Ladon

REVYTECH · CloudBSD

Ladon

Clustered secrets for FreeBSD and CloudBSD. Quorum from day one — not a single-node toy that grows a cluster later.

ladon.cloudbsd.org ladon.revytechinc.com

Secrets the operator way

Seal the cluster. Unseal with shards. Put KV paths. Workloads pull by reference — passwords never live in committed YAML.

  • KV at rest

    AES-256-GCM. Paths and namespaces line up with Aeolus scopes so demo/db/password means the same place everywhere.

  • Quorum first

    Three-node Raft from the start. Kill one node; reads and writes still land on the survivors.

  • mTLS mesh

    Nodes authenticate to each other on a private CA. Operators stay off the public CA for the control plane.

Cluster shape

ladon status
# every node answers; leader elected
ladon status
sealed=false  peers=3  leader=n2  raft=healthy

ladon kv put demo/db/password
ladon kv get demo/db/password

Same CLI on FreeBSD and CloudBSD. Deploy samples for n1–n3 live under deploy/ in the repo.

Consumed, not embedded

Aeolus ensembles reference Ladon. They do not ship a second secrets database.

ensemble.yml
services:
  - name: db
    image: ghcr.io/cloudbsdorg/aeolus-mariadb:16
    secretRef:
      - ladon: demo/db/password
        env: MYSQL_PASSWORD

Product landing for the runtime: aeolus.cloudbsd.org. FreeBSD 16 image recipes: cloudbsdorg/aeolus-examples.