Homelab KMS for Talos Linux disk encryption and Synology encrypted volume unsealing. azath seals secrets with AES-256-GCM and gates every successful unseal behind a Telegram approval, so a stolen client cannot auto-unseal without you.
In the Malazan world, Azath Houses are silent wardens — ancient structures that seal away forces too dangerous to leave unbound.
azath is a small gRPC KMS that implements the Talos KMS protocol and serves encrypted passphrases to Synology clients. It runs as two servers (LAN + VPS) sharing a master key and device list, with Caddy terminating TLS in front of loopback-only gRPC listeners. Every unseal requires a Telegram approval (or a short-lived approval cache hit); disabling a device in config and redeploying stops all sealing and unsealing for that device.
| Command | Purpose | Status |
|---|---|---|
azath serve |
gRPC Seal/Unseal server for the Talos KMS protocol |
implemented |
azath config validate <path> |
Validate server config | implemented |
azath config new-device --name <name> --config <path> |
Append a configured device and print its generated UUID | implemented |
azath seal |
Seal one secret against an azath endpoint | planned |
azath client |
Unseal one sealed blob and run one command | planned |
For the threat model, shared-state requirements, and server/client model, see docs/architecture/mvp.md.
azath ships a root-run installer for Debian 13 servers and Synology DSM 7 clients on amd64 and arm64.
- Install on Debian 13 — server binary, managed systemd unit, verification, rollback.
- Install on Synology DSM 7 — client binary only.
End-to-end deployment runbooks:
azath is Go 1.26, module github.com/maruina/azath, entry point cmd/azath/main.go.
make build # build bin/azath (version + commit injected via ldflags)
make test # go test ./... -v -race -count=1
make lint # go vet + golangci-lint
make vet # go vet only
make clean # remove bin/Run make test before marking work complete. Code conventions, invariants, and validation commands are in AGENTS.md.
Releases are tag-driven. Push a v-prefixed tag and the Release workflow builds the artifacts and publishes the GitHub release:
git tag v0.2.0
git push origin v0.2.0The release notes are generated by GoReleaser from the commits since the previous tag, grouped by conventional-commit type (feat/fix, with an "Other changes" bucket) and with merge commits and chore(deps)/ci/style/test noise excluded. See .goreleaser.yml for the exact filters.
The release ships two archives (azath_linux_amd64.tar.gz, azath_linux_arm64.tar.gz), checksums.txt, and the root-run install.sh as release assets. The workflow asserts exactly those assets are published.
Before cutting the first public release, follow the publication and rollout gates in deploy/README.md: goreleaser check and goreleaser release --snapshot --clean validation, installer validation under debian:13-slim and busybox:1.37, a Gitleaks history audit, and smoke-testing Debian 13 and DSM 7.
azath protects against stolen clients auto-unsealing without Telegram approval. It does not protect against compromise of both a sealed blob and the azath master key, or against approving a malicious request without verifying the server/device details in Telegram. See docs/architecture/mvp.md for the full threat model.