Control plane · v0.1

One control plane for every app you ship.

Nexus handles the things every app needs — signing people in, deciding who can do what, holding the keys, and watching everything stays alive — so each project can focus on what makes it different.

Self-hosted · Fail-closed by design · Open-source ready

Unknown project
Active
Control plane overview
Project created
API key issued
SDK connected
Identity
Permissions
Registry
Audit
Live · last heartbeat 42s ago
Design principles

The rules the whole system is built around.

Source of truth
One place holds the answer. When Nexus can’t be sure, nothing happens.
Declare, don’t decide
Apps say what they can do. Nexus decides who may do it.
Fail-closed
In doubt, Nexus says no. Safety over convenience, always.
Module catalog

Every module Nexus is built around.

Available today or on the roadmap — toggle what you need per project.

Modules
The shared services Nexus provides, wired through one control plane.
IdentityAvailable

Project-isolated users and OAuth/OIDC login.

nexus/identity

PermissionsAvailable

Catalog, roles, and assignments.

nexus/permissions

RegistryAvailable

Instances and heartbeat health.

nexus/registry

NotifyAvailable

Email and notifications, one service.

nexus/notify

AuditAvailable

Append-only sensitive events.

nexus/audit

StoragePlanned

Files and objects, per project.

nexus/storage

VaultPlanned

Secrets and encrypted values.

nexus/vault

ConfigPlanned

Dynamic configuration per project.

nexus/config

MetricsPlanned

Usage and uptime signals.

nexus/metrics

BackupsPlanned

Snapshots and restore.

nexus/backup

Available now·Dashed tiles are planned — on the roadmap, not yet built.
How it works

Declare. Decide. Answer.

DeclareYour app publishes what it can do.
DecideYou grant those actions to roles and people.
AnswerYour app asks Nexus. It answers yes or no.
Yours

Self-hosted. Yours, completely.

A personal control plane — built to run on your own infrastructure and stay there.

Runs on your own server

Docker or a single host — no Kubernetes, no lock-in.

You hold the keys

Fail-closed by design. Your data, your rules.

Built to be open-sourced

A clean modular core with nothing hidden.

Bring your apps to one center of gravity.

Claim your instance and connect your first project in minutes.