ShellOrchestra

BY DEVELASTIC

ProductSecurityPricingPro cabinet
Sign in

Security model

ShellOrchestra is built for operators who want convenient browser control without pretending that server orchestration is low-risk. The product favors explicit authorization, narrow scripts, and visible trust boundaries.
No remote agent

Managed hosts are reached through OpenSSH and standard system tools. ShellOrchestra does not require installing a permanent agent daemon on servers.

SSH CA by default

Instead of long-lived authorized_keys entries, ShellOrchestra can configure an SSH CA and issue short-lived user certificates for connections.

Trusted devices

Server-access material is tied to trusted client devices. New devices and sensitive key changes are approved through the trusted-device workflow.

Sandboxed app model

Desktop apps are designed around narrow backend actions, payload validation, iframe sandboxes for untrusted rich content, and audit logging.