Security and architecture
What you hand over, and what you do not.
This page answers two questions: what the control plane can reach, and what happens when part of it fails. Installation is here too, because “it runs on your machines” is a security fact before it is a getting-started one.
Security
The control plane holds no credentials.
Credentials stay on the machine that owns them; the database knows only a path and a reference. Compromising the database yields no provider credential.
- Mutual TLS for every byte after enrolment
- Redaction cannot be bypassed
- The browser never reaches a host directly
Provider isolation goes through the process environment, never a command line: a process list is world-readable and an environment is not. Nodes speak mutual TLS after a single-use enrolment token.
Being on an internal network is not a security control.
Redaction lives inside the log handler rather than at call sites, so it cannot be forgotten. Terminal output is never written as raw HTML, and a browser never connects to a machine directly.
proofgo test ./internal/security/redact — redaction lives in the log handler
Install
Four dependencies, four binaries, one doctor.
Ubuntu, Go and Node. A database, a queue, a cache and a message broker. doctor verifies all of them without changing anything, and tells you which mode it found.
One step waits for you on a fresh install: no account/model pairing is routable until one has been verified. That is deliberate — it is what stops work being sent to a pairing nobody has checked.
Known gaps.
Every document carries a "known gaps" section. That is the honest part; read it before relying on a capability.
- No scheduled backup — the commands exist, nothing runs them on a timer.
- No one-command node install; the binary is copied and enrolled by hand.
- The server install script does nothing about TLS or the reverse proxy; both are manual.
- A retention policy is seeded, and nothing enforces it.
- A handler that fails for a transient reason is not retried; it dead-letters.
- The terminal layer has not yet been exercised against a live tmux.
The recovery procedure differs by mode, which is why doctor names it. No containers, no orchestrator, no runtime that must be installed on every target before anything can run.
proofmake doctor — verifies all four dependencies non-destructively
On your own machines, with your own accounts.
Kimene runs on your infrastructure and manages your own provider accounts. It is not a credential-sharing service, not a multi-tenant proxy, and not a way around provider limits.