Skip to content

Components

Current osctrl architecture diagram

Diagram of the current osctrl components in action. osctrl-mcp sits beside osctrl-cli as another automation interface backed by osctrl-api.

Component Role
osctrl-tls TLS endpoint implementing the osquery remote API
osctrl-api REST API for nodes and for osctrl itself
osctrl-mcp Model Context Protocol bridge for assistant and automation workflows
osctrl-frontend Browser operator interface backed by osctrl-api
osctrl-cli Command line interface for automation
nginx TLS termination and load balancing
Backend Centralized storage for all osctrl data
Metrics Instrumentation for osctrl operations
osctrld Bootstrap and maintenance of osquery installations