Security and trust

Explicit control, isolated identities.

Choose self-managed monitoring or opt into managed control from lsbs.cloud. Both connections remain outbound-only.

Outbound-only connection

Monitoring and managed control open no inbound agent port.

Separate control agent

Managed operations never travel through the monitoring identity or report acknowledgement.

Typed operations only

The managed agent rejects unknown operation envelopes and never accepts arbitrary shell commands.

Per-server identity

Repository, monitoring and managed-control credentials are independently revocable per server.

Replay resistance

Signed requests use bounded timestamps, one-use nonces, leases and idempotency keys.

Emergency exit

A root-only local action erases the managed identity and restores local WebAdmin writes.

Current technical beta

Manual infrastructure now; provider adapters later.

You provide the existing server address and domain. No Hetzner or DNS token is stored or used in this release.

Read the monitoring data statement →
Monitoring
Command-free
Managed control
Explicit opt-in
Private keys
Stay on each server
Provider API
Disabled