Trusplex Operator

Operator runs the server work you'd rather not.

Ask in plain language: disk, logs, processes, a stuck service. Operator works on your servers over SSH, shows you what it found, and waits for your approval before anything destructive. Nothing is installed on the box.

web-1 · reachableAgent
The API is returning 502s. Check web-1 and fix it.
run_command · web-1
$ journalctl -u app -n 3
connecting to postgres://app:[REDACTED:DB_PASSWORD]@10.0.0.4
error: connection pool exhausted
The app's database pool is exhausted and it has stopped accepting requests. A restart clears it; I've noted the pool size in memory for later.

Approve destructive action

Nothing executes until you approve; your permission is re-checked, uncached, at that moment.
- restart server "web-1" via: sudo systemctl restart app
DeclineApprove & run
The agent

Hand it the job, not the steps.

Operator's agent works through a fixed set of tools. It prefers safe, read-only commands first, and it never makes up command output.

Commands

Runs shell commands on the server you name, and pages through long output instead of losing it.

Files

Lists, reads and edits files, writes new ones and deletes old ones, over SFTP.

Restarts

Restarts a server with the restart command you configured for it, and only with your approval.

Memory

Keeps runbooks and durable facts about your environment. Anything in IMMEDIATE.md is in front of it in every session.

The model is yours: Operator uses the language model your project connects in Trusplex Console (OpenAI, OpenRouter or Ollama), chosen per environment. Operator never holds the key.

When you'd rather drive

A terminal and your files, in the browser.

Terminal

A live shell on any registered server, over the same key. Output is scrubbed of your secrets as it streams, and every open and close is audited.

Files

Browse, upload, download, edit in place, rename and delete. Transfers go over SFTP on the same connection, up to 25 MB each, and downloads are scrubbed of your secrets.

Secrets

Store a value once and use it as @DB_PASSWORD@ in a command. It is filled in just before the command runs, and nobody can read it back: not you, not the API, not the agent.

Setup

One line in authorized_keys.

Register a server with its host, port and SSH user. Operator gives each environment its own Ed25519 key. Add the public half to ~/.ssh/authorized_keys for that user, press Verify, and you are connected.

To your server, Operator is just that user. Limit what the user can do, and you limit Operator. Password login can stay off.

# ~/.ssh/authorized_keys — the whole install
ssh-ed25519 AAAAC3Nz… trusplex-operator:<environment-id>

Every connection updates the server's status, so when one won't connect you can see why:

pending
Registered. The key isn't confirmed on the server yet.
reachable
The last connection succeeded.
key rejected
The server answered but refused the key. It isn't in authorized_keys for that user yet.
unreachable
The port is closed, the host is down, or the name doesn't resolve.
You stay in control

It asks before anything it can't undo.

Approval for destructive actions

When the agent wants to restart a server or delete a file, it stops and shows you exactly what it will run. Nothing happens until you choose Approve & run, and your permission is checked again at that moment.

Checked twice, every time

Each tool call must pass your own permissions and the agent's fixed policy. The agent can never do more than the person who asked it.

Secrets come back redacted

Everything that leaves a server, from command output to downloads, is scanned for your secrets and your environment's private key. What you see is [REDACTED:NAME], even as an owner.

An answer to "what changed?"

Every command, tool call, file change, redaction, approval and denial is in the audit log, whether a person or the agent did it.

Operator is not monitoring, CI or a deploy pipeline. It is hands for the work those tools leave behind. Where you already have a tool for a job, keep it.

Your first server takes one paste.

Sign in, create a project, register a server and add the key. Then hand Operator the next ops task that comes up.