OPERATIONS

Central Management

Coordinate distributed protection through a self-hosted control plane. Organize applications into projects and manage the people, credentials, agents, and security policies attached to each project.

CAPABILITIES

What it provides

  • Project membership with viewer, member, and owner roles.
  • Certificate-based agent enrollment and gRPC mutual TLS.
  • Configuration bundles delivered to connected WAF agents.
  • Audit records for security-relevant administrative changes.

DEPLOYMENT WORKFLOW

How to use it

  1. 01

    Deploy the control plane and initialize an administrator account.

  2. 02

    Create a project, assign appropriate membership, and provision agent credentials.

  3. 03

    Connect agents, verify their status, and apply project policies from the dashboard.

CONFIGURATION & OPERATION

Where it fits in your setup

System administrator access is separate from project roles. Provision credentials through the Credentials page and protect private keys. The certificate fingerprint identifies the agent’s project; provider Auth-Keys are separate credentials.

COVERAGE & LIMITS

What to account for

Agent connectivity and version compatibility affect update delivery. Self-hosting also means operating backups, upgrades, database retention, and access controls. Different data providers may require their own credentials and outbound connectivity.

Put the policy into practice.

Follow the documentation and validate with your own workload.

Open documentation →