mvp.md.

Install

azath ships a root-run installer for Debian 13 servers and Synology DSM 7 clients on amd64 and arm64.

End-to-end deployment runbooks:

Contributing

azath is Go 1.26, module github.com/maruina/azath, entry point cmd/azath/main.go.

make build   # build bin/azath (version + commit injected via ldflags)
make test    # go test ./... -v -race -count=1
make lint    # go vet + golangci-lint
make vet     # go vet only
make clean   # remove bin/

Run make test before marking work complete. Code conventions, invariants, and validation commands are in AGENTS.md.

Releasing

Releases are tag-driven. Push a v-prefixed tag and the Release workflow builds the artifacts and publishes the GitHub release:

git tag v0.2.0
git push origin v0.2.0

The release notes are generated by GoReleaser from the commits since the previous tag, grouped by conventional-commit type (feat/fix, with an "Other changes" bucket) and with merge commits and chore(deps)/ci/style/test noise excluded. See .goreleaser.yml for the exact filters.

The release ships two archives (azath_linux_amd64.tar.gz, azath_linux_arm64.tar.gz), checksums.txt, and the root-run install.sh as release assets. The workflow asserts exactly those assets are published.

Before cutting the first public release, follow the publication and rollout gates in deploy/README.md: goreleaser check and goreleaser release --snapshot --clean validation, installer validation under debian:13-slim and busybox:1.37, a Gitleaks history audit, and smoke-testing Debian 13 and DSM 7.

Security model

azath protects against stolen clients auto-unsealing without Telegram approval. It does not protect against compromise of both a sealed blob and the azath master key, or against approving a malicious request without verifying the server/device details in Telegram. See docs/architecture/mvp.md for the full threat model.

Contributors

maruinarenovate[bot]

Issues